Skip to main content

Microsoft 365 | Entra ID memberOf Rule Retirement: Liongard Impact and Partner Guidance

Overview ✨

Microsoft is permanently retiring the memberOf rule operator for dynamic memberships in Microsoft Entra ID. Organizations that use this operator in dynamic group or dynamic administrative unit rules must replace those rules according to Microsoft’s guidance before the retirement date.

Liongard proactively reviewed the potential impact on the Microsoft 365 Inspector and related functionality. The review found no dependency on the memberOf operator, dynamic membership rule text, or group-nesting lookups.

✅ Liongard’s Microsoft 365 Inspector does not depend on the Microsoft Entra ID memberOf dynamic membership rule operator. No Liongard change is required for this Microsoft retirement.


Impact on Liongard

  • The inspector reads group, member, and role-member lists.

  • The inspector does not use the memberOf operator.

  • The inspector does not perform group-nesting lookups.

  • The inspector does not create or modify groups or membership rules.

  • Dynamic groups are identified through groupTypes containing DynamicMembership.

  • No Liongard metric, alert, or view uses the dynamic membership rule text itself.

ℹ️ No current Liongard impact has been identified. The Microsoft 365 Inspector will continue to collect supported Entra ID group and membership data using the existing Microsoft Graph endpoints.


What Partners Need To Do

Partners using dynamic groups or dynamic administrative units should review their Entra ID rules and replace any use of memberOf before November 3, 2026. This is an Entra ID configuration requirement and is not a Liongard configuration change.

  1. Identify dynamic groups and dynamic administrative units that use the memberOf operator.

  2. Rewrite affected rules using a Microsoft-supported alternative.

  3. Validate that the resulting memberships are correct in Microsoft Entra ID.

  4. Confirm that the Microsoft 365 Inspector continues to report the expected membership data during a normal collection cycle.

⚠️ Important: If Microsoft Entra ID ceases to evaluate an affected rule, Liongard will report the membership data provided by Entra ID. Any membership changes that occur may appear as normal chnages in the Microsoft 365 Inspector; this does not mean that Liongard caused the changes.

If you notice unexpected membership data after the retirement, first verify the membership results directly in Microsoft Entra ID. Then ensure that the Microsoft 365 Inspector is collecting data correctly and compare the reported membership with the data returned by Entra ID.


References 🌟

🚨 Note : We may occasionally provide links to third-party tools or resources for additional reference. These resources are offered for convenience only, and Liongard does not control, maintain, or guarantee their functionality, accuracy, or availability. Please review and use any third-party resources at your own discretion.

Did this answer your question?