Microsoft to Retire Entra ID MemberOf Rule Operator

Organizations must replace affected configurations to avoid outdated memberships and access assignments.

Microsoft logo

Key Takeaways:

  • The Entra ID MemberOf rule operator will be retired later this year.
  • Dynamic groups, administrative units, and entitlement management policies may be affected.
  • Organizations should identify and replace MemberOf-based configurations before the deadline.

Microsoft will retire the MemberOf rule operator in Microsoft Entra ID later this year. This change will require organizations to update or replace affected configurations before November 2026.

In Microsoft Entra ID, the MemberOf rule operator was introduced as a preview feature, allowing administrators to build dynamic groups, administrative units, or entitlement policies based on a user’s membership in another group. Instead of creating complex attribute-based rules, organizations can automatically include users who already belong to specific groups. This capability makes it easier to manage access and assignments across related resources.

“Microsoft continues improving the scale and reliability of dynamic membership processing. During preview, Microsoft observed that use of MemberOf can affect dynamic membership processing across a tenant even if you have one MemberOf rule operator in your tenant. Because of this limitation, it is not recommended for production use and will be retired,” the company explained on the Microsoft 365 admin center.

Which Microsoft Entra ID features will be affected?

Microsoft plans to deprecate the MemberOf rule operator for Entra ID customers in early November 2026. Organizations have until November 3, 2026 to update, replace, or remove any configurations that depend on it. This change will impact several Microsoft Entra ID features, including dynamic membership groups, dynamic administrative units (AUs), and Entitlement Management auto-assignment policies.

If organizations don’t make the necessary changes ahead of the retirement deadline, any memberships or assignments that rely on the MemberOf operator will stop updating and remain locked in their last known state. Consequently, access permissions could become outdated, allowing former users to retain access while preventing new users from receiving the permissions they need.

This change could affect a wide range of services and controls, including Microsoft Teams, SharePoint, Conditional Access policies, group-based licensing, administrative unit scopes, and Entitlement Management assignments. This could lead to outdated access management and governance challenges across the organization.

Preparing for the Microsoft Entra ID MemberOf retirement

To prepare for the retirement of the MemberOf rule operator, organizations should begin by identifying every dynamic group, administrative unit, and entitlement management policy that relies on it. Administrators should then replace MemberOf-based rules with supported dynamic membership criteria wherever possible or switch to assigned memberships when an equivalent rule cannot be created. It’s advised to thoroughly test and validate memberships, access permissions, and assignment behaviors to ensure users continue receiving the correct level of access.

Organizations should also review whether existing groups, administrative units, and policies are still necessary. Administrators can remove unused or outdated configurations to identity management and reduce administrative overhead.

IT admins concerned about migration challenges

In a Reddit thread, many IT admins appear frustrated because the MemberOf operator, despite remaining in preview, became a practical way to mimic nested group functionality in Microsoft Entra ID. Several administrators noted that they had already incorporated it into production environments due to its usefulness in managing access, licensing, and group memberships.

The biggest concern is that Microsoft is retiring the feature without offering a direct replacement that provides the same functionality, which will force organizations to redesign existing processes and membership structures.

Enterprise admins are also concerned about the migration effort required before the November 2026 deadline. They believe that replacing MemberOf-based logic with attribute-driven rules, static groups, or custom automation may require significant planning and testing, especially in larger environments.