Microsoft Entra memberOf Retirement: What Admins Should Check Before Dynamic Groups Stop Updating

Microsoft Entra memberOf retirement affects dynamic groups, access policies and licensing. Check what must be replaced before 3 November 2026.
Practical Microsoft security, identity and governance insights
Practical Microsoft security, identity and governance insights

Microsoft Entra memberOf retirement affects dynamic groups, access policies and licensing. Check what must be replaced before 3 November 2026.

Most organisations have an AI policy. Very few have AI governance. This article turns the policy into a working operating model for Microsoft 365, mapping six governance layers to Purview, Entra and Compliance Manager, with a Copilot governance starting point, a maturity model, and an up to date view on the EU AI Act.

Microsoft Entra ID Account Recovery introduces a new self-service recovery model built around verified identity proofing rather than traditional helpdesk resets. This article explores how the feature works, where it fits in a modern passwordless strategy, its architectural implications for Zero Trust environments, and why organisations should start evaluating it now despite its current preview limitations.

Most Microsoft Entra tenants look mature at the policy layer, but far fewer can clearly explain which system is actually authoritative for their groups. This article explores why Group Source of Authority is not just a sync setting, but a governance control question that shapes ownership, lifecycle, access review enforcement and real identity assurance.

On 19 March 2026, Microsoft quietly released one of the most requested enterprise identity features to Public Preview: a native, platform-managed backup and point-in-time recovery capability for Entra ID tenant configuration. No big announcement, no Message Centre notification. Just a…

Entra Tenant Governance extends UTCM into a multi-tenant governance model, adding tenant discovery, governance relationships and policy templates on top of Microsoft’s native monitoring and snapshot engine. This post breaks down how it works mechanically, what each licensing tier unlocks, where the control-plane risks sit, and when native governance makes sense versus third-party tooling.

Many Microsoft Entra tenants are technically secure but structurally fragile. This article explains why administrative boundary design — using Administrative Units, scoped delegation and governance segmentation — is essential for defensible enterprise tenant governance.

Microsoft is introducing Tenant Configuration Management as a native configuration governance layer for Microsoft 365. This article explores how continuous configuration monitoring, drift detection and baseline enforcement will reshape Microsoft security and compliance operating models.

Conditional Access is the backbone of Zero Trust in Microsoft Entra ID, yet real world attacks increasingly demonstrate how it can be bypassed. From device and token abuse to built in exclusions and misunderstood session controls, attackers exploit gaps that many organisations assume are protected.
Triggered by Microsoft’s upcoming change in February 2026, where session revocation will finally behave as expected during incident response, this blog analyses observed Conditional Access bypass techniques from real incidents in 2024 and 2025. More importantly, it explains why a strong security baseline is essential to compensate for what Conditional Access was never designed to solve alone.

Discover the game-changing 'Require Risk Remediation' control in Microsoft Entra Conditional Access. This preview feature simplifies risk management by handling both password and passwordless users in one policy, reducing complexity and misconfigurations. Get a step-by-step guide, real-world benefits, and pragmatic insights into its limitations for enhanced security.