Forum Discussion
Ketzpatel
Aug 19, 2022Brass Contributor
Dynamic Security group in Azure AD using attribute - preferreddatalocation
I have a need to configure group-based licensing for multi-geo license assignment and I would like to create a dynamic security group in Azure using the attribute preferreddatalocation but this is not a supported attribute to use in Azure AD.
any other option to configure group-based licensing for multi-geo based on the preferreddatalocation? we only apply multi-geo to specific country users and not all.
5 Replies
- oliwer_sundgrenIron ContributorHey there!
Any reason not to use the "usagelocation" attribute for this scenario?- KetzpatelBrass Contributor
unfortunately we can not use usage location. Within that country only users and executives with highly sensitive data has multi-geo licenses assigned to keep their mailboxes to FR data center.
- oliwer_sundgrenIron ContributorI understand!
Then I would recommend using an extension attribute to tag these specific users with, and then use that attribute in your dynamic groups rule. That's the simplest and most bullet proof solution I can think of π
Let me know if that helps or if you have further questions!
- Use "country" or "usagelocation"? Or custom attributes/extensions: https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-dynamic-membership#extension-properties-and-custom-extension-properties