entra id dynamic group membership not updating
Diagnoses Entra ID dynamic groups whose membership does not change when user attributes change. Covers membership rule syntax, evaluation-cycle timing, and the processing state. Use when a dynamic group is missing users it should have or still holds users it should not. Not for assigned static groups or license-group problems.
TL;DR
Dynamic groups re-evaluate on a batch cycle, not instantly, so first check whether you are just early. Then read the membership rule literally: typos in attribute names and values are the top cause of groups that never match. Use the validate-rules check, confirm the attribute actually changed in Entra (HR sync lag is real), and give the next evaluation cycle time to run.
Steps
- Open the group in Entra admin and check the membership processing state. Expected: "Membership update complete." If it shows processing or an error, wait for it to finish or note the error.
- Open the membership rule and read it literally, character by character. Expected: it references the attribute you think changed, e.g. user.department equals "Sales". A misspelled attribute name silently matches nothing.
- Run the rule validation check if available. Expected: no syntax errors. One bad clause can zero out the entire group.
- Confirm the attribute value actually changed in Entra, not just in the HR system. Expected: the user's profile in Entra shows the new value. HR sync lag means the rule may be evaluating stale data.
- Allow one full evaluation cycle (can take hours on large tenants), then recheck membership. Expected: membership reflects the rule. To test the engine itself, temporarily set the rule to something trivially true for a test user, watch it apply, then restore the real rule.
Use this when
- A dynamic group is missing users it should contain
- A dynamic group still contains users who should have aged out
- Membership was correct before and stopped updating after an attribute change
Not for this skill when
- The group is assigned (static): membership changes are manual by design
- Licenses are not applying (license assignment is a separate pipeline)
- You need membership to change within seconds (dynamic groups are batch, not real-time)
Compatibility
- Entra ID P1 or P2 (dynamic groups need P1+)
- Dynamic user groups and dynamic device groups
Variants
The group never had any members
The rule probably matches nothing at all. Test it against a known user with the rule-test feature.
Members are removed too slowly after termination
Attribute changes from HR sync lag behind the actual termination. Check when the HR sync last ran.
Why it happens
Dynamic groups are a batch evaluation engine, not event triggers. The three usual suspects, in order: a rule that does not say what you think it says, attribute sync lag from the HR system, and a long evaluation cycle on a big tenant.
Edge cases
- Nested dynamic groups are not supported: a dynamic group cannot be evaluated as a member of another dynamic group.
- Extension attributes synced from on-prem AD must finish syncing before the rule can see them.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_aCL0HoXX0stBk7ZaRAH39Q
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.