Forum Discussion
PHS staged rollout works for existing users but not new synced users
Hi, when staged rollout works for existing users but not new synced users, I would look closely at group membership timing and sync state.
Things to check:
1. Confirm the new users are in the staged rollout group in Entra ID.
2. Confirm the group itself is in the staged rollout configuration.
3. Check whether group membership is direct or dynamic, and whether dynamic processing has completed.
4. Verify password hash sync has completed for the new users.
5. Check sign-in logs to see whether the user is still being routed to federation.
My hunch would be timing or group scope first, then PHS state second.
We've been leveraging just a single group for staged rollout and have had it in place for a long time (like over a year). All members are direct members and PHS is complete.
I also tried the route of creating a cloud user, place them into a staged rollout group, hard match to on-prem AD and see if they could still login without being redirected to the federation. It still redirected.