Microsoft Entra ID
Fundamentals

Guidance for using Group Source of Authority (SOA) in Microsoft Entra ID

In brief

The guidance now links to updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory and nested-group membership behavior. Page metadata was also refreshed.

What Entra admins need to know

Administrators consulting this guidance should use the updated references; no required action is stated.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Guidance for using Group Source of Authority (SOA)

  1. Convert the Source of Authority (SOA) when ready.
  2. Use custom expressions to ensure Cloud Sync provisions groups back to AD DS with the same CN and OU values.

For more information, see Provision groups to Active Directory Domain Services by using Microsoft Entra Cloud SyncProvision groups to Active Directory Domain Services by using Microsoft Entra Cloud Sync.

Transition group management

Then you start to manage group memberships in Microsoft Entra ID for the converted CloudGroupB. You provision it as a nested group within the on-premises group OnPremGroupA. If OnPremGroupA remains in-scope for sync, when the AD DS to Microsoft Entra ID sync configuration runs for OnPremGroupA, the membership reference for CloudGroupB doesn't sync. By design, the sync client doesn't recognize the cloud group membership references.

For more information about how group sync works with SOA in similar use cases,information, see Nested Groups and membership references handlingHow provisioning to Active Directory works.

How SOA applies to nested groups

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…