Unique Logo Interpretations for NOVAXIS TECHNOLOGY (5)
NOAVAXIS Technology

ACTION REQUIRED · MICROSOFT ENTRA ID

Microsoft Entra ID MemberOf Changes: What Organizations Need to Do Before November 3, 2026

Microsoft is ending the public preview of the MemberOf rule operator. Organizations using it in dynamic groups, administrative units or Entitlement Management should identify affected configurations and migrate them before the deadline.

Published: September 28, 2026   ·   NOAVAXIS Technology Intelligence

EXECUTIVE SUMMARY

A preview feature is reaching an important deadline.

Microsoft has announced that the public preview of the MemberOf rule operator in Microsoft Entra ID is ending.

After November 3, 2026, affected dynamic membership groups and dynamic administrative units using MemberOf will stop updating and remain in their last known state.

Entitlement Management automatic assignment policies using MemberOf are also affected. Microsoft states that assignment processing will stop until MemberOf is removed from the rule.

Deadline: November 3, 2026 Organizations should identify every configuration that depends on MemberOf, design a supported replacement and validate the resulting membership and access before the deadline.

WHAT IS CHANGING?

Understanding the MemberOf rule operator

The MemberOf preview allows administrators to create dynamic membership configurations based on membership of other groups.

For example, an organization could create a dynamic group whose membership is populated from one or more existing source groups rather than relying entirely on user or device attributes.

EXAMPLE MEMBEROF RULE
user.memberof -any (group.objectId -in ['groupId'])

Microsoft has treated MemberOf as a preview capability and documented limitations around its use. Organizations that adopted it should now migrate affected configurations.

WHO IS AFFECTED?

Three areas require attention.

01

Dynamic Membership Groups

Dynamic user or device groups with membership rules containing MemberOf should be identified and migrated.

02

Dynamic Administrative Units

Administrative units using MemberOf-based dynamic membership require replacement logic or conversion to assigned membership.

03

Entitlement Management

Access package automatic assignment policies whose membership rules use MemberOf must also be reviewed.

WHY THIS MATTERS

The risk is not simply that a rule becomes unsupported.

The larger concern is that membership can remain frozen in its last known state. When groups or administrative scopes influence access and operations, stale membership can create unexpected consequences.

Stale Access Users who should leave a group might remain members when membership stops updating.
Access Gaps Users who should receive access may not be added as business roles and attributes change.
Administrative Scope Dynamic administrative-unit membership may no longer reflect the intended administrative boundary.
Entitlement Processing MemberOf-based automatic assignment policies can stop adding and removing access-package assignments.

WHAT ORGANIZATIONS SHOULD DO

Don't wait until November to discover the dependency.

The priority should be discovery first, followed by replacement design, controlled migration and validation.

1. Inventory MemberOf usage

Identify dynamic groups, dynamic administrative units and Entitlement Management automatic assignment policies whose rules contain MemberOf.

2. Understand what each configuration controls

Document where the resulting membership is used and what could be affected if that membership becomes stale.

3. Design supported replacement logic

Where possible, rebuild the requirement using supported user or device attributes and supported dynamic membership operators. If dynamic logic is not appropriate, consider assigned membership or another controlled assignment process.

4. Test before replacing production rules

Compare expected membership with the replacement configuration and investigate differences before moving the new approach into production.

5. Validate access and administrative scope

After migration, verify not only group membership but also the applications, resources, administrative scopes and access packages that depend on it.

6. Remove obsolete configurations

Once the replacement is validated, retire MemberOf dependencies that are no longer required and document the new ownership and operating process.

NOAVAXIS RECOMMENDATION

Treat this as an identity dependency review, not just a rule edit.

Replacing MemberOf syntax without understanding where the resulting groups are used can move the problem rather than solve it.

Start by mapping the dependency: rule → membership → access or administrative function → business owner. Then design and test the replacement against the actual business requirement.

Recommended timeline Begin discovery now. Allow enough time before November 3 for replacement design, testing, stakeholder validation and remediation rather than treating the deadline as the migration date.

BEYOND THE DEADLINE

Identity configurations need ongoing ownership.

Microsoft cloud environments continuously change. Preview features mature or retire, business structures change, applications are introduced and access requirements evolve.

Organizations should maintain clear ownership for dynamic membership rules, periodically review whether those rules still reflect the intended business requirement and monitor Microsoft platform changes that affect identity and access.

MICROSOFT ENTRA ID REVIEW

Unsure whether your environment depends on MemberOf?

NOAVAXIS can help identify affected Microsoft Entra configurations, assess their dependencies and build a practical remediation plan before the November deadline.

Talk to NOAVAXIS
```