The article was rewritten for provisioning groups from Microsoft Entra ID to Active Directory, adding updated setup steps, screenshots, and sections for scoping, attribute mapping, testing, and default settings. Previous combined users-and-groups guidance was removed, and a deprecation notice was added.
Cloud Sync group guidance adds explicit membership rules and five-member tests
The week’s Entra changes are chiefly a reorganization of Microsoft Entra Cloud Sync guidance around group provisioning to AD DS. A new tutorial and rewritten setup articles separate group workflows from older users-and-groups material; the planning page now documents which members and identifiers cloud-synced groups require, while on-demand testing guidance tells administrators to select a group and up to five members. Seven older pages were removed, including references for prerequisites, general provisioning behavior, and test-and-enable operations.
- New tutorial centers Cloud Sync on group provisioning to AD DS
Entra ID · Provisioning
The new tutorial covers Entra-to-AD and AD-to-Entra scenarios and explains how source of authority and membership affect provisioning. It recommends Selected security groups as the default scoping filter to help prevent performance issues.
- Cloud Sync topology guidance records explicit group membership requirements
Entra ID · Provisioning
The guidance states that cloud-synced groups can contain only on-premises synchronized users and additional cloud-created security groups, and that all users must have `onPremisesObjectIdentifier`. The example link and diagram descriptions were also updated.
- On-demand provisioning guidance now tests groups with up to five members
Entra ID · Provisioning
The revised procedure tells administrators to select a group and up to five members for testing. User-specific instructions and result-review details were removed, and provisioning-direction references now point to Microsoft Entra ID-to-Active Directory guidance.
- Cloud Sync setup guidance is rewritten for group provisioning workflows
Entra ID · Provisioning
The configure article was rewritten with setup steps, screenshots, scoping, attribute mapping, testing, and default settings for provisioning groups from Microsoft Entra ID to Active Directory. It removes the previous combined users-and-groups guidance and adds a deprecation notice.
- The Cloud Sync test-and-enable reference was deleted
Entra ID · Provisioning
The how-to page for testing and enabling Microsoft Entra ID-to-Active Directory provisioning was removed, including guidance on on-demand tests, default properties, enabling configurations, quarantines, restarting synchronization, and removing configurations.
Review group-provisioning designs and runbooks against the updated membership conditions and group-focused setup. For on-demand tests, select group members manually, up to five. Teams relying on deleted prerequisite or test-and-enable pages will need current Cloud Sync references; the supplied updates state no mandatory configuration change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
17 updatesPlan Cloud Sync Topologies
Feature updateThe documentation now states that cloud-synced groups can contain only on-premises synchronized users and additional cloud-created security groups, and that all users must have `onPremisesObjectIdentifier`. The example link and diagram descriptions were also updated.
The article now describes extending a group schema attribute and using it to filter groups provisioned to Active Directory. It replaces the previous combined users-and-groups examples with a group-focused scenario and setup instructions.
A new tutorial explains how to configure Microsoft Entra Cloud Sync to provision groups to on-premises AD DS. It covers Entra-to-AD and AD-to-Entra scenarios, including how source of authority and membership affect provisioning.
The 246-line tutorial for provisioning cloud-managed users and groups to Active Directory with Microsoft Entra Cloud Sync was deleted. It covered preview user provisioning for access to an on-premises Kerberos application.
The article now documents selecting a group and up to five members for testing. User-specific instructions and result-review details were removed, and provisioning-direction references were updated.
The article was retitled and updated to focus on provisioning directory extensions to Active Directory with Cloud Sync, including group schema, scoping, and attribute mapping. Links now point to updated Cloud Sync resources and a group-provisioning scenario.
On Demand Provision
Doc updateThe article’s introduction now describes on-demand provisioning from Microsoft Entra ID to Active Directory and links to related guidance.
The article explaining how Microsoft Entra Cloud Sync provisions users, groups, and memberships to Active Directory was deleted.
The article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises Active Directory with Cloud Sync was deleted, along with its related links and next-step guidance.
The how-to page for testing and enabling Microsoft Entra ID to Active Directory provisioning was deleted, including guidance on on-demand tests, default properties, enabling configurations, quarantines, restarting sync, and removing configurations.
Group Source Of Authority Guidance
Doc updateThe guidance now links to the group provisioning tutorial and its updated section on nested groups and membership references.
The article comparing group-only, user-only, and users-and-groups provisioning from Microsoft Entra ID to Active Directory was deleted, including guidance on scoping, configuration limits, and performance.
Provision Entra Id To Active Directory
Doc updateThe documentation page describing Microsoft Entra Cloud Sync provisioning of users, groups, and memberships from Entra ID to Active Directory was deleted.
The article describing the preview GroupDN setup for preserving a group’s organizational unit and name during Source of Authority conversion was deleted.
Group Source Of Authority Configure
Doc updateThe documentation now points administrators to the Microsoft Entra Cloud Sync tutorial for provisioning groups to Active Directory Domain Services, replacing the previous provisioning overview and on-premises app governance links.
Protect M365 From On Premises Attacks
Doc updateThe Access guidance now points to an updated Microsoft Entra Cloud Sync documentation link for provisioning groups to Active Directory.
Microsoft Entra ID Governance
2 updatesRoad To The Cloud Implement
Doc updateThe documentation now links to the Microsoft Entra Cloud Sync group provisioning tutorial instead of the configuration guide.
Source Of Authority Overview
Doc updateThe guidance for recreating AD DS groups as cloud security groups, provisioning them as Universal groups, and updating applications to use their new security identifiers was revised.
