← Previous day

Next day →
Day in brief

Documentation maintenance dominates; the Entra ID `memberOf` dynamic-group preview is the standout capability item

The 18 March record contains 42 updated items, with no new, removed, or Message Center entries. The most substantive item is updated documentation for an Entra ID feature preview that builds dynamic groups and administrative units from other groups. The other meaningful exceptions are an External ID account-lifecycle warning and Entra ID clarifications on naming policies and delegated administration. Nothing supplied establishes general availability, retirement, a rollout date, or a mandatory tenant change.

  • The updated article describes a preview that lets administrators create dynamic membership groups and administrative units populated from members of other groups through the `memberOf` attribute. It also says applications can read the full membership of these groups and that the groups can be used for licensing assignments. This is preview documentation, not evidence of general availability or a tenant-wide rollout.

  • The naming-policy guidance explicitly lists six supported built-in user attributes: Department, Company, Office, StateOrProvince, CountryOrRegion, and Title. Unsupported attributes are treated as fixed strings, while extension attributes and custom attributes aren't supported. This is an ordinary documentation clarification rather than evidence of a product behavior change on 18 March.

  • The updated article explains that the Microsoft Entra admin portal includes capabilities for administrators to see relationships with Microsoft Cloud Service Providers. It also distinguishes the older Delegated Admin Permissions (DAP) model from Granular Delegated Admin Permissions (GDAP). The supplied evidence provides no migration deadline or new-role announcement; the practical value is permissions and relationship review for CSP-managed tenants.

  • The updated cleanup guidance highlights that, before August 2022, email-verified self-service B2B sign-up could create accounts in unmanaged or “viral” tenants. Access can persist after users leave the organization. Organizations with this legacy scenario should assess whether unmanaged accounts remain and consult the cleanup guidance; the supplied summary does not specify a new cleanup mechanism or enforcement change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

44 updates

28

Groups Dynamic Rule Member Of

Updated

This feature preview in Microsoft Entra ID enables admins to create dynamic membership groups and administrative units that populate by adding members of other groups using the `memberOf` attribute. Apps that couldn't read group-based membership previously in Microsoft Entra ID can now read the entire membership of these new `memberOf` groups. Not only can these groups be used for apps but they can also be used for licensing assignments.

Users Bulk Download

Updated

1. Select **Users** > **All users** > **Download users**. By default, all user profiles are exported.

Groups Dynamic Tutorial

Updated

You're not required to assign licenses to the users for them to be members in dynamic membership groups. You only need the minimum number of available Microsoft Entra ID P1 licenses in the organization to cover all such users.

Bulk create users in Microsoft Entra ID

Updated

Microsoft Entra ID, part of Microsoft Entra, supports bulk user create and delete operations and supports downloading lists of users. Just fill out the comma-separated values (CSV) template you can download from Microsoft Entra ID.

Groups Bulk Download

Updated

:::image type="content" source="media/bulk-operations/groups-management-page.png" alt-text="Screenshot of the Microsoft Entra admin center Groups blade showing the All groups list with column headers and actions.":::

Groups Quickstart Naming Policy

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).

Users Bulk Restore

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).

Groups Bulk Import Members

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).

Close your work or school account in an unmanaged Microsoft Entra organization

Updated

If you're a user in an unmanaged organization (tenant) in Microsoft Entra ID, and you no longer need to use apps from that organization or maintain any association with it, you can close your account at any time. An unmanaged organization doesn't have an administrator. Users in an unmanaged organization can close their accounts on their own, without contacting an administrator.

Groups Change Type

Updated

Creating dynamic membership groups eliminates the management overhead of adding and removing users. This article shows you how to convert existing membership groups from static to dynamic, by using either the Azure portal or PowerShell cmdlets. In Microsoft Entra, a single tenant can have a maximum of 15,000 dynamic membership groups.

Groups Members Owners Search

Updated

On the **All groups** page, when you enter a search string, you can toggle between **contains** and **starts with** searches on the **All groups** page only.

Groups Saasapps

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).

3

What is delegated administration?

Updated

Managing permissions for external partners is a key part of your security posture. The administrator portal experience in Microsoft Entra ID, part of Microsoft Entra, now includes capabilities so that an administrator can see the relationships that their Microsoft Entra tenant has with Microsoft Cloud Service Providers (CSP) who can manage the tenant. This permissions model is called delegated administration. This article introduces the Microsoft Entra administrator to the relationship between the old Delegated Admin Permissions (DAP) permission model and the new [Granular Delegated Admin Permissions (GDAP)](/partner-center/gdap-introduction) permission model.

Directory Overview User Model

Updated

You can use groups in Microsoft Entra ID to assign licenses, or deployed enterprise apps, to large numbers of users. You can also use groups to assign all administrator roles except for Microsoft Entra Global Administrator, or you can grant access to external resources, such as SaaS applications or SharePoint sites.

2

Certificate Based Authentication Technical Deep Dive

Updated

:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png" alt-text="Screenshot that shows how to turn on issuer hints." lightbox="media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png":::

Share accounts with Microsoft Entra ID

Updated

In Microsoft Entra ID, part of Microsoft Entra, sometimes organizations need to use a single username and password for multiple people, which often happens in the following cases:

2
2

Groups Naming Policy

Updated

You can use attributes that can help you and your users identify which department, office, or geographic region for which the group was created. For example, if you define your naming policy as `PrefixSuffixNamingRequirement = "GRP [GroupName] [Department]"` and `User's department = Engineering`, then an enforced group name might be `"GRP My Group Engineering."` Supported Microsoft Entra attributes are `\[Department\]`, `\[Company\]`, `\[Office\]`, `\[StateOrProvince\]`, `\[CountryOrRegion\]`, and `\[Title\]`. Unsupported user attributes are treated as fixed strings. An example is `"\[postalCode\]"`. Extension attributes and custom attributes aren't supported.

Users Revoke Access

Updated

Access tokens and refresh tokens are frequently used with thick client applications, and also used in browser-based applications such as single page apps.

2

Groups Restore Deleted

Updated

User Administrator and Partner Tier 1 Support | Can restore any deleted Microsoft 365 group or cloud security group except those groups assigned to the Global Administrator role

Groups Settings Cmdlets

Updated

For more information on how to prevent nonadministrator users from creating security groups, set the `AllowedToCreateSecurityGroups` property to False as described in [Update-MgPolicyAuthorizationPolicy](/powershell/module/microsoft.graph.identity.signins/update-mgpolicyauthorizationpolicy).

1
1

Microsoft Graph

Updated

To manage custom security attribute assignments for users in your Microsoft Entra organization, you can use PowerShell or Microsoft Graph API. The following examples can be used to manage assignments.

1
1
1

Clean Up Unmanaged Accounts

Updated

Prior to August 2022, Microsoft Entra B2B supported self-service sign-up for email-verified users. With this feature, users create Microsoft Entra accounts, when they verify email ownership. These accounts were created in unmanaged (or viral) tenants: users created accounts with an organization domain, not under IT team management. Access persists after users leave the organization.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…