Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium
A Microsoft 365 administrator needs to create a new group that automatically includes all users located in 'London' and excludes any users with a job title containing 'Contractor'. This group will be used to assign licenses and access to specific SharePoint sites. Which type of group should the administrator create?
- ASecurity group with dynamic membership
- BMail-enabled security group
- CDistribution group
- DMicrosoft 365 Group
Show answer & explanationAnswer & explanation
Correct answer: A. Security group with dynamic membership
A security group with dynamic membership allows for automatic population of members based on user attributes, such as location and job title, using rules. This is ideal for assigning licenses and permissions dynamically without manual updates.
Why the other options are wrong
- B. Mail-enabled security groups can be used for both security and email, but standard ones don't support dynamic membership based on rules.
- C. Distribution groups are for email distribution and cannot be used for license assignment or access control.
- D. A Microsoft 365 Group is for collaboration and can have dynamic membership, but a Security group is specifically designed for authorization (licensing, access) based on dynamic rules.
Azure AD Dynamic Groups
Groups in Azure Active Directory (Azure AD) whose membership is automatically managed based on defined rules that evaluate user or device attributes.
- Membership updates automatically.
- Can be security groups or Microsoft 365 groups.
- Uses attribute-based rules (e.g., department, location, job title).
- Simplifies group management for large organizations.
Memory trick: Dynamic groups are like smart filters, automatically sorting users into the right buckets based on their details.