‹ Back to list
Plan for ChangeMC1449166

Action required: Update Microsoft Intune assignments targeting memberOf dynamic groups before November 2026

Services: Microsoft Intune· Published: 2026-08-06· MS modified: 2026-08-06Action by 2026-11-03
User impactAdmin impactRetirement

Microsoft announcement

[What and why:]

As announced in MC1448379, we are making changes to improve the overall processing efficiency and reliability of Microsoft Entra dynamic groups. As part of this effort, the memberOf dynamic membership operator will be retired beginning November 3, 2026. Membership and assignment data will automatically stop updating and remain in their last known state.

Your tenant has Microsoft Intune policies, apps, or compliance rules assigned to one or more memberOf dynamic groups. This post is specific to your Intune deployment and the assignments that depend on those groups.

[Rollout schedule:]

Starting on November 3, 2026, memberOf dynamic groups will be retired and membership stops updating.

[Impact on your organization:]

Who is affected: Tenants with Intune policies, apps, or compliance rules assigned to memberOf dynamic groups.

Platforms and services affected: All Intune workloads — device configuration profiles, compliance policies, app deployments, endpoint security policies, scripts, remediations, and role scope groups.

What will happen: When the memberOf dynamic membership operator is retired, your Intune assignments continue to exist but membership lists will not be updated. As a result:

  • New devices that enroll will not receive policies, apps, or compliance rules assigned through the affected group.
  • Users or devices that leave the intended scope will keep policies they should no longer have.
  • Compliance results can drift as membership goes stale — a device may report compliant when it should not, or the reverse.
  • Role scope groups that use memberOf will stop reflecting organizational changes, which can grant or restrict admin access incorrectly.

[Action required:]

  1. Review your Intune assignments now. In the Microsoft Intune admin center, identify which of your memberOf dynamic groups are used as assignment targets. For each affected group, document its assignments across configuration profiles, compliance policies, apps, endpoint security policies, roles (scope groups), scripts, and remediations.
  2. Update to an alternative targeting method before the deadline. Converting a dynamic group to assigned membership preserves the group's ID and keeps every Intune assignment intact — only the membership method changes, so nothing needs to be re-targeted. Where dynamic membership is still required, rewrite the rule using supported operators, or replace the memberOf rule with a static parent group that nests the referenced child groups. Intune filters can also reduce reliance on group structure for many targeting scenarios.
  3. Validate after updating assignments. Confirm that policies still appear under the correct assignment groups, use a sample of devices to verify they receive the expected configuration, and monitor the compliance dashboard for unexpected behavior.

[Compliance considerations:]

Because membership and assignment data will stop updating, compliance and access outcomes can drift from your intended state — devices may retain or lose policies that no longer match their actual membership. Review your compliance-sensitive and access-governing assignments first such as compliance policies, endpoint security policies, and role scope groups, and validate them to ensure expected behavior.

[Additional information:]

Change history