← Previous day

Next day →
Day in brief

7 October was documentation-led, with Source of Authority guidance as the clearest substantive Entra ID update

Microsoft Entra ID updates centered on a related Source of Authority (SOA) documentation refresh. The clearest guidance describes moving group authority to Entra ID, removing AD DS groups no longer needed, and using security group provisioning back to AD DS when an on-premises group must remain. The architecture material also calls out applications that depend on LDAP access to AD. Other actionable edits clarify named-location handling of unmapped IPs, disabled Conditional Access policy cleanup, and soft versus hard deletion recovery. All supplied records are documentation updates; the evidence does not establish a named preview, general availability release, retirement, or service-behavior change. The two External ID entries contain only tip markers, so no specific External ID capability change can be established.

  • An updated Entra ID Source of Authority overview says converting Group SOA to Microsoft Entra ID lets administrators manage groups in the cloud and delete AD DS groups that are no longer needed. If a group must remain on-premises, the guidance describes using security group provisioning from Entra ID to AD DS so cloud changes are reflected there. This is updated architecture guidance, not evidence of a new availability event or changed tenant behavior.

  • The updated Entra ID architect guidance identifies custom-developed and third-party applications that point LDAP settings at AD and either bind or query the directory, or prompt users for AD credentials. This is a dependency to account for when assessing SOA or AD DS changes; the supplied evidence does not say that LDAP authentication behavior changed.

  • Entra ID assignment and network guidance says IPs that cannot be mapped to a specific country or region can be captured in a geographic named location by selecting Include unknown countries/regions. A Conditional Access policy using that named location can then apply to those addresses. This is a documentation clarification, with no evidence of a changed default; review location-based policies where unmapped IPs matter.

  • The updated Plan Conditional Access guidance says that a policy which is disabled and no longer needed should be deleted. This is policy-lifecycle and security-hygiene guidance, not evidence of automatic deletion or a change to disabled-policy behavior.

  • The updated Entra ID recovery page explains the distinction between soft and hard deletions and how to recover or recreate objects. It is operational documentation; the supplied summary identifies no new recovery capability or altered service behavior. Administrators responsible for object lifecycle should use the distinction when checking recovery procedures.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

14 updates

4

Source Of Authority Overview

Updated

One AD DS minimization approach is to convert the Group Source of Authority (SOA) to Microsoft Entra ID. This approach lets you directly manage those groups in the cloud. You can delete AD DS groups that you no longer need on-premises. If you need to keep a group on-premises, you can configure security group provisioning from Microsoft Entra ID to AD DS. Then you can make changes to the group in Microsoft Entra ID and have those changes reflected in the on-premises group.

Assignment Network

Updated

Some IP addresses can't be mapped to a specific country or region. To capture these IP locations, select the box **Include unknown countries/regions** when defining a geographic location. This option allows you to choose if these IP addresses should be included in the named location. Use this setting when the policy using the named location should apply to unknown locations.

2

Guidance It Architects Source Of Authority

Updated

- **LDAP Authentication/Queries** – Applications can have LDAP server settings pointing to AD and perform binds or lookups, custom-developed or third-party products prompting users for AD credentials.

2

User Source Of Authority Configure

Updated

:::image type="content" source="media/how-to-user-source-of-authority-configure/try-update.png" alt-text="Screenshot of an attempt to update a user to verify it's read-only.":::

2
1
1
2
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…