Entitlement Management Access Package Auto Assignment Policy
In brief
The documentation now clarifies that multiple automatic assignment policies for one access package are supported only when users do not match multiple policies simultaneously.
What Entra admins need to know
Review overlapping policy scopes to avoid assigning the same users through multiple policies.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
You can use rules to determine access package assignment based on identity properties in Microsoft Entra ID, part of Microsoft Entra. In Entitlement Management, an access package can have multiple policies, and each policy establishes how identities get an assignment to the access package, and for how long. As an administrator, you can establish a policy for automatic assignments by supplying a membership rule, that Entitlement Management follows to create and remove assignments automatically. Similar to a dynamic group, when an automatic assignment policy is created, identity attributes are evaluated for matches with the policy's membership rule. When an attribute changes for an identity, these automatic assignment policy rules in the access packages are processed for membership changes. Assignments to identities are then added or removed depending on whether they meet the rule criteria.
@@ -14,7 +14,7 @@ ai-usage: ai-assisted You can use rules to determine access package assignment based on identity properties in Microsoft Entra ID, part of Microsoft Entra. In Entitlement Management, an access package can have multiple policies, and each policy establishes how identities get an assignment to the access package, and for how long. As an administrator, you can establish a policy for automatic assignments by supplying a membership rule, that Entitlement Management follows to create and remove assignments automatically. Similar to a [dynamic group](../identity/users/groups-create-rule.md), when an automatic assignment policy is created, identity attributes are evaluated for matches with the policy's membership rule. When an attribute changes for an identity, these automatic assignment policy rules in the access packages are processed for membership changes. Assignments to identities are then added or removed depending on whether they meet the rule criteria. > [!NOTE]- > It is suggested to only use one automatic assignment policy per access package. Configuring more than one auto-assignment policy is supported ONLY if you ensure there is no overlap with users in scope for each policy. If a user matches more than one automatic assignment policy, this is not supported and there may be subsequent problems losing access should a user fall out of scope of one policy but not the other.+ > It is suggested to only use one automatic assignment policy per access package. Configuring more than one automatic assignment policy is supported ONLY if you ensure there is no overlap with users in scope for each policy. This includes ensuring that users do not match multiple policies at the same time and do not transition from the scope of one policy to another. If a user matches more than one automatic assignment policy, or transitions from one policy to another, this is not supported and there may be subsequent problems losing access. > [!IMPORTANT] > The preview of the `memberOf` rule operator is ending. Starting November 3, 2026, automatic assignment policies whose membership rule uses `memberOf` are quarantined. The policies remain, but assignment processing stops, and no assignments are added or removed until you remove `memberOf` from the rule. Before November 3, 2026, [identify the policies that use the memberOf attribute](#find-automatic-assignment-policies-that-use-the-memberof-attribute) and rebuild each rule with a supported attribute-based operator. If no equivalent rule covers your scenario, plan an alternative assignment method before you remove the policy that contains the rule, so that assignments aren't dropped. Automatic assignment policies that don't use `memberOf` aren't affected. For more information, see [Configure dynamic membership groups with the memberOf attribute](../identity/users/groups-dynamic-rule-member-of.md). 