← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

New apps face COOP enforcement after January 31, 2027

Microsoft Entra guidance sets a January 31, 2027 milestone for COOP policy enforcement on new applications, while Cloud Sync guidance expands coverage of provisioning Microsoft Entra users and groups into AD DS. The period also brings a concrete ChatWork SCIM retirement date and documents an Entra Connect hotfix for a Pass-through Authentication setup issue.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

42 updates

13

Migrate Group Writeback

Doc update

The group writeback migration documentation now links to the guidance for changing other attribute mappings.

Preserve a group's organizational unit (Preview)

New featureAction required

New preview documentation explains how to capture a group's distinguished name in a GroupDN extension before converting its Source of Authority to Microsoft Entra ID.

Connect Version History

Feature updateAction required

Version 2.6.92.0 was released on September 18, 2026, fixing a 2.6.91.0 issue that could prevent Pass-through Authentication setup through the Microsoft Entra Connect wizard.

Prepare apps for Microsoft Entra COOP policy

Feature updateAction required

New applications will be subject to Microsoft Entra COOP policy across web protocols after January 31, 2027. Popup-based sign-in may fail unless apps use a COOP-compatible flow, such as MSAL.js v5.

Connect Version History

Doc updateAction required

The version history no longer states that the 09/23/2026 hotfix will be deployed through phased auto-upgrade. The Microsoft Graph permissions notice was repositioned.

Connect Version History

Doc update

The version history now lists release 2.6.92.0 as September 23, 2026, and the related 2.6.91.0 support date as September 23, 2027. The page metadata date was also updated.

Attribute Mapping

Doc update

The page’s Microsoft Entra ID-to-AD attribute mapping section was removed and its introductory link now points to the dedicated configuration guide.

Connect Version History

Feature update

The version history now states that auto-upgrade will move existing installations to the September 18, 2026 hotfix through multiple phases.

Attribute Mapping Entra To Active Directory

Doc update

The guide for provisioning from Microsoft Entra ID to Active Directory was removed. It covered attribute mappings, scoping filters, sAMAccountName customization, and target-container configuration.

13

Tutorial: Govern access to an on-premises app (Preview)

New feature

The new tutorial explains how to provision cloud-managed users, a security group, and its membership into AD DS so members can access an on-premises Kerberos application. User provisioning is identified as being in preview.

Plan Cloud Sync Topologies

Doc update

The page updates diagram descriptions and explains that provisioned group members must have an AD account. Eligible members include synchronized users, cloud-managed users in scope for user provisioning, and cloud-created security groups. The provisioning example link was also updated.

Microsoft Entra provisioning behavior (Preview)

Doc update

The article documents how Cloud Sync scopes, matches, creates, updates, and deletes users, groups, and memberships in Active Directory, including matching with msDS-ExternalDirectoryObjectId and user source-of-authority scenarios.

Microsoft Entra provisioning setup (Preview)

New feature

The article expands beyond group-only provisioning to explain provisioning users, groups, or both from Microsoft Entra ID to on-premises AD DS. It adds prerequisites, deployment options, scoping filters, target containers, and attribute-mapping guidance; user-related options are marked Preview.

Test Microsoft Entra provisioning (Preview)

New feature

A new preview how-to explains on-demand testing for users and groups, default accidental-delete and email settings, enabling configurations, handling quarantines, restarting sync, and removing configurations.

Microsoft Entra prerequisites for AD (Preview)

New featureAction required

A new article documents prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS using Cloud Sync. It also links to configuration, testing, deployment, and agent setup guidance.

Use directory extensions when provisioning to Active Directory

Doc update

The tutorial now covers provisioning both users and groups from Microsoft Entra ID to Active Directory. It adds examples for filtering groups by an extension value and mapping a user extension into an Active Directory attribute, along with updated prerequisites and guidance.

On-demand provisioning - Microsoft Entra ID to Active Directory

Doc update

The guide now documents testing individual users or groups when provisioning from Microsoft Entra ID to Active Directory. It adds steps for selecting objects, selecting up to five group members, and reviewing detailed results, retries, and additional tests.

On Demand Provision

Doc update

The article now states that it covers on-demand provisioning from Active Directory to Microsoft Entra ID and links to a separate article for provisioning in the reverse direction.

Tutorial Group Provisioning

Doc update

The tutorial for provisioning groups to AD DS with Microsoft Entra Cloud Sync was deleted, including its setup guidance, scoping recommendation, and group/user synchronization scenarios.

7

Microsoft Entra provisioning options (Preview)

New feature

A new article explains groups-only, users-only, and users-and-groups provisioning from Microsoft Entra ID to AD DS. User provisioning is in preview, while group provisioning is generally available; it also documents per-domain configuration limits and performance guidance.

Provision Microsoft Entra ID objects to AD

New feature

The new overview describes how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to AD, including supported configurations, user types, attribute updates, enforcement, and provisioning flow. User provisioning is in preview, while group provisioning is generally available; password writeback isn't supported.

Transfer user SOA to Microsoft Entra ID

Doc update

The article now describes provisioning Microsoft Entra-managed users back to Active Directory with Cloud Sync so they can access Kerberos-based on-premises applications while their lifecycle is governed from the cloud. It also updates passwordless authentication guidance and diagrams.

Provision Entra Id To Active Directory

Doc updateAction required

The guidance now specifies that password-based apps, including LDAP-authenticated apps, must be updated to Kerberos for cloud-managed users to use passwordless authentication.

Source Of Authority Overview

Doc update

The article’s introductory wording and references were updated, including the link to cloud-first identity management guidance. The described Group SOA and group replication steps remain unchanged.

Provision Entra Id To Active Directory

Doc update

The documentation now states that password writeback isn't supported for applications that collect passwords, including applications that authenticate users through an LDAP bind.

2

How Provisioning To Active Directory Works

Doc update

The documentation now identifies affected accounts as cloud-managed users and explains that password writeback is unavailable for them. It also states that they can access Kerberos-based applications through passwordless authentication using the AD account created by provisioning.

How Provisioning To Active Directory Works

Doc update

The documentation now specifies that password writeback isn't available for users created in Microsoft Entra. These users can authenticate to Kerberos-based applications only through passwordless authentication using the provisioned AD account.

1
1

Microsoft Entra cloud-first identity guidance

Doc update

The guide now focuses on phased transitions of user and group source of authority to Microsoft Entra ID while maintaining application access. It also updates readiness content and LDAP-binding application guidance, including provisioning cloud-managed users and groups back to on-premises AD or using Microsoft Entra Domain Services.

1
1

Token Protection Deployment Guide - Windows

Doc update

The guide now states that users without a registered or enrolled device are prompted to register it, and documents a different message for users who have not installed the latest September 2026 Windows update.

1

Road To The Cloud Implement

Doc update

The guidance now links to a different Microsoft Entra Cloud Sync configuration page for provisioning groups to Active Directory Domain Services.

1

Microsoft Entra Id Governance Licensing For Guest Users

Doc update

The licensing table now covers guests disabled or deleted by lifecycle policies, sponsor attestations, and users sponsoring new guests. It also lists the related beta API endpoints for attestation and sponsorship.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…