← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Entra Cloud Sync guidance details preview user and GA group provisioning to AD

Cloud Sync dominates the period: new Microsoft Entra guidance describes provisioning users and groups from Microsoft Entra ID to on-premises AD DS, with group provisioning generally available and user provisioning in preview. The new material also covers provisioning modes, object matching and lifecycle behavior, prerequisites, targeted testing, and a Kerberos application scenario. Separate notices record an Entra Connect 2.6.92.0 fix, a Chatwork SCIM cutoff on October 1, and Security Copilot inclusion in Microsoft 365 E5/E7 plans.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

36 updates

13

Tutorial: Govern access to an on-premises app (Preview)

New feature

The new tutorial explains how to provision cloud-managed users, a security group, and its membership into AD DS so members can access an on-premises Kerberos application. User provisioning is identified as being in preview.

Plan Cloud Sync Topologies

Doc update

The page updates diagram descriptions and explains that provisioned group members must have an AD account. Eligible members include synchronized users, cloud-managed users in scope for user provisioning, and cloud-created security groups. The provisioning example link was also updated.

Microsoft Entra provisioning behavior (Preview)

Doc update

The article documents how Cloud Sync scopes, matches, creates, updates, and deletes users, groups, and memberships in Active Directory, including matching with msDS-ExternalDirectoryObjectId and user source-of-authority scenarios.

Microsoft Entra provisioning setup (Preview)

New feature

The article expands beyond group-only provisioning to explain provisioning users, groups, or both from Microsoft Entra ID to on-premises AD DS. It adds prerequisites, deployment options, scoping filters, target containers, and attribute-mapping guidance; user-related options are marked Preview.

Test Microsoft Entra provisioning (Preview)

New feature

A new preview how-to explains on-demand testing for users and groups, default accidental-delete and email settings, enabling configurations, handling quarantines, restarting sync, and removing configurations.

Microsoft Entra prerequisites for AD (Preview)

New featureAction required

A new article documents prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS using Cloud Sync. It also links to configuration, testing, deployment, and agent setup guidance.

Use directory extensions when provisioning to Active Directory

Doc update

The tutorial now covers provisioning both users and groups from Microsoft Entra ID to Active Directory. It adds examples for filtering groups by an extension value and mapping a user extension into an Active Directory attribute, along with updated prerequisites and guidance.

On-demand provisioning - Microsoft Entra ID to Active Directory

Doc update

The guide now documents testing individual users or groups when provisioning from Microsoft Entra ID to Active Directory. It adds steps for selecting objects, selecting up to five group members, and reviewing detailed results, retries, and additional tests.

On Demand Provision

Doc update

The article now states that it covers on-demand provisioning from Active Directory to Microsoft Entra ID and links to a separate article for provisioning in the reverse direction.

Tutorial Group Provisioning

Doc update

The tutorial for provisioning groups to AD DS with Microsoft Entra Cloud Sync was deleted, including its setup guidance, scoping recommendation, and group/user synchronization scenarios.

12

Migrate Group Writeback

Doc update

The group writeback migration documentation now links to the guidance for changing other attribute mappings.

Preserve a group's organizational unit (Preview)

New featureAction required

New preview documentation explains how to capture a group's distinguished name in a GroupDN extension before converting its Source of Authority to Microsoft Entra ID.

Connect Version History

Feature updateAction required

Version 2.6.92.0 was released on September 18, 2026, fixing a 2.6.91.0 issue that could prevent Pass-through Authentication setup through the Microsoft Entra Connect wizard.

Connect Version History

Doc updateAction required

The version history no longer states that the 09/23/2026 hotfix will be deployed through phased auto-upgrade. The Microsoft Graph permissions notice was repositioned.

Connect Version History

Doc update

The version history now lists release 2.6.92.0 as September 23, 2026, and the related 2.6.91.0 support date as September 23, 2027. The page metadata date was also updated.

Attribute Mapping

Doc update

The page’s Microsoft Entra ID-to-AD attribute mapping section was removed and its introductory link now points to the dedicated configuration guide.

Connect Version History

Feature update

The version history now states that auto-upgrade will move existing installations to the September 18, 2026 hotfix through multiple phases.

Attribute Mapping Entra To Active Directory

Doc update

The guide for provisioning from Microsoft Entra ID to Active Directory was removed. It covered attribute mappings, scoping filters, sAMAccountName customization, and target-container configuration.

5

Microsoft Entra provisioning options (Preview)

New feature

A new article explains groups-only, users-only, and users-and-groups provisioning from Microsoft Entra ID to AD DS. User provisioning is in preview, while group provisioning is generally available; it also documents per-domain configuration limits and performance guidance.

Provision Microsoft Entra ID objects to AD

New feature

The new overview describes how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to AD, including supported configurations, user types, attribute updates, enforcement, and provisioning flow. User provisioning is in preview, while group provisioning is generally available; password writeback isn't supported.

Transfer user SOA to Microsoft Entra ID

Doc update

The article now describes provisioning Microsoft Entra-managed users back to Active Directory with Cloud Sync so they can access Kerberos-based on-premises applications while their lifecycle is governed from the cloud. It also updates passwordless authentication guidance and diagrams.

Source Of Authority Overview

Doc update

The article’s introductory wording and references were updated, including the link to cloud-first identity management guidance. The described Group SOA and group replication steps remain unchanged.

1
1

Microsoft Entra cloud-first identity guidance

Doc update

The guide now focuses on phased transitions of user and group source of authority to Microsoft Entra ID while maintaining application access. It also updates readiness content and LDAP-binding application guidance, including provisioning cloud-managed users and groups back to on-premises AD or using Microsoft Entra Domain Services.

1
1

Road To The Cloud Implement

Doc update

The guidance now links to a different Microsoft Entra Cloud Sync configuration page for provisioning groups to Active Directory Domain Services.

1

Microsoft Entra Id Governance Licensing For Guest Users

Doc update

The licensing table now covers guests disabled or deleted by lifecycle policies, sponsor attestations, and users sponsoring new guests. It also lists the related beta API endpoints for attestation and sponsorship.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…