← Previous week
Week in brief

Cloud Sync group guidance splits out as Global Secure Access documents custom-header preview

The week centered on a group-focused rewrite of Microsoft Entra Cloud Sync guidance for provisioning to AD DS. Microsoft added a dedicated tutorial, recast the main configuration article around groups, documented explicit topology assumptions, and revised on-demand testing. Several broad users-and-groups reference pages were removed. Separately, Global Secure Access published preview guidance for custom HTTP headers through Web Content Filtering v2, with TLS inspection and other prerequisites.

  • The new guidance describes adding custom HTTP headers to matching outbound web requests through Web Content Filtering v2 rules. It covers tenant restrictions and other header-aware services. Administrators must configure TLS inspection and meet the documented Global Secure Access prerequisites to use the capability.

  • The new tutorial explains provisioning groups from Microsoft Entra ID to on-premises Active Directory Domain Services, including Entra-to-AD and AD-to-Entra scenarios, source-of-authority behavior, and membership effects. It recommends Selected security groups as the default scoping filter to help prevent performance issues.

  • The rewritten procedure adds setup steps, screenshots, and sections covering scoping, attribute mapping, testing, and default settings. Its previous combined users-and-groups guidance was removed, and the article now includes a deprecation notice.

  • The updated planning guidance says cloud-synced groups can contain only on-premises synchronized users and additional cloud-created security groups, and that all users must have `onPremisesObjectIdentifier`. Administrators should compare existing group designs with these documented conditions.

  • The updated procedure tells administrators to select a group and manually choose up to five members for testing. User-specific instructions and result-review details were removed, and the provisioning-direction references were updated.

For Entra administrators

Cloud Sync administrators should use the new group tutorial and rewritten configuration guidance, review designs against the documented membership and `onPremisesObjectIdentifier` requirements, and use the group test flow with no more than five members. Teams evaluating Global Secure Access custom headers must configure TLS inspection and meet the documented prerequisites. Older consolidated provisioning pages, including prerequisite and test-and-enable guidance, are no longer available.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

11

Plan Cloud Sync Topologies

Feature update

The documentation now states that cloud-synced groups can contain only on-premises synchronized users and additional cloud-created security groups, and that all users must have `onPremisesObjectIdentifier`. The example link and diagram descriptions were also updated.

31 August 2026

Tutorial Users Groups Provisioning Walkthrough

Doc update

The 246-line tutorial for provisioning cloud-managed users and groups to Active Directory with Microsoft Entra Cloud Sync was deleted. It covered preview user provisioning for access to an on-premises Kerberos application.

31 August 2026

On Demand Provision

Doc update

The article’s introduction now describes on-demand provisioning from Microsoft Entra ID to Active Directory and links to related guidance.

31 August 2026

Prerequisites Provision Entra To Active Directory

Doc update

The article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises Active Directory with Cloud Sync was deleted, along with its related links and next-step guidance.

31 August 2026

Test And Enable Provisioning Entra To Active Directory

Doc update

The how-to page for testing and enabling Microsoft Entra ID to Active Directory provisioning was deleted, including guidance on on-demand tests, default properties, enabling configurations, quarantines, restarting sync, and removing configurations.

31 August 2026
3

Group Source Of Authority Guidance

Doc update

The guidance now links to the group provisioning tutorial and its updated section on nested groups and membership references.

31 August 2026

Deployment Options Provision To Active Directory

Doc update

The article comparing group-only, user-only, and users-and-groups provisioning from Microsoft Entra ID to Active Directory was deleted, including guidance on scoping, configuration limits, and performance.

31 August 2026

Provision Entra Id To Active Directory

Doc update

The documentation page describing Microsoft Entra Cloud Sync provisioning of users, groups, and memberships from Entra ID to Active Directory was deleted.

31 August 2026
2

Group Source Of Authority Configure

Doc update

The documentation now points administrators to the Microsoft Entra Cloud Sync tutorial for provisioning groups to Active Directory Domain Services, replacing the previous provisioning overview and on-premises app governance links.

31 August 2026
1

Protect M365 From On Premises Attacks

Doc update

The Access guidance now points to an updated Microsoft Entra Cloud Sync documentation link for provisioning groups to Active Directory.

31 August 2026
1

Agent Access Packages

Doc update

The documentation now provides step-by-step My Access portal instructions for authorized users to request an access package for another user, including the US Government portal URL.

31 August 2026
1

Road To The Cloud Implement

Doc update

The documentation now links to the Microsoft Entra Cloud Sync group provisioning tutorial instead of the configuration guide.

31 August 2026
1

Source Of Authority Overview

Doc update

The guidance for recreating AD DS groups as cloud security groups, provisioning them as Universal groups, and updating applications to use their new security identifiers was revised.

31 August 2026
1
1

How to configure custom HTTP headers in Global Secure Access

Public preview

New documentation describes adding custom HTTP headers to matching outbound web requests through Web Content Filtering v2 rules. The capability is currently in preview and supports tenant restrictions and other header-aware services.

31 August 2026
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…