![Mastering Identity and Access Management with Microsoft Azure](https://wfqqreader-1252317822.image.myqcloud.com/cover/884/36698884/b_36698884.jpg)
Configure dynamic group memberships
In the next section, we will configure straightforward dynamic group memberships to use the department attribute to add users to their department group and build up a dynamic licensing assignment. Group-based licensing currently does not support groups that contain other groups (nested groups).
When enabling dynamic groups, current memberships will be lost.
The usage location of a user needs to be set to assign a license.
As the admin@domain.onmicrosoft.com, choose the Accounting group, navigate to properties, and change the membership type to Dynamic User.
Create a simple rule, department Equals (-eq) Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/b4e98202-681e-4998-9b18-a171ae9dabff.png?sign=1739278777-55SNL6ijL4pdYeh6vg1eW9cXq2AgQ5kh-0-9bde80b9f758486622d8f19b3cbc83e8)
Set the department attribute (profile section) on the accounting users Brian Cox and Jeff Simpson to Accounting:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/bb725e0d-f542-4984-8e69-4b552a9e2d0e.png?sign=1739278777-YWveiJ0dzyGOKkyVYD2CLRg6XdjPARCx-0-f439b6952e2f0d45d49838224243f537)
The member should be added automatically. Check the group membership and verify the two new members:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/22c71e10-5bd3-4b5c-8ad3-c0b720b3a30a.png?sign=1739278777-WG8R8JEzh9v78T2q2GNGHmgdu423Jxtn-0-b942fe2ef751aa9271098df131c30b59)
Next, we will provide an automatic licensing solution.
Create the following security group:
- Office 365 full feature licensing
- Group description: Automatic Office 365 Full Feature Licensing
- Membership type: Dynamic User
- Dynamic query: userType -eq Member:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/c4c4cd37-530e-409e-8cb5-47e34850a679.png?sign=1739278777-a1nHO22TOziRib4ywHFMAtVBpXUM8mwC-0-217154d529db756a1e2fa365a1514b86)
Under Licenses | Products, assign the Office 365 E5 plan. Don't choose any assignment options at the moment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/562b5fba-363c-4973-ab41-77e714912df3.png?sign=1739278777-4icb4Tfv30YFp22intI0prvGXQpogVfj-0-c5d2418234ef946bc0ff754c44b0b35e)
Wait until the membership has updated and check the license assignment for Don.Hall@domain.onmicrosoft.com.
You will see that the user gets the license through a direct and group-based assignment:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/ee6dd666-83d0-46e9-919b-1406451e37a4.png?sign=1739278777-OlabRXSDg1vct9v8eY9JYa0kEPLc7VvQ-0-ffae0aad9c350eb03cbc51b6e2cd602e)
In the next section, we will configure role assignments to administrative units.