A group, either security or Microsoft 365, where a rule on user or device properties decides who belongs, adding and removing people automatically. You can't add anyone manually, and a Microsoft Entra ID P1 licence is needed for every distinct member.
Also called dynamic group.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Dynamic membership group in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft 365
Formerly Office 365, Microsoft's software-as-a-service productivity suite. A Microsoft Entra tenant provides its identity, and its data is not governed by Azure RBAC.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Architecture Definition Document
A key deliverable bringing together the main architecture artifacts across the four domains for every relevant state: baseline, transition and target. It sets out, in qualitative terms, what the architect intends.
- Microsoft Entra ID P1
Premium tier of Microsoft Entra ID, bundled with Microsoft 365 Business Premium, that unlocks capabilities like Conditional Access.
- Licence
What entitles one particular user to the services a subscription offers. Each product licence is made up of several service plans (one per app or service), and before giving it to someone an admin has to record that user's usage location.
Related terms
- Automatic assignment policy
Works much like a dynamic group: a membership rule based on user attributes decides who gets an access package and removes assignments when people stop matching. It is an ID Governance entitlement management feature, and neither catalog owners nor access package managers are allowed to set one up.
- Dynamic membership rules
Expressions defining dynamic group membership, written with hyphenated, case-insensitive operators like -eq, -in, -notIn, -match, -startsWith, -and and -or. One rule cannot combine device and user attributes.
- Group Tag
Dynamic group rules can match on this optional Autopilot value, which is written to OrderID on the Microsoft Entra device object, so deployment profiles reach particular devices.
- ZTDId
A physical ID tag carried by all Autopilot devices. Dynamic group rules match on it to gather every one of them.