![Mastering Identity and Access Management with Microsoft Azure](https://wfqqreader-1252317822.image.myqcloud.com/cover/884/36698884/b_36698884.jpg)
Configure dynamic group memberships
In the next section, we will configure straightforward dynamic group memberships to use the department attribute to add users to their department group and build up a dynamic licensing assignment. Group-based licensing currently does not support groups that contain other groups (nested groups).
When enabling dynamic groups, current memberships will be lost.
The usage location of a user needs to be set to assign a license.
As the admin@domain.onmicrosoft.com, choose the Accounting group, navigate to properties, and change the membership type to Dynamic User.
Create a simple rule, department Equals (-eq) Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/b4e98202-681e-4998-9b18-a171ae9dabff.png?sign=1738979596-6bzNSQmx189xorWpKZZYOyMf8A2iPkT9-0-ebb0a68215b8d5a9571f13e06371954a)
Set the department attribute (profile section) on the accounting users Brian Cox and Jeff Simpson to Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/bb725e0d-f542-4984-8e69-4b552a9e2d0e.png?sign=1738979596-w5KEsAn40eK3c845rs0QVZUvhPiQ8osC-0-a4b4efd70a4ccb8c62cd66c4291cea83)
The member should be added automatically. Check the group membership and verify the two new members:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/22c71e10-5bd3-4b5c-8ad3-c0b720b3a30a.png?sign=1738979596-U8yu0cyIY88tCQ8C0AQbDagYTKXDYmq5-0-50cb4917589ed6602ed51a118af60119)
Next, we will provide an automatic licensing solution.
Create the following security group:
- Office 365 full feature licensing
- Group description: Automatic Office 365 Full Feature Licensing
- Membership type: Dynamic User
- Dynamic query: userType -eq Member:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/c4c4cd37-530e-409e-8cb5-47e34850a679.png?sign=1738979596-QgDYr8tDjHmKPD2pPKP5DVq4Zy2ElvXT-0-f1a62330dc0271d10e7508e9bff93cfb)
Under Licenses | Products, assign the Office 365 E5 plan. Don't choose any assignment options at the moment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/562b5fba-363c-4973-ab41-77e714912df3.png?sign=1738979596-3aUwHiPHuqvQ9gEf0BAOXNoJirLomWtF-0-4a8902d18b80be3e5c19d968f2b8781e)
Wait until the membership has updated and check the license assignment for Don.Hall@domain.onmicrosoft.com.
You will see that the user gets the license through a direct and group-based assignment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/ee6dd666-83d0-46e9-919b-1406451e37a4.png?sign=1738979596-WgoCNXTDxDjUWbim5QWY0QNw43f6I9Xe-0-da8f2b487fda5f4475edf2d5dd42b0bb)
In the next section, we will configure role assignments to administrative units.