The new tutorial explains how to provision cloud-managed users, a security group, and its membership into AD DS so members can access an on-premises Kerberos application. User provisioning is identified as being in preview.
Entra Cloud Sync guidance details preview user and GA group provisioning to AD
Cloud Sync dominates the period: new Microsoft Entra guidance describes provisioning users and groups from Microsoft Entra ID to on-premises AD DS, with group provisioning generally available and user provisioning in preview. The new material also covers provisioning modes, object matching and lifecycle behavior, prerequisites, targeted testing, and a Kerberos application scenario. Separate notices record an Entra Connect 2.6.92.0 fix, a Chatwork SCIM cutoff on October 1, and Security Copilot inclusion in Microsoft 365 E5/E7 plans.
- Cloud Sync guidance separates groups-only, users-only, and combined provisioning
Entra ID · Fundamentals
The new article lays out groups-only, users-only, and users-and-groups provisioning from Microsoft Entra ID to AD DS. It identifies group provisioning as generally available and user provisioning as preview, and documents per-domain configuration limits and performance guidance.
- New provisioning behavior guidance maps matching and object lifecycle outcomes
Entra ID · Provisioning
The new reference documents how Cloud Sync scopes, matches, creates, updates, and deletes users, groups, and memberships in Active Directory. It includes matching with msDS-ExternalDirectoryObjectId and user source-of-authority scenarios.
- Security Copilot joins Microsoft 365 E5/E7 without a new purchase
ID Governance · Microsoft identity platform
The Message Center notice says Security Copilot is now included in Microsoft 365 E5/E7, with agents spanning Defender, Entra, Intune, Purview, and the Security Copilot portal. Included plans receive monthly Security Compute Units and developer tools; additional paid features remain available.
- Entra Connect 2.6.92.0 fixes Pass-through Authentication wizard setup
Entra ID · General
Version 2.6.92.0, released September 18, 2026, fixes a 2.6.91.0 issue that could prevent Pass-through Authentication setup through the Microsoft Entra Connect wizard.
- Chatwork SCIM provisioning is scheduled to end October 1, 2026
Entra ID · Provisioning
The updated Entra enterprise app guidance warns that ChatWork will discontinue SCIM-based provisioning on October 1, 2026, retiring the Microsoft Entra Enterprise App Gallery integration.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
36 updates
Microsoft Entra ID
33 updatesPlan Cloud Sync Topologies
Doc updateThe page updates diagram descriptions and explains that provisioned group members must have an AD account. Eligible members include synchronized users, cloud-managed users in scope for user provisioning, and cloud-created security groups. The provisioning example link was also updated.
The article documents how Cloud Sync scopes, matches, creates, updates, and deletes users, groups, and memberships in Active Directory, including matching with msDS-ExternalDirectoryObjectId and user source-of-authority scenarios.
Microsoft Entra provisioning setup (Preview)
New featureThe article expands beyond group-only provisioning to explain provisioning users, groups, or both from Microsoft Entra ID to on-premises AD DS. It adds prerequisites, deployment options, scoping filters, target containers, and attribute-mapping guidance; user-related options are marked Preview.
Test Microsoft Entra provisioning (Preview)
New featureA new preview how-to explains on-demand testing for users and groups, default accidental-delete and email settings, enabling configurations, handling quarantines, restarting sync, and removing configurations.
Microsoft Entra prerequisites for AD (Preview)
New featureAction requiredA new article documents prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS using Cloud Sync. It also links to configuration, testing, deployment, and agent setup guidance.
The tutorial now covers provisioning both users and groups from Microsoft Entra ID to Active Directory. It adds examples for filtering groups by an extension value and mapping a user extension into an Active Directory attribute, along with updated prerequisites and guidance.
The guide now documents testing individual users or groups when provisioning from Microsoft Entra ID to Active Directory. It adds steps for selecting objects, selecting up to five group members, and reviewing detailed results, retries, and additional tests.
The article now covers directory extensions for both users and groups, clarifies the supported application identifier and Tenant Schema Extension App prerequisite, and updates examples, links, and related content.
Configure Chatwork for automatic user provisioning with Microsoft Entra ID
RetirementAction requiredThe documentation warns that ChatWork will discontinue SCIM-based provisioning on October 1, 2026, retiring the Entra Enterprise App Gallery integration.
The page’s subservice metadata was updated, and its attribute-mapping link now points to the renamed configuration guide.
On Demand Provision
Doc updateThe article now states that it covers on-demand provisioning from Active Directory to Microsoft Entra ID and links to a separate article for provisioning in the reverse direction.
Tutorial Group Provisioning
Doc updateThe tutorial for provisioning groups to AD DS with Microsoft Entra Cloud Sync was deleted, including its setup guidance, scoping recommendation, and group/user synchronization scenarios.
Migrate Group Writeback
Doc updateThe group writeback migration documentation now links to the guidance for changing other attribute mappings.
Preserve a group's organizational unit (Preview)
New featureAction requiredNew preview documentation explains how to capture a group's distinguished name in a GroupDN extension before converting its Source of Authority to Microsoft Entra ID.
Connect Version History
Feature updateAction requiredVersion 2.6.92.0 was released on September 18, 2026, fixing a 2.6.91.0 issue that could prevent Pass-through Authentication setup through the Microsoft Entra Connect wizard.
The page metadata was updated, and its references now link to the revised “Provision users and groups from Microsoft Entra ID to Active Directory” article.
Connect Version History
Doc updateAction requiredThe version history no longer states that the 09/23/2026 hotfix will be deployed through phased auto-upgrade. The Microsoft Graph permissions notice was repositioned.
Connect Version History
Doc updateThe version history now lists release 2.6.92.0 as September 23, 2026, and the related 2.6.91.0 support date as September 23, 2027. The page metadata date was also updated.
The page’s subservice changed from hybrid to hybrid-cloud-sync, and its reviewer changed from dhanyak to dhanyahk.
Prepare Your Environment for User SOA
Doc updateThe page’s subservice metadata changed from hybrid to hybrid-cloud-sync, and its reviewer metadata was updated.
User Source Of Authority Guidance
Doc updateThe page now identifies the subservice as hybrid-cloud-sync instead of hybrid and corrects the reviewer attribution.
Attribute Mapping
Doc updateThe page’s Microsoft Entra ID-to-AD attribute mapping section was removed and its introductory link now points to the dedicated configuration guide.
Connect Version History
Feature updateThe version history now states that auto-upgrade will move existing installations to the September 18, 2026 hotfix through multiple phases.
The guide for provisioning from Microsoft Entra ID to Active Directory was removed. It covered attribute mappings, scoping filters, sAMAccountName customization, and target-container configuration.
A new article explains groups-only, users-only, and users-and-groups provisioning from Microsoft Entra ID to AD DS. User provisioning is in preview, while group provisioning is generally available; it also documents per-domain configuration limits and performance guidance.
Provision Microsoft Entra ID objects to AD
New featureThe new overview describes how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to AD, including supported configurations, user types, attribute updates, enforcement, and provisioning flow. User provisioning is in preview, while group provisioning is generally available; password writeback isn't supported.
Transfer user SOA to Microsoft Entra ID
Doc updateThe article now describes provisioning Microsoft Entra-managed users back to Active Directory with Cloud Sync so they can access Kerberos-based on-premises applications while their lifecycle is governed from the cloud. It also updates passwordless authentication guidance and diagrams.
The guidance now links to updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory and nested-group membership behavior. Page metadata was also refreshed.
Source Of Authority Overview
Doc updateThe article’s introductory wording and references were updated, including the link to cloud-first identity management guidance. The described Group SOA and group replication steps remain unchanged.
Protect M365 From On Premises Attacks
Doc updateThe on-premises access guidance now links to a Microsoft Entra Cloud Sync how-to page for provisioning groups to Active Directory.
The guide now focuses on phased transitions of user and group source of authority to Microsoft Entra ID while maintaining application access. It also updates readiness content and LDAP-binding application guidance, including provisioning cloud-managed users and groups back to on-premises AD or using Microsoft Entra Domain Services.
The page’s subservice metadata changed to hybrid-cloud-sync, and the listed reviewer changed.
Microsoft Entra ID Governance
3 updatesRoad To The Cloud Implement
Doc updateThe guidance now links to a different Microsoft Entra Cloud Sync configuration page for provisioning groups to Active Directory Domain Services.
The licensing table now covers guests disabled or deleted by lifecycle policies, sponsor attestations, and users sponsoring new guests. It also lists the related beta API endpoints for attestation and sponsorship.
Security Copilot is now included with Microsoft 365 E5/E7 plans, integrating agents across Defender, Entra, Intune, Purview, and its portal. No purchase or action is needed. Organizations get monthly Security Compute Units, developer tools, and can explore additional paid features or opt out by contacting support.
