Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID by using Group Source of Authority (SOA), including prerequisites, setup, validation, and how to roll back.
Group Source of Authority preview guidance dominates an otherwise documentation-only Entra week
For the week of 28 July 2025, the supplied feed contains 42 Microsoft Learn updates and no new, removed, or Message Center items. The clearest substantive cluster is Microsoft Entra ID's Group Source of Authority (SOA) (Preview): updated material covers moving group management from AD DS to the cloud, prerequisites, cleanup, configuration, validation and rollback, auditing, preserved organizational units, and post-conversion self-service management. Smaller but concrete updates cover ID Governance approval workflows and Entra Connect audit and configuration references. External ID and Global Secure Access updates are primarily operational documentation refinements. Nothing in the feed supports calling any of these a GA launch, retirement, or confirmed product-behavior change.
- Group Source of Authority (SOA) (Preview) received a broad hybrid-group guidance set
Entra ID · Fundamentals
Updated overview, how-it-works, prerequisite, configuration, group-cleanup, original-organizational-unit, auditing and monitoring, and self-service pages collectively describe transferring group management from AD DS to Microsoft Entra ID. The guidance covers managing, provisioning, restoring, validating, and rolling back groups, including self-service management after conversion. Because these are updated Learn pages and the capability is labeled Preview, they document an evaluation and implementation path rather
- Entitlement Management documentation expands the dynamic-approval path (Preview)
ID Governance · Governance
The updated guidance says access-package approvers can be assigned directly or determined dynamically, with native examples including the requester's manager, second-level manager, or a sponsor from a connected organization. The explicitly Preview custom-extension article covers determining approval requirements externally. A related update shows how to add a verified ID requirement to an access-package policy. These are configuration guidance updates, not a stated GA or behavior change.
- Entra Connect documentation adds precision around sync auditing and application and certificate management
Entra ID · Authentication
The Admin Audit Logging page includes a 2507 entry for enabling or disabling sync start after installation and says an event is logged. A Default page states that Entra Connect provides three options for application and certificate management, and the version release-history page was also updated. The records clarify where administrators should look but do not identify a new build or say that logging behavior changed this week.
- External ID updates clarify external-tenant application onboarding and feature boundaries
External ID · Fundamentals
The External ID in external tenants material includes a link to the workforce-versus-external-tenant supported-features matrix. The enterprise-application page describes adding gallery applications through the admin center, along with configuration and deployment guidance. The evidence supports documentation clarification for tenant-model and onboarding decisions, not newly enabled features or general availability.
- Global Secure Access refreshed macOS client and traffic-visibility documentation
Global Secure Access · General
Updated pages cover downloading and installing the macOS client, its release history, application-usage analytics, and the traffic dashboard. No client version or feature delta is supplied, so these entries should be treated as operational documentation updates rather than a client release announcement.
The main administrator task is targeted documentation review, not a broad tenant change. Teams evaluating Group SOA should use the preview guidance to assess hybrid-group cleanup, conversion, monitoring, and rollback before changing operating procedures. Entra Connect operators can use the updated audit reference for the documented event when sync is enabled or disabled after installation and the page describing three application and certificate-management options; the evidence does not establish a required upgrade or newly introduced behavior. For access packages, review the dynamic-approval and verified-ID guidance only if those controls are in scope. The updated Mandatory Multifactor Authentication entry contains no content detail beyond authorship, so it is not evidence of a changed M
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
32 updatesmanager: mwongerapk
author: Justinha
Gpad Prereqs
Updatedauthor: omondiatieno
author: Justinha
The goal for group analysis is to review and confirm which of the groups in a domain are:
author: Justinha
Apple Sso Plugin
Updated( ** ) You only need to allow sovereign cloud domains if you rely on those in your environment.
Agent Optimization
Updatedauthor: MicrosoftGuyJFlo
manager: pmwongera
Agent Optimization
Updatedauthor: MicrosoftGuyJFlo
Managing groups across hybrid environments is essential for organizations that transition from on-premises Active Directory Domain Services (AD DS) to the cloud. Group Source of Authority (SOA) in Microsoft Entra ID enables you to transfer group management from AD DS to the cloud, providing greater flexibility, modern governance, and streamlined administration. This guidance explains how to use Group SOA to manage, provision, restore, and roll back groups in hybrid and cloud environments. It explains best practices to clean up groups, convert group management, and ensure secure, efficient access control as you modernize your identity infrastructure.
author: justinha
Source Of Authority Overview
UpdatedLearn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.
Whats New
Updated**Service category:** Group Management
author: justinha
author: Justinha
author: Justinha
Admin Audit Logging
Updated|2507|Enable/Disable sync start after installation.| Event is logged when sync is enabled or disabled after the installation is finished.|
Tutorial - Provision groups to Active Directory Domain Services by using Microsoft Entra Cloud Sync
Updatedmanager: mwongerapk
A guide for independent software vendors for enabling automated provisioning in Microsoft Entra ID
Puzzel Provisioning Tutorial
Updated
Default
UpdatedMicrosoft Entra Connect provides three options for application and certificate management:
author: justinha
author: justinha
author: justinha
Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
Learn how to configure and set up a custom email provider with the One Time Passcode Send event type.
Single Sign On Saml Protocol
Updated| Parameter | Type | Description |
manager: pmwongera
Microsoft Entra ID Governance
3 updates}
1. Select **Add** to add the verified ID requirement to the access package policy.
In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. Entitlement management natively supports dynamically determining approvers such as the requestors manager, their second-level manager, or a sponsor from a connected organization:
Microsoft Entra External ID
3 updates- [Supported features in workforce and external tenants](customers/how-to-add-enterprise-application.md)
Learn how to add enterprise applications to your Microsoft Entra external tenant using the admin center. Discover gallery apps, configuration steps, and deployment tips.
Supported Features Customers
UpdatedFeature |Workforce tenant | External tenant |
Microsoft Entra Global Secure Access
4 updatesApplication Usage Analytics
Updatedmanager: dougeby
Traffic Dashboard
Updatedmanager: dougeby
Install Macos Client
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
Macos Client Release History
UpdatedThis article tracks the changes in each released version of the Global Secure Access client for macOS.
