Entra ID memberOf operator ends in November 2026

Microsoft is ending the public preview of the memberOf operator for dynamic membership in Microsoft Entra ID. After 3 November 2026, dynamic membership groups, dynamic administrative units, and access package auto-assignment policies that use this operator stop updating. For companies, the practical question is not whether the feature was convenient, but where it is already controlling access, policies, or permissions today.

What Microsoft is ending

The memberOf operator was designed to derive dynamic membership from existing groups: direct members of a source group are automatically added to a dynamic target group or administrative unit. Microsoft now states in Microsoft Learn that the public preview is ending. The documentation also says the feature was not intended for production use and can slow dynamic membership processing in a tenant.

The effect of the deadline matters. After 3 November 2026, existing rules are not simply deleted. Instead, they remain in their last known state. That is what makes the change risky: a problem may not look like a clear outage, but like membership that gradually becomes stale.

Which configurations are affected

Microsoft names three areas where the operator must be removed or replaced. Tenants that copied nested group logic from traditional Active Directory into Entra ID should review this especially carefully.

  • Dynamic membership groups with rules such as user.memberof -any (...) or device.memberof -any (...).
  • Dynamic administrative units where administrative scope is calculated through memberOf.
  • Auto-assignment policies in Entitlement Management when access packages are assigned through memberOf rules.
  • Dependent targets such as Teams, SharePoint, or Conditional Access assignments if they rely on those groups.

Why this matters for smaller companies

Smaller tenants can be affected as well, especially when a few central groups drive many permissions. A dynamic group might bundle access to Teams, SharePoint sites, applications, access packages, or policies. If that group stops updating after the deadline, former employees can keep access for too long, or new employees might not receive the access they need.

Microsoft explicitly lists stale Teams and SharePoint access, Conditional Access targeting, group-based licensing, and access package assignments as possible outcomes. This is not licensing advice: the point is that technical assignments can remain outdated when the underlying membership is no longer processed.

In small and midsize environments, these rules often start as a practical shortcut: one group for a department, another for external staff, and a dynamic target group for an app. As long as every change is processed, the design is almost invisible. Once processing stops, it becomes an access risk that may only surface during an audit, a team change, or a support case.

The deadline: 3 November 2026

The date is stated in the Microsoft Learn documentation. Before 3 November 2026, every use of the operator should be reviewed and removed or replaced. Because Microsoft does not name an identical successor feature, the real work is mapping the business logic: which group logic can use supported dynamic operators, where assigned membership is cleaner, and where a process needs to change.

For companies with 10 to 250 seats, this usually does not require a large migration project. What matters is finding every use. If the obvious groups are changed but one access package rule or administrative unit remains, the tenant can still end up in exactly the stale state Microsoft warns about.

The review should therefore start with the rules, not with individual applications. Once every memberOf rule is known, it becomes possible to decide whether a supported attribute rule, assigned membership, or a changed access process is the right replacement.

What companies should do now

The change is manageable if it is not left until autumn 2026. A short technical review with a documented decision for each finding is usually the best starting point.

  • Export dynamic groups and search their rules for memberOf.
  • Check dynamic administrative units and Entitlement Management policies separately with Microsoft Graph PowerShell.
  • Replace memberOf, where possible, with supported dynamic rule operators or a deliberately assigned membership.
  • Validate the actual members and dependent access after each change.
  • Document exceptions, owners, and a date for follow-up review.

Official Microsoft sources

Whether your tenant uses memberOf rules and which replacement fits can be reviewed as part of Microsoft Entra ID, a Microsoft Security Assessment, or focused Microsoft 365 Consulting – get in touch.

Recommended Next Step

What does this mean for your environment?

Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment