Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard

A Microsoft 365 administrator is configuring a new tenant and needs to set up a group that automatically includes all users from the 'Sales' department whose 'City' attribute is set to 'New York'. The group should update its membership dynamically as user attributes change. Which type of group should the administrator create in Azure AD to meet these requirements?

  1. ADynamic user group
  2. BMicrosoft 365 group
  3. CMail-enabled security group
  4. DStatic security group
Show answer & explanation

Correct answer: A. Dynamic user group

A dynamic user group in Azure AD allows membership to be automatically managed based on user attributes defined by a rule. This directly fulfills the requirement for a group that includes users based on their 'Department' and 'City' attributes and dynamically updates membership.

Why the other options are wrong

  • B. Microsoft 365 groups are for collaboration with shared resources; while they can be dynamic, the core requirement is an Azure AD group that dynamically updates based on *user attributes* for general purposes.
  • C. Mail-enabled security groups are for both security and email distribution but their membership is typically static or synchronized, not dynamically updated based on attributes.
  • D. Static security groups require manual membership management, which does not meet the dynamic update requirement.

Azure AD Dynamic Groups

Azure AD groups (security or Microsoft 365) whose membership is automatically updated based on predefined rules that query user or device attributes.

  • Requires an Azure AD Premium P1 or P2 license.
  • Supports dynamic membership for users or devices.
  • Simplifies group management for large and frequently changing organizations.

Memory trick: Think of dynamic groups as smart filters that automatically sort users into the right club.

More Deploy and manage a Microsoft 365 tenant questions