![Mastering Identity and Access Management with Microsoft Azure](https://wfqqreader-1252317822.image.myqcloud.com/cover/884/36698884/b_36698884.jpg)
Configure dynamic group memberships
In the next section, we will configure straightforward dynamic group memberships to use the department attribute to add users to their department group and build up a dynamic licensing assignment. Group-based licensing currently does not support groups that contain other groups (nested groups).
When enabling dynamic groups, current memberships will be lost.
The usage location of a user needs to be set to assign a license.
As the admin@domain.onmicrosoft.com, choose the Accounting group, navigate to properties, and change the membership type to Dynamic User.
Create a simple rule, department Equals (-eq) Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/b4e98202-681e-4998-9b18-a171ae9dabff.png?sign=1739286381-wSNz0OYVk5xKYkh82TA9t19eMJoqVJZC-0-4c418910c6f57b4facbef1014f1ac43f)
Set the department attribute (profile section) on the accounting users Brian Cox and Jeff Simpson to Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/bb725e0d-f542-4984-8e69-4b552a9e2d0e.png?sign=1739286381-pSxjtHmFotOBGSCcWDrJCG4P5vA6JEQM-0-41cfbe014573492de2988d0effb30c7e)
The member should be added automatically. Check the group membership and verify the two new members:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/22c71e10-5bd3-4b5c-8ad3-c0b720b3a30a.png?sign=1739286381-GQAamFyf4rfzmBjmHVq3RThFJ6tWE4fu-0-54e3f498cb72fe80f00c5a71622981a5)
Next, we will provide an automatic licensing solution.
Create the following security group:
- Office 365 full feature licensing
- Group description: Automatic Office 365 Full Feature Licensing
- Membership type: Dynamic User
- Dynamic query: userType -eq Member:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/c4c4cd37-530e-409e-8cb5-47e34850a679.png?sign=1739286381-LCkTdJSfMpWtsRYsGoIweULaEvE8EgQ6-0-6ff2ce98d7eb42f2e06aea9dfa053a8c)
Under Licenses | Products, assign the Office 365 E5 plan. Don't choose any assignment options at the moment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/562b5fba-363c-4973-ab41-77e714912df3.png?sign=1739286381-djESsenDKB2Kfftwz0XTdh2tGUaFQXRk-0-028b3b155d7bce9fc635b81d2868ae91)
Wait until the membership has updated and check the license assignment for Don.Hall@domain.onmicrosoft.com.
You will see that the user gets the license through a direct and group-based assignment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/ee6dd666-83d0-46e9-919b-1406451e37a4.png?sign=1739286381-5KJ0gzIdaD74hKdokbdkhK4dw30aQcAq-0-496e34d02ea5cb482e7f136723841db4)
In the next section, we will configure role assignments to administrative units.