Microsoft 365 Message Center item MC1448379

MC1448379 - Microsoft Entra ID: Replace MemberOf rules by November 3, 2026

Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations using MemberOf in dynamic groups, administrative units, or entitlement policies must replace these rules to avoid stale access, licensing, and policy enforcement issues. Review and update configurations before the deadline.

Message Center ID
MC1448379
Category
plan For Change
Severity
normal
Services
Microsoft Entra
Tags
User impact, Admin impact, Retirement
Published
2026-08-05
Last updated
2026-08-05
Expires
2026-12-03
Action required by
2026-11-03

What and whyThe public preview of the MemberOf rule operator in Microsoft Entra ID is ending. Organizations using MemberOf in dynamic membership groups, dynamic administrative units (AUs), or entitlement management auto-assignment policies must replace these configurations by November 3, 2026.Microsoft continues improving the scale and reliability of dynamic membership processing. During preview, Microsoft observed that use of MemberOf can affect dynamic membership processing across a tenant even if you have one MemberOf rule operator in your tenant. Because of this limitation, it is not recommended for production use and will be retired.Rollout scheduleRetirement (Worldwide): Beginning in early November 2026Action required by: November 3, 2026Impact on your organizationWho is affectedOrganizations using the MemberOf rule operator in:Dynamic membership groupsDynamic administrative units (AUs)Entitlement management auto-assignment policiesPlatforms and servicesMicrosoft Entra IDMicrosoft Entra GroupsMicrosoft Entra Administrative UnitsMicrosoft Entra Entitlement ManagementWhat will happenIf no action is taken, configurations that use the MemberOf operator will stop updating after November 3, 2026. Membership and assignment data will remain in their last known state, which can lead to stale access and enforcement gaps.Potential impacts include:Teams and SharePoint access associated with Microsoft 365 groups may become outdated. New members may not receive access, while removed members may retain access.Conditional Access policies may no longer reflect current user or device membership.Entitlement Management auto-assignment policies may no longer add or remove access package assignments as intended.Group-based licensing may stop assigning or removing licenses correctly, resulting in unlicensed or overlicensed users.Dynamic administrative unit membership and scope may become outdated.Action required and recommendationsBefore November 3, 2026, review all uses of the MemberOf operator and remove or replace those configurations.Dynamic membership groupsExport dynamic membership groups from the Microsoft Entra admin center and identify rules containing MemberOf.Replace MemberOf with supported rule operators or convert the group to assigned membership.Validate group membership after making changes.If the group is no longer needed, consider pausing or deleting it.Dynamic administrative unitsUse Microsoft Graph PowerShell to identify dynamic administrative units that use MemberOf rules.Replace MemberOf-based rules with supported rule operators or convert the administrative unit to assigned membership.Validate both membership and administrative scope after making changes.If the administrative unit is no longer needed, consider deleting it.Entitlement Management auto-assignment policiesUse Microsoft Graph PowerShell to identify auto-assignment policies that use MemberOf.Replace MemberOf-based policies with supported operators where possible.If no equivalent rule is available, plan an alternative assignment method before retirement.Validate access package assignments after making changes.Learn moreConfigure an automatic assignment policy for an access package in entitlement management | Microsoft Entra ID Governance | Microsoft Entra | Microsoft LearnConfigure dynamic membership groups with the memberOf attribute in the Entra admin center | Users | Microsoft Entra ID | Microsoft Entra | Microsoft LearnCreate simpler, more efficient rules for dynamic membership groups in Microsoft Entra ID | Users | Microsoft Entra ID | Microsoft Entra | Microsoft LearnManage users or devices for an administrative unit with rules for dynamic membership groups | Role-based access control | Microsoft Entra ID | Microsoft Entra | Microsoft LearnCompliance considerationsConfigurations that rely on MemberOf for access management, licensing, entitlement management, Conditional Access targeting, or administrative scoping may stop updating after retirement. Review affected configurations to ensure continued compliance and access governance after November 3, 2026.