Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantEasy
A Microsoft 365 administrator is onboarding a new employee, Alex. Alex will be part of the Sales department and requires access to specific applications and resources. The company uses Azure AD group-based licensing and dynamic groups for resource access. Which attribute should the administrator configure for Alex's user account to ensure automatic assignment to the correct Sales department groups and licenses?
- ADepartment
- BProxy Addresses
- CJob Title
- DUser Principal Name (UPN)
Show answer & explanationAnswer & explanation
Correct answer: A. Department
Dynamic groups in Azure AD use rules based on user attributes to automatically add or remove members. To ensure Alex is automatically added to groups and receives licenses associated with the Sales department, the 'Department' attribute on Alex's user account must be correctly set.
Why the other options are wrong
- B. Proxy Addresses are for email routing and aliases, not for dynamic group membership based on departmental affiliation.
- C. While 'Job Title' can be used, 'Department' is more directly correlated with group membership for departmental access and licensing.
- D. UPN is a login identifier, not typically used for dynamic group membership based on organizational roles.
Azure AD Dynamic Group Attributes
Azure AD Dynamic Groups automatically manage membership based on user attributes. Administrators define rules using attributes like 'department', 'country', or 'job title', and Azure AD adds or removes users as their attributes change.
- Simplifies group management by automating membership.
- Rules are based on user properties stored in Azure AD.
- Common attributes include Department, Company, Country, Usage Location, Job Title.
- Supports 'AND', 'OR', 'NOT' operators for complex rules.
Memory trick: Attributes drive the dynamic group's flow, ensuring access where users go.