ACTION REQUIRED · MICROSOFT ENTRA ID
Microsoft Entra ID MemberOf Changes: What Organizations Need to Do Before November 3, 2026
Microsoft is ending the public preview of the MemberOf rule operator. Organizations using it in dynamic groups, administrative units or Entitlement Management should identify affected configurations and migrate them before the deadline.
EXECUTIVE SUMMARY
A preview feature is reaching an important deadline.
Microsoft has announced that the public preview of the MemberOf rule operator in Microsoft Entra ID is ending.
After November 3, 2026, affected dynamic membership groups and dynamic administrative units using MemberOf will stop updating and remain in their last known state.
Entitlement Management automatic assignment policies using MemberOf are also affected. Microsoft states that assignment processing will stop until MemberOf is removed from the rule.
WHAT IS CHANGING?
Understanding the MemberOf rule operator
The MemberOf preview allows administrators to create dynamic membership configurations based on membership of other groups.
For example, an organization could create a dynamic group whose membership is populated from one or more existing source groups rather than relying entirely on user or device attributes.
user.memberof -any (group.objectId -in ['groupId'])
Microsoft has treated MemberOf as a preview capability and documented limitations around its use. Organizations that adopted it should now migrate affected configurations.
WHO IS AFFECTED?
Three areas require attention.
Dynamic Membership Groups
Dynamic user or device groups with membership rules containing MemberOf should be identified and migrated.
Dynamic Administrative Units
Administrative units using MemberOf-based dynamic membership require replacement logic or conversion to assigned membership.
Entitlement Management
Access package automatic assignment policies whose membership rules use MemberOf must also be reviewed.
WHY THIS MATTERS
The risk is not simply that a rule becomes unsupported.
The larger concern is that membership can remain frozen in its last known state. When groups or administrative scopes influence access and operations, stale membership can create unexpected consequences.
WHAT ORGANIZATIONS SHOULD DO
Don't wait until November to discover the dependency.
The priority should be discovery first, followed by replacement design, controlled migration and validation.
Identify dynamic groups, dynamic administrative units and Entitlement Management automatic assignment policies whose rules contain MemberOf.
Document where the resulting membership is used and what could be affected if that membership becomes stale.
Where possible, rebuild the requirement using supported user or device attributes and supported dynamic membership operators. If dynamic logic is not appropriate, consider assigned membership or another controlled assignment process.
Compare expected membership with the replacement configuration and investigate differences before moving the new approach into production.
After migration, verify not only group membership but also the applications, resources, administrative scopes and access packages that depend on it.
Once the replacement is validated, retire MemberOf dependencies that are no longer required and document the new ownership and operating process.
NOAVAXIS RECOMMENDATION
Treat this as an identity dependency review, not just a rule edit.
Replacing MemberOf syntax without understanding where the resulting groups are used can move the problem rather than solve it.
Start by mapping the dependency: rule → membership → access or administrative function → business owner. Then design and test the replacement against the actual business requirement.
BEYOND THE DEADLINE
Identity configurations need ongoing ownership.
Microsoft cloud environments continuously change. Preview features mature or retire, business structures change, applications are introduced and access requirements evolve.
Organizations should maintain clear ownership for dynamic membership rules, periodically review whether those rules still reflect the intended business requirement and monitor Microsoft platform changes that affect identity and access.
MICROSOFT ENTRA ID REVIEW
Unsure whether your environment depends on MemberOf?
NOAVAXIS can help identify affected Microsoft Entra configurations, assess their dependencies and build a practical remediation plan before the November deadline.
Talk to NOAVAXIS