Summary
The public preview of the MemberOf rule operator in Microsoft Entra ID is ending. Organizations using MemberOf in dynamic membership groups, dynamic administrative units (AUs), or entitlement management auto-assignment policies must replace these configurations by November 3, 2026.
Microsoft continues improving the scale and reliability of dynamic membership processing. During preview, Microsoft observed that use of MemberOf can affect dynamic membership processing across a tenant even if you have one MemberOf rule operator in your tenant. Because of this limitation, it is not recommended for production use and will be retired.
Microsoft 365 Message Center ID: MC1448379
Published: Aug 5, 2026
Service: Microsoft Entra
Tag: Major change, User impact, Admin impact, Retirement
Act by Nov 3, 2026
Rollout schedule
Retirement (Worldwide): Beginning in early November 2026
Action required by: November 3, 2026
Impact on your organization
Who is affected
Organizations using the MemberOf rule operator in:
- Dynamic membership groups
- Dynamic administrative units (AUs)
- Entitlement management auto-assignment policies
Platforms and services
- Microsoft Entra ID
- Microsoft Entra Groups
- Microsoft Entra Administrative Units
- Microsoft Entra Entitlement Management
What will happen
If no action is taken, configurations that use the MemberOf operator will stop updating after November 3, 2026. Membership and assignment data will remain in their last known state, which can lead to stale access and enforcement gaps.
Potential impacts include:
- Teams and SharePoint access associated with Microsoft 365 groups may become outdated. New members may not receive access, while removed members may retain access.
- Conditional Access policies may no longer reflect current user or device membership.
- Entitlement Management auto-assignment policies may no longer add or remove access package assignments as intended.
- Group-based licensing may stop assigning or removing licenses correctly, resulting in unlicensed or overlicensed users.
- Dynamic administrative unit membership and scope may become outdated.
Action required and recommendations
Before November 3, 2026, review all uses of the MemberOf operator and remove or replace those configurations.
Dynamic membership groups
- Export dynamic membership groups from the Microsoft Entra admin center and identify rules containing MemberOf.
- Replace MemberOf with supported rule operators or convert the group to assigned membership.
- Validate group membership after making changes.
- If the group is no longer needed, consider pausing or deleting it.
Dynamic administrative units
- Use Microsoft Graph PowerShell to identify dynamic administrative units that use MemberOf rules.
- Replace MemberOf-based rules with supported rule operators or convert the administrative unit to assigned membership.
- Validate both membership and administrative scope after making changes.
- If the administrative unit is no longer needed, consider deleting it.
Entitlement Management auto-assignment policies
- Use Microsoft Graph PowerShell to identify auto-assignment policies that use MemberOf.
- Replace MemberOf-based policies with supported operators where possible.
- If no equivalent rule is available, plan an alternative assignment method before retirement.
- Validate access package assignments after making changes.
Learn more
- Configure an automatic assignment policy for an access package in entitlement management | Microsoft Entra ID Governance | Microsoft Entra | Microsoft Learn
- Configure dynamic membership groups with the memberOf attribute in the Entra admin center | Users | Microsoft Entra ID | Microsoft Entra | Microsoft Learn
- Create simpler, more efficient rules for dynamic membership groups in Microsoft Entra ID | Users | Microsoft Entra ID | Microsoft Entra | Microsoft Learn
- Manage users or devices for an administrative unit with rules for dynamic membership groups | Role-based access control | Microsoft Entra ID | Microsoft Entra | Microsoft Learn
Compliance considerations
Configurations that rely on MemberOf for access management, licensing, entitlement management, Conditional Access targeting, or administrative scoping may stop updating after retirement. Review affected configurations to ensure continued compliance and access governance after November 3, 2026.