This feature preview in Microsoft Entra ID enables admins to create dynamic membership groups and administrative units that populate by adding members of other groups using the `memberOf` attribute. Apps that couldn't read group-based membership previously in Microsoft Entra ID can now read the entire membership of these new `memberOf` groups. Not only can these groups be used for apps but they can also be used for licensing assignments.
Documentation maintenance dominates; the Entra ID `memberOf` dynamic-group preview is the standout capability item
The 18 March record contains 42 updated items, with no new, removed, or Message Center entries. The most substantive item is updated documentation for an Entra ID feature preview that builds dynamic groups and administrative units from other groups. The other meaningful exceptions are an External ID account-lifecycle warning and Entra ID clarifications on naming policies and delegated administration. Nothing supplied establishes general availability, retirement, a rollout date, or a mandatory tenant change.
- Entra ID: `memberOf` dynamic groups are documented as a feature preview
Entra ID · General
The updated article describes a preview that lets administrators create dynamic membership groups and administrative units populated from members of other groups through the `memberOf` attribute. It also says applications can read the full membership of these groups and that the groups can be used for licensing assignments. This is preview documentation, not evidence of general availability or a tenant-wide rollout.
- Entra ID: groups naming-policy attribute limits are clarified
Entra ID · Developer
The naming-policy guidance explicitly lists six supported built-in user attributes: Department, Company, Office, StateOrProvince, CountryOrRegion, and Title. Unsupported attributes are treated as fixed strings, while extension attributes and custom attributes aren't supported. This is an ordinary documentation clarification rather than evidence of a product behavior change on 18 March.
- Entra ID: delegated-administration guidance explains CSP relationships and DAP/GDAP
Entra ID · Fundamentals
The updated article explains that the Microsoft Entra admin portal includes capabilities for administrators to see relationships with Microsoft Cloud Service Providers. It also distinguishes the older Delegated Admin Permissions (DAP) model from Granular Delegated Admin Permissions (GDAP). The supplied evidence provides no migration deadline or new-role announcement; the practical value is permissions and relationship review for CSP-managed tenants.
- External ID: legacy unmanaged accounts are flagged as a persistent-access cleanup concern
External ID · General
The updated cleanup guidance highlights that, before August 2022, email-verified self-service B2B sign-up could create accounts in unmanaged or “viral” tenants. Access can persist after users leave the organization. Organizations with this legacy scenario should assess whether unmanaged accounts remain and consult the cleanup guidance; the supplied summary does not specify a new cleanup mechanism or enforcement change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
44 updates
Microsoft Entra ID
43 updatesLearn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Users Bulk Download
Updated1. Select **Users** > **All users** > **Download users**. By default, all user profiles are exported.
Groups Dynamic Tutorial
UpdatedYou're not required to assign licenses to the users for them to be members in dynamic membership groups. You only need the minimum number of available Microsoft Entra ID P1 licenses in the organization to cover all such users.
Groups Quickstart Expiration
UpdatedExpiration policy is simple:
Learn how to manage rules for dynamic membership groups to automatically populate group members and rule references.
Learn how to test members against a rule for dynamic membership groups in Microsoft Entra ID.
Download group members in bulk in the Microsoft Entra admin center.
If you're performing these Microsoft 365 operations from 21Vianet:
Users Search Enhanced
UpdatedEnhancements include:
Users Bulk Delete
Updated> [!IMPORTANT]
Microsoft Entra ID, part of Microsoft Entra, supports bulk user create and delete operations and supports downloading lists of users. Just fill out the comma-separated values (CSV) template you can download from Microsoft Entra ID.
Groups Bulk Download
Updated:::image type="content" source="media/bulk-operations/groups-management-page.png" alt-text="Screenshot of the Microsoft Entra admin center Groups blade showing the All groups list with column headers and actions.":::
1. Select **External collaboration settings**.
You can use rules to determine dynamic membership groups based on user or device properties in Microsoft Entra ID. This article describes how to set up a rule for dynamic membership groups in the Azure portal.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).
Users Bulk Restore
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).
Groups Bulk Import Members
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).
If you're a user in an unmanaged organization (tenant) in Microsoft Entra ID, and you no longer need to use apps from that organization or maintain any association with it, you can close your account at any time. An unmanaged organization doesn't have an administrator. Users in an unmanaged organization can close their accounts on their own, without contacting an administrator.
> [!NOTE]
Learn how dynamic group management works.
You can remove a large number of members from a group by using a comma-separated values (CSV) file in the portal for Microsoft Entra ID.
Groups Change Type
UpdatedCreating dynamic membership groups eliminates the management overhead of adding and removing users. This article shows you how to convert existing membership groups from static to dynamic, by using either the Azure portal or PowerShell cmdlets. In Microsoft Entra, a single tenant can have a maximum of 15,000 dynamic membership groups.
Groups Members Owners Search
UpdatedOn the **All groups** page, when you enter a search string, you can toggle between **contains** and **starts with** searches on the **All groups** page only.
Groups Saasapps
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).
Usage constraints and other service limits for the Microsoft Entra service
Learn how to optimize your membership rules to automatically populate groups.
Global Administrator
UpdatedGlobal Administrator
Managing permissions for external partners is a key part of your security posture. The administrator portal experience in Microsoft Entra ID, part of Microsoft Entra, now includes capabilities so that an administrator can see the relationships that their Microsoft Entra tenant has with Microsoft Cloud Service Providers (CSP) who can manage the tenant. This permissions model is called delegated administration. This article introduces the Microsoft Entra administrator to the relationship between the old Delegated Admin Permissions (DAP) permission model and the new [Granular Delegated Admin Permissions (GDAP)](/partner-center/gdap-introduction) permission model.
Whats New
Updated- clicktale
You can use groups in Microsoft Entra ID to assign licenses, or deployed enterprise apps, to large numbers of users. You can also use groups to assign all administrator roles except for Microsoft Entra Global Administrator, or you can grant access to external resources, such as SaaS applications or SharePoint sites.
:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png" alt-text="Screenshot that shows how to turn on issuer hints." lightbox="media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png":::
In Microsoft Entra ID, part of Microsoft Entra, sometimes organizations need to use a single username and password for multiple people, which often happens in the following cases:
Microsoft Entra passkeys on Windows enable phishing-resistant, passwordless sign-in using Windows Hello on both managed and unmanaged devices. Public preview runs from late March to May 2026. Organizations must opt in and configure passkey policies; existing security policies remain unchanged. No compliance issues identified.
Between November 2025 and February 2026, Microsoft Baseline Security Mode automatically created two disabled draft Entra Conditional Access policies in some tenants. This is not a security issue, requires no action, and a fix will remove unintended drafts and prevent automatic creation.
Groups Naming Policy
UpdatedYou can use attributes that can help you and your users identify which department, office, or geographic region for which the group was created. For example, if you define your naming policy as `PrefixSuffixNamingRequirement = "GRP [GroupName] [Department]"` and `User's department = Engineering`, then an enforced group name might be `"GRP My Group Engineering."` Supported Microsoft Entra attributes are `\[Department\]`, `\[Company\]`, `\[Office\]`, `\[StateOrProvince\]`, `\[CountryOrRegion\]`, and `\[Title\]`. Unsupported user attributes are treated as fixed strings. An example is `"\[postalCode\]"`. Extension attributes and custom attributes aren't supported.
Users Revoke Access
UpdatedAccess tokens and refresh tokens are frequently used with thick client applications, and also used in browser-based applications such as single page apps.
Groups Restore Deleted
UpdatedUser Administrator and Partner Tier 1 Support | Can restore any deleted Microsoft 365 group or cloud security group except those groups assigned to the Global Administrator role
Groups Settings Cmdlets
UpdatedFor more information on how to prevent nonadministrator users from creating security groups, set the `AllowedToCreateSecurityGroups` property to False as described in [Update-MgPolicyAuthorizationPolicy](/powershell/module/microsoft.graph.identity.signins/update-mgpolicyauthorizationpolicy).
Groups Lifecycle
Updated- **Teams**: Visit a Teams channel.
Microsoft Graph
UpdatedTo manage custom security attribute assignments for users in your Microsoft Entra organization, you can use PowerShell or Microsoft Graph API. The following examples can be used to manage assignments.
Everbridge Tutorial
Updated
Groups Troubleshooting
UpdatedTo disable group creation for nonadmin users in PowerShell:
Microsoft Entra External ID
1 updateClean Up Unmanaged Accounts
UpdatedPrior to August 2022, Microsoft Entra B2B supported self-service sign-up for email-verified users. With this feature, users create Microsoft Entra accounts, when they verify email ownership. These accounts were created in unmanaged (or viral) tenants: users created accounts with an organization domain, not under IT team management. Access persists after users leave the organization.
