Migrate SharePoint Apps from ACS to Azure AD
Question details
The user needs to migrate SharePoint applications from Azure Access Control Service (ACS) to Azure Active Directory (Azure AD) while restricting app access to specific private groups instead of the entire domain.
- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Upgrading identity management and configuring restricted group access during a SharePoint tenant migration.
- Observed behavior
- Requires a transition from the deprecated ACS model to modern Azure AD for application authentication and precise access control.
Ensure you have Global Administrator or SharePoint Administrator privileges in your Microsoft 365 tenant. It is highly recommended to audit all current ACS-based SharePoint add-ins before initiating the identity migration.
Seek Expert Guidance on Microsoft Q&A
Since migrating from ACS to Azure AD involves complex identity management and tenant-level configurations, Microsoft's official Q&A platform is the best channel to resolve specific architectural issues and group access constraints.
Data migration and identity infrastructure changes between Azure Access Control Service and Azure Active Directory require advanced tenant-level support. This goes beyond standard SharePoint features.
Navigate your web browser to the official Microsoft Q&A forum at https://learn.microsoft.com/en-us/answers/questions/.
Use the search bar to look for 'SharePoint ACS to Azure AD migration' to see if a specialist has already addressed your specific private group access scenario.
If you cannot find a match, click 'Ask a question'. Provide detailed information about your current ACS setup and clarify that you want to restrict the new Azure AD app access to specific private groups.
Ensure you apply tags such as 'Azure Active Directory', 'SharePoint Development', and 'Identity' so that appropriate Microsoft engineers and specialists can find and answer your query.
Understand the Modernization Transition Steps
Familiarize yourself with the fundamental workflow for moving away from ACS-based authentication to modern Microsoft Entra ID (Azure AD) integrated apps.
Manage Your Migration Documentation with WPS Office
Complex tenant migrations require extensive planning, documentation, and data tracking. While WPS Office does not manage Azure identity infrastructure directly, it serves as a powerful, free, and lightweight alternative to Microsoft Office for organizing all your migration checklists and project plans.
- 1. Download WPS Office: Visit the official WPS website to download and install the free WPS Office suite on your computer.
- 2. Draft Migration Plans: Open WPS Writer to create comprehensive tenant migration plans, detailing your transition from ACS to Azure AD.
- 3. Share with Your IT Team: Save your documents in standard Microsoft formats to ensure perfect compatibility when sharing with colleagues or external consultants.

Frequently Asked Questions
Why is Microsoft retiring Azure Access Control Service (ACS) for SharePoint?
Microsoft is modernizing its identity platforms by replacing the legacy ACS with Azure Active Directory (Microsoft Entra ID). This shift provides enhanced security, modern authentication protocols (like OAuth 2.0), better compliance, and more robust conditional access mechanisms.
Can I restrict Azure AD SharePoint apps to specific groups only?
Yes. Unlike older ACS configurations that often defaulted to broader domain-level access, Azure AD allows administrators to assign application access strictly to specific users or security groups using the Enterprise Applications management blade in the Azure portal.
Where can I get specialized technical support for SharePoint identity migration?
For complex identity and tenant migration queries, the official Microsoft Q&A forum is highly recommended. Microsoft engineers and specialized community experts actively monitor the 'Azure Active Directory' and 'SharePoint' tags to provide tailored architectural guidance.




