What and why
As previously announced in MC1448379 (August 5, 2026), the public preview of the MemberOf rule operator in Microsoft Entra ID is ending. Organizations using MemberOf in dynamic membership groups, dynamic administrative units (AUs), or entitlement management auto-assignment policies must replace these configurations by November 3, 2026.
Microsoft continues to improve the scale and reliability of dynamic membership processing. During the preview, Microsoft observed that use of MemberOf can affect dynamic membership processing across a tenant, even when only a single MemberOf rule is present. Because of this limitation, the preview functionality is being retired and is not recommended for production use.
Rollout schedule
- Retirement date (Worldwide): November 3, 2026
- Action required by: November 3, 2026
Impact on your organization
Who is affected
- Organizations using the MemberOf rule operator in:
- Dynamic membership groups
- Dynamic administrative units (AUs)
- Entitlement management auto-assignment policies
Platforms and services
- Microsoft Entra ID
- Microsoft Entra Groups
- Microsoft Entra Administrative Units
- Microsoft Entra Entitlement Management
- Group-based licensing
- Conditional Access configurations that rely on dynamic group membership
What will happen
Beginning November 3, 2026:
- Dynamic groups using MemberOf will stop processing membership changes.
- Dynamic administrative units using MemberOf will stop updating membership and administrative scope.
- Entitlement management auto-assignment policies using MemberOf will stop processing assignment updates.
- Existing membership and assignment data will remain in their last known state.
- New users may not receive required access or licenses.
- Former users may retain access or licenses that should have been removed.
- Conditional Access policies may rely on outdated group membership.
- Teams, SharePoint, and other applications that depend on dynamic group membership may receive outdated membership information.
- Group-based licensing assignments may no longer reflect current user eligibility.
Action required and recommendations
Complete the following actions before November 3, 2026.
Dynamic membership groups:
- Export dynamic membership groups from the Microsoft Entra admin center and identify rules containing MemberOf.
- Replace MemberOf with supported rule operators where possible.
- Convert groups to assigned membership if a supported dynamic rule alternative is not available.
- Validate membership results after making changes.
- Remove groups that are no longer required.
Dynamic administrative units:
- Use Microsoft Graph PowerShell to identify dynamic administrative units that use MemberOf rules.
- Replace MemberOf-based rules with supported rule operators where possible.
- Convert administrative units to assigned membership if necessary.
- Validate both membership and administrative scope after making changes.
- Remove administrative units that are no longer required.
Entitlement Management auto-assignment policies:
- Use Microsoft Graph PowerShell to identify auto-assignment policies that use MemberOf.
- Replace MemberOf-based policies with supported operators where possible.
- Plan an alternate assignment approach if no equivalent rule is available.
- Validate access package assignments after making changes.
Learn more
Compliance considerations
| Question | Answer |
| Does the change alter how existing customer data is processed, stored, or accessed (for example, documents, emails, chats, identities, or group memberships)? | Yes. After November 3, 2026, configurations that use the MemberOf rule operator will stop updating membership and assignment information. Existing membership and assignment data will remain in its last known state, which may result in outdated access, licensing assignments, Conditional Access targeting, administrative scope, and entitlement assignments. |
| Does the change modify, interrupt, or disable Conditional Access policies? | Yes. Conditional Access policies that rely on dynamic groups using the MemberOf rule operator may no longer receive updated group membership information after retirement. Organizations should review and update affected configurations before November 3, 2026. |