← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Cloud Sync group provisioning guidance shifts to focused AD DS workflows and constraints

The period is dominated by a substantial restructuring of Microsoft Entra Cloud Sync guidance for provisioning groups to Active Directory. Microsoft added a dedicated AD DS tutorial, rewrote setup and testing material, documented tighter topology requirements, and removed seven older pages covering combined provisioning, prerequisites, deployment options, and test-and-enable procedures. Separately, Global Secure Access guidance now describes preview custom HTTP headers through Web Content Filtering v2 rules.

  • The new tutorial covers provisioning groups to on-premises Active Directory Domain Services in both Entra-to-AD and AD-to-Entra scenarios, including how source of authority and membership affect provisioning. It recommends Selected security groups as the default scoping filter to help prevent performance issues.

  • The guidance now states that cloud-synced groups can contain only on-premises synchronized users and additional cloud-created security groups, and that all users must have `onPremisesObjectIdentifier`.

  • The revised procedure instructs administrators to select a group and up to five members for testing. User-specific instructions and result-review details were removed, and references were updated for provisioning from Microsoft Entra ID to Active Directory.

  • The former how-to page for testing and enabling Entra-to-Active Directory provisioning was deleted. It had covered on-demand tests, default properties, enabling configurations, quarantines, restarting synchronization, and removing configurations.

  • New guidance describes adding custom HTTP headers to matching outbound web requests through Web Content Filtering v2 rules, including tenant restrictions and other header-aware services. TLS inspection and the documented Global Secure Access prerequisites are required.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

22 updates

11

Plan Cloud Sync Topologies

Feature update

The documentation now states that cloud-synced groups can contain only on-premises synchronized users and additional cloud-created security groups, and that all users must have `onPremisesObjectIdentifier`. The example link and diagram descriptions were also updated.

Tutorial Users Groups Provisioning Walkthrough

Doc update

The 246-line tutorial for provisioning cloud-managed users and groups to Active Directory with Microsoft Entra Cloud Sync was deleted. It covered preview user provisioning for access to an on-premises Kerberos application.

On Demand Provision

Doc update

The article’s introduction now describes on-demand provisioning from Microsoft Entra ID to Active Directory and links to related guidance.

Prerequisites Provision Entra To Active Directory

Doc update

The article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises Active Directory with Cloud Sync was deleted, along with its related links and next-step guidance.

Test And Enable Provisioning Entra To Active Directory

Doc update

The how-to page for testing and enabling Microsoft Entra ID to Active Directory provisioning was deleted, including guidance on on-demand tests, default properties, enabling configurations, quarantines, restarting sync, and removing configurations.

3

Deployment Options Provision To Active Directory

Doc update

The article comparing group-only, user-only, and users-and-groups provisioning from Microsoft Entra ID to Active Directory was deleted, including guidance on scoping, configuration limits, and performance.

Provision Entra Id To Active Directory

Doc update

The documentation page describing Microsoft Entra Cloud Sync provisioning of users, groups, and memberships from Entra ID to Active Directory was deleted.

2

Group Source Of Authority Configure

Doc update

The documentation now points administrators to the Microsoft Entra Cloud Sync tutorial for provisioning groups to Active Directory Domain Services, replacing the previous provisioning overview and on-premises app governance links.

1
1

Agent Access Packages

Doc update

The documentation now provides step-by-step My Access portal instructions for authorized users to request an access package for another user, including the US Government portal URL.

1

Road To The Cloud Implement

Doc update

The documentation now links to the Microsoft Entra Cloud Sync group provisioning tutorial instead of the configuration guide.

1

Source Of Authority Overview

Doc update

The guidance for recreating AD DS groups as cloud security groups, provisioning them as Universal groups, and updating applications to use their new security identifiers was revised.

1
1

How to configure custom HTTP headers in Global Secure Access

Public preview

New documentation describes adding custom HTTP headers to matching outbound web requests through Web Content Filtering v2 rules. The capability is currently in preview and supports tenant restrictions and other header-aware services.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…