Entra ID & IdentityHow-To & HardeningRetrospectives

How to Update Documentation, Scripts and Policies After the Entra ID Rename

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2023, written in 2026 with the benefit of hindsight.

The rename from Azure AD to Microsoft Entra ID didn't change functionality, but it's a good reason to update documentation and retire legacy tooling — especially deprecated PowerShell modules.

Step 1: Update documentation and runbooks

Search internal documentation, runbooks, policies and training materials for "Azure AD" and "AAD." Update names and screenshots to the Entra admin center. Keep a short glossary mapping old names to new.

Step 2: Retire deprecated PowerShell modules

Microsoft deprecated the AzureAD and MSOnline (MSOL) PowerShell modules. Scripts using them need migration to Microsoft Graph PowerShell (or the Microsoft Entra PowerShell module).

  1. Find scripts: search for Connect-AzureAD, Connect-MsolService, Get-AzureAD*, Get-Msol*.
  2. Map cmdlets to Graph equivalents (Microsoft publishes a cmdlet map).
  3. Use app-only authentication with certificates or managed identities for automation, with least-privilege Graph permissions.
  4. Test and deploy.

Step 3: Review automation permissions

During migration, check what permissions each script's app registration has. Many scripts were granted broad permissions years ago.

Step 4: Update policies and contracts

Update security policies, vendor contracts and compliance mappings that reference Azure AD.

Step 5: Review licensing names

Confirm procurement and finance records reflect Entra ID P1/P2 names to avoid confusion at renewal.

Step 6: Use the moment for a configuration review

The rename is a natural checkpoint for a broader Entra ID health check (see the configuration health checklist).

azure ad to entra id changesEntra ID rename2023

More on this story