![Mastering Identity and Access Management with Microsoft Azure](https://wfqqreader-1252317822.image.myqcloud.com/cover/884/36698884/b_36698884.jpg)
Configure dynamic group memberships
In the next section, we will configure straightforward dynamic group memberships to use the department attribute to add users to their department group and build up a dynamic licensing assignment. Group-based licensing currently does not support groups that contain other groups (nested groups).
When enabling dynamic groups, current memberships will be lost.
The usage location of a user needs to be set to assign a license.
As the admin@domain.onmicrosoft.com, choose the Accounting group, navigate to properties, and change the membership type to Dynamic User.
Create a simple rule, department Equals (-eq) Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/b4e98202-681e-4998-9b18-a171ae9dabff.png?sign=1739241158-jE8RGg6XlSHOBcxW5H0IatGBdnm6psUi-0-53ab1765fdcbc8b0fb2cf25c68506386)
Set the department attribute (profile section) on the accounting users Brian Cox and Jeff Simpson to Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/bb725e0d-f542-4984-8e69-4b552a9e2d0e.png?sign=1739241158-AisK9t1laLWXwQAGobYizBZTtIW9w5bk-0-3937cb2d3c338bb6f98691dd5e966799)
The member should be added automatically. Check the group membership and verify the two new members:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/22c71e10-5bd3-4b5c-8ad3-c0b720b3a30a.png?sign=1739241158-dWQ2UAzYbScUGSAUhtUn4OU4LVexBLkj-0-82022a48a6e36bfcd8499794e2b8e692)
Next, we will provide an automatic licensing solution.
Create the following security group:
- Office 365 full feature licensing
- Group description: Automatic Office 365 Full Feature Licensing
- Membership type: Dynamic User
- Dynamic query: userType -eq Member:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/c4c4cd37-530e-409e-8cb5-47e34850a679.png?sign=1739241158-ys5sU3FSkKJ7ByXsLTkschnQdqRF3Oca-0-d6a7ce7d1815ae896577804609bccf11)
Under Licenses | Products, assign the Office 365 E5 plan. Don't choose any assignment options at the moment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/562b5fba-363c-4973-ab41-77e714912df3.png?sign=1739241158-hIPSSGmaP13J0W9kLHgArvzRj7R21cCG-0-c542e9f068ac58e58c47902c8a8357fb)
Wait until the membership has updated and check the license assignment for Don.Hall@domain.onmicrosoft.com.
You will see that the user gets the license through a direct and group-based assignment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/ee6dd666-83d0-46e9-919b-1406451e37a4.png?sign=1739241158-COxQGj5btCTLZzGE1ayhy0W8EB6qdOvp-0-7299fea765f42149ba811134903c8299)
In the next section, we will configure role assignments to administrative units.