MC1488834 - Microsoft Entra ID: Final reminder to replace MemberOf rule operator configurations by November 3, 2026

Message Center

Summary

Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations must replace MemberOf in dynamic groups, administrative units, and entitlement policies to avoid outdated memberships, access, and licensing issues. After this date, MemberOf-based updates will stop, impacting Conditional Access and related services.

Published

Oct 5, 2026

Service

Microsoft Entra

Tag

User impact
Admin impact
Retirement

Act by

Nov 3, 2026

More information

What and why

As previously announced in MC1448379 (August 5, 2026), the public preview of the MemberOf rule operator in Microsoft Entra ID is ending. Organizations using MemberOf in dynamic membership groups, dynamic administrative units (AUs), or entitlement management auto-assignment policies must replace these configurations by November 3, 2026.

Microsoft continues to improve the scale and reliability of dynamic membership processing. During the preview, Microsoft observed that use of MemberOf can affect dynamic membership processing across a tenant, even when only a single MemberOf rule is present. Because of this limitation, the preview functionality is being retired and is not recommended for production use.

Rollout schedule

  • Retirement date (Worldwide): November 3, 2026
  • Action required by: November 3, 2026

Impact on your organization

Who is affected

  • Organizations using the MemberOf rule operator in:
  • Dynamic membership groups
  • Dynamic administrative units (AUs)
  • Entitlement management auto-assignment policies

Platforms and services

  • Microsoft Entra ID
  • Microsoft Entra Groups
  • Microsoft Entra Administrative Units
  • Microsoft Entra Entitlement Management
  • Group-based licensing
  • Conditional Access configurations that rely on dynamic group membership

What will happen

Beginning November 3, 2026:

  • Dynamic groups using MemberOf will stop processing membership changes.
  • Dynamic administrative units using MemberOf will stop updating membership and administrative scope.
  • Entitlement management auto-assignment policies using MemberOf will stop processing assignment updates.
  • Existing membership and assignment data will remain in their last known state.
  • New users may not receive required access or licenses.
  • Former users may retain access or licenses that should have been removed.
  • Conditional Access policies may rely on outdated group membership.
  • Teams, SharePoint, and other applications that depend on dynamic group membership may receive outdated membership information.
  • Group-based licensing assignments may no longer reflect current user eligibility.

Action required and recommendations

Complete the following actions before November 3, 2026.

Dynamic membership groups:

  • Export dynamic membership groups from the Microsoft Entra admin center and identify rules containing MemberOf.
  • Replace MemberOf with supported rule operators where possible.
  • Convert groups to assigned membership if a supported dynamic rule alternative is not available.
  • Validate membership results after making changes.
  • Remove groups that are no longer required.

Dynamic administrative units:

  • Use Microsoft Graph PowerShell to identify dynamic administrative units that use MemberOf rules.
  • Replace MemberOf-based rules with supported rule operators where possible.
  • Convert administrative units to assigned membership if necessary.
  • Validate both membership and administrative scope after making changes.
  • Remove administrative units that are no longer required.

Entitlement Management auto-assignment policies:

  • Use Microsoft Graph PowerShell to identify auto-assignment policies that use MemberOf.
  • Replace MemberOf-based policies with supported operators where possible.
  • Plan an alternate assignment approach if no equivalent rule is available.
  • Validate access package assignments after making changes.

Learn more

Compliance considerations

QuestionAnswer
Does the change alter how existing customer data is processed, stored, or accessed (for example, documents, emails, chats, identities, or group memberships)?Yes. After November 3, 2026, configurations that use the MemberOf rule operator will stop updating membership and assignment information. Existing membership and assignment data will remain in its last known state, which may result in outdated access, licensing assignments, Conditional Access targeting, administrative scope, and entitlement assignments.
Does the change modify, interrupt, or disable Conditional Access policies?Yes. Conditional Access policies that rely on dynamic groups using the MemberOf rule operator may no longer receive updated group membership information after retirement. Organizations should review and update affected configurations before November 3, 2026.