Dynamic AD group

%3CLINGO-SUB%20id%3D%22lingo-sub-1344065%22%20slang%3D%22en-US%22%3EDynamic%20AD%20group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1344065%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EHi%20Experts%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3EI%20am%20using%20exchange%20hybrid%20environment%2C%20all%20my%20users%20are%20created%20on%20onprem%20and%20migrated%20to%20cloud.%20for%20example%20i%20have%20user1%20whose%20department%20number%20is%20100%2C%20every%20user%20has%20department%20number%20in%20AD%20attribute.%20i%20have%20another%20user%20whose%20department%20number%20is%20101.%20my%20requirement%20is%20to%20add%20these%20users%20to%20office365%20unified%20group%20dynamically%2C%20i.e%20user%20whose%20department%20number%20is%20100%20or%20101%20should%20be%20added%20to%20this%20office365%20group%20dynamically%20and%20if%20tomorrow%20employee%20leaves%20the%20company%20it%20should%20be%20removed%20automatically%2Cor%20is%20it%20possible%20to%20create%20a%20dynamic%20group%20in%20Azure%20AD%20to%20pull%20the%20members%20of%20department%20100%20and%20101%20and%20add%20this%20group%20to%20office365%20unified%20group.%20Experts%20guide%20me%20on%20this.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1344065%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1349012%22%20slang%3D%22en-US%22%3ERe%3A%20Dynamic%20AD%20group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1349012%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F144450%22%20target%3D%22_blank%22%3E%40Roger%20Roger%3C%2FA%3E%26nbsp%3BYes%2C%20if%20you%20have%20a%20Azure%20AD%20Premium%20subscription%20you%20can%20utilize%20Dynamic%20Groups%20as%20per%20your%20requirements.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fusers-groups-roles%2Fgroups-dynamic-membership%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fusers-groups-roles%2Fgroups-dynamic-membership%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20your%20case%20the%20syntax%20would%20be%20%22(%3CSPAN%3Euser.accountEnabled%20-eq%20true)%20and%3C%2FSPAN%3E%20(user.department%20-eq%20%22100%22)%20or%20(user.department%20-eq%20%22101%22)%22.%20This%20would%20allow%20all%20enabled%20users%20with%20these%20values%20in%20the%20Department%20Attribute%20to%20be%20added%20dynamically%20to%20this%20group.%20Provided%20that%20their%20account%20gets%20disabled%20when%20their%20employment%20ends%2C%20they%20lose%20membership%20to%20this%20group.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EViktor%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1382711%22%20slang%3D%22en-US%22%3ERe%3A%20Dynamic%20AD%20group%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1382711%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F144450%22%20target%3D%22_blank%22%3E%40Roger%20Roger%3C%2FA%3E%26nbsp%3BI%20agree%20with%20the%20comment%20of%20Victor%3C%2FP%3E%3CP%3ECreate%20an%20O365%20Group%20and%20use%20Dynamic%20User%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22JordyBlommaert_0-1589292556515.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F190931i851A08E8AA6814D8%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22JordyBlommaert_0-1589292556515.png%22%20alt%3D%22JordyBlommaert_0-1589292556515.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EUse%20following%20dynamic%20query%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22JordyBlommaert_1-1589292587276.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F190933i434E72C8BC40E154%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20title%3D%22JordyBlommaert_1-1589292587276.png%22%20alt%3D%22JordyBlommaert_1-1589292587276.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Hi Experts

I am using exchange hybrid environment, all my users are created on onprem and migrated to cloud. for example i have user1 whose department number is 100, every user has department number in AD attribute. i have another user whose department number is 101. my requirement is to add these users to office365 unified group dynamically, i.e user whose department number is 100 or 101 should be added to this office365 group dynamically and if tomorrow employee leaves the company it should be removed automatically,or is it possible to create a dynamic group in Azure AD to pull the members of department 100 and 101 and add this group to office365 unified group. Experts guide me on this.

2 Replies

@Roger Roger Yes, if you have a Azure AD Premium subscription you can utilize Dynamic Groups as per your requirements.

 

https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-dynamic-membership

 

In your case the syntax would be "(user.accountEnabled -eq true) and (user.department -eq "100") or (user.department -eq "101")". This would allow all enabled users with these values in the Department Attribute to be added dynamically to this group. Provided that their account gets disabled when their employment ends, they lose membership to this group.

 

Regards,

 

Viktor

@Roger Roger I agree with the comment of Victor

Create an O365 Group and use Dynamic User:

JordyBlommaert_0-1589292556515.png

Use following dynamic query:

JordyBlommaert_1-1589292587276.png