Migrate Group Writeback
Doc updateThe group writeback migration documentation now links to the guidance for changing other attribute mappings.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Microsoft Entra guidance sets a January 31, 2027 milestone for COOP policy enforcement on new applications, while Cloud Sync guidance expands coverage of provisioning Microsoft Entra users and groups into AD DS. The period also brings a concrete ChatWork SCIM retirement date and documents an Entra Connect hotfix for a Pass-through Authentication setup issue.
New applications will be subject to Microsoft Entra COOP policy across web protocols after January 31, 2027. Popup-based sign-in may fail unless applications use a COOP-compatible flow such as MSAL.js v5. Applications that are not ready can temporarily opt out through the Microsoft Graph coopEnforcement property, then re-enable enforcement after migration.
A new article documents groups-only, users-only, and users-and-groups provisioning from Microsoft Entra ID to AD DS. User provisioning is marked Preview, while group provisioning is generally available; the guidance also covers per-domain configuration limits and performance considerations.
Updated provisioning guidance states that password writeback is not supported for users created in Microsoft Entra ID. Password-based applications, including applications using LDAP binds, must be updated to Kerberos for cloud-managed users to use passwordless authentication.
The ChatWork provisioning guide warns that SCIM-based provisioning will be discontinued on October 1, 2026, retiring the Microsoft Entra Enterprise App Gallery integration. Existing customers will no longer be able to provision users to ChatWork after that date.
The version history identifies 2.6.92.0 as a fix for a 2.6.91.0 issue that could prevent Pass-through Authentication setup through the Microsoft Entra Connect wizard. Administrators on 2.6.79.0 are directed to uninstall it and install 2.6.92.0; those affected by the 2.6.91.0 issue can use the hotfix.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The group writeback migration documentation now links to the guidance for changing other attribute mappings.
New preview documentation explains how to capture a group's distinguished name in a GroupDN extension before converting its Source of Authority to Microsoft Entra ID.
Version 2.6.92.0 was released on September 18, 2026, fixing a 2.6.91.0 issue that could prevent Pass-through Authentication setup through the Microsoft Entra Connect wizard.
New applications will be subject to Microsoft Entra COOP policy across web protocols after January 31, 2027. Popup-based sign-in may fail unless apps use a COOP-compatible flow, such as MSAL.js v5.
The page metadata was updated, and its references now link to the revised “Provision users and groups from Microsoft Entra ID to Active Directory” article.
The version history no longer states that the 09/23/2026 hotfix will be deployed through phased auto-upgrade. The Microsoft Graph permissions notice was repositioned.
The version history now lists release 2.6.92.0 as September 23, 2026, and the related 2.6.91.0 support date as September 23, 2027. The page metadata date was also updated.
The page’s subservice changed from hybrid to hybrid-cloud-sync, and its reviewer changed from dhanyak to dhanyahk.
The page’s subservice metadata changed from hybrid to hybrid-cloud-sync, and its reviewer metadata was updated.
The page now identifies the subservice as hybrid-cloud-sync instead of hybrid and corrects the reviewer attribution.
The page’s Microsoft Entra ID-to-AD attribute mapping section was removed and its introductory link now points to the dedicated configuration guide.
The version history now states that auto-upgrade will move existing installations to the September 18, 2026 hotfix through multiple phases.
The guide for provisioning from Microsoft Entra ID to Active Directory was removed. It covered attribute mappings, scoping filters, sAMAccountName customization, and target-container configuration.
The new tutorial explains how to provision cloud-managed users, a security group, and its membership into AD DS so members can access an on-premises Kerberos application. User provisioning is identified as being in preview.
The page updates diagram descriptions and explains that provisioned group members must have an AD account. Eligible members include synchronized users, cloud-managed users in scope for user provisioning, and cloud-created security groups. The provisioning example link was also updated.
The article documents how Cloud Sync scopes, matches, creates, updates, and deletes users, groups, and memberships in Active Directory, including matching with msDS-ExternalDirectoryObjectId and user source-of-authority scenarios.
The article expands beyond group-only provisioning to explain provisioning users, groups, or both from Microsoft Entra ID to on-premises AD DS. It adds prerequisites, deployment options, scoping filters, target containers, and attribute-mapping guidance; user-related options are marked Preview.
A new preview how-to explains on-demand testing for users and groups, default accidental-delete and email settings, enabling configurations, handling quarantines, restarting sync, and removing configurations.
A new article documents prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS using Cloud Sync. It also links to configuration, testing, deployment, and agent setup guidance.
The tutorial now covers provisioning both users and groups from Microsoft Entra ID to Active Directory. It adds examples for filtering groups by an extension value and mapping a user extension into an Active Directory attribute, along with updated prerequisites and guidance.
The guide now documents testing individual users or groups when provisioning from Microsoft Entra ID to Active Directory. It adds steps for selecting objects, selecting up to five group members, and reviewing detailed results, retries, and additional tests.
The article now covers directory extensions for both users and groups, clarifies the supported application identifier and Tenant Schema Extension App prerequisite, and updates examples, links, and related content.
The documentation warns that ChatWork will discontinue SCIM-based provisioning on October 1, 2026, retiring the Entra Enterprise App Gallery integration.
The page’s subservice metadata was updated, and its attribute-mapping link now points to the renamed configuration guide.
The article now states that it covers on-demand provisioning from Active Directory to Microsoft Entra ID and links to a separate article for provisioning in the reverse direction.
The tutorial for provisioning groups to AD DS with Microsoft Entra Cloud Sync was deleted, including its setup guidance, scoping recommendation, and group/user synchronization scenarios.
A new article explains groups-only, users-only, and users-and-groups provisioning from Microsoft Entra ID to AD DS. User provisioning is in preview, while group provisioning is generally available; it also documents per-domain configuration limits and performance guidance.
The new overview describes how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to AD, including supported configurations, user types, attribute updates, enforcement, and provisioning flow. User provisioning is in preview, while group provisioning is generally available; password writeback isn't supported.
The article now describes provisioning Microsoft Entra-managed users back to Active Directory with Cloud Sync so they can access Kerberos-based on-premises applications while their lifecycle is governed from the cloud. It also updates passwordless authentication guidance and diagrams.
The guidance now specifies that password-based apps, including LDAP-authenticated apps, must be updated to Kerberos for cloud-managed users to use passwordless authentication.
The guidance now links to updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory and nested-group membership behavior. Page metadata was also refreshed.
The article’s introductory wording and references were updated, including the link to cloud-first identity management guidance. The described Group SOA and group replication steps remain unchanged.
The documentation now states that password writeback isn't supported for applications that collect passwords, including applications that authenticate users through an LDAP bind.
The documentation now identifies affected accounts as cloud-managed users and explains that password writeback is unavailable for them. It also states that they can access Kerberos-based applications through passwordless authentication using the AD account created by provisioning.
The documentation now specifies that password writeback isn't available for users created in Microsoft Entra. These users can authenticate to Kerberos-based applications only through passwordless authentication using the provisioned AD account.
The on-premises access guidance now links to a Microsoft Entra Cloud Sync how-to page for provisioning groups to Active Directory.
The guide now focuses on phased transitions of user and group source of authority to Microsoft Entra ID while maintaining application access. It also updates readiness content and LDAP-binding application guidance, including provisioning cloud-managed users and groups back to on-premises AD or using Microsoft Entra Domain Services.
The page’s subservice metadata changed to hybrid-cloud-sync, and the listed reviewer changed.
The guide now states that users without a registered or enrolled device are prompted to register it, and documents a different message for users who have not installed the latest September 2026 Windows update.
The guidance now links to a different Microsoft Entra Cloud Sync configuration page for provisioning groups to Active Directory Domain Services.
The licensing table now covers guests disabled or deleted by lifecycle policies, sponsor attestations, and users sponsoring new guests. It also lists the related beta API endpoints for attestation and sponsorship.
Security Copilot is now included with Microsoft 365 E5/E7 plans, integrating agents across Defender, Entra, Intune, Purview, and its portal. No purchase or action is needed. Organizations get monthly Security Compute Units, developer tools, and can explore additional paid features or opt out by contacting support.