Creating Dynamic Groups
Cayosoft Dynamic Groups automatically maintain the membership of an existing group based on defined membership rules. You can include or exclude users and other supported objects based on attributes and other query criteria, helping keep group membership aligned with organizational requirements without manually updating individual members.
Dynamic Groups can be configured for Active Directory and Microsoft 365 groups. Dynamic Groups populate an existing target group; they do not create the target group.
When to use Dynamic Groups
Use Dynamic Groups when you need to automatically maintain the membership of an existing group based on defined criteria.
Common scenarios include:
- Maintaining group membership based on user attributes such as department, location, or other supported attribute values.
- Automatically including objects that match defined query criteria.
- Automatically excluding objects that match defined query criteria.
- Combining query-based membership rules with explicitly included or excluded objects.
- Keeping Active Directory or Microsoft 365 group membership updated as directory data changes.
Video Tutorial
In this video guide, you will learn in what scenarios you can use Dynamic Groups, how they work, and their basic configuration.
The following example shows an Active Directory Dynamic Group configuration with two membership commands: AD Users, where group membership is controlled automatically, and AD members of this group, where the membership of the specified group is controlled manually.
Getting Started
Dynamic Groups begin with the selection of an existing group onto which the rules are applied to control the group's membership. Dynamic Groups do not create groups; they populate the existing group according to the configured rules.
There are two types of Dynamic Groups: Active Directory and Microsoft 365. Each Dynamic Group can have:
- The following Membership rules:
- Include Query - includes the set of objects that meet a certain condition.
- Exclude Query - excludes the set of objects that meet a certain condition.
- Include Objects - includes specific objects.
- Exclude Objects - excludes specific objects.
- Rule Enforce/Schedule section
- Rule Output section
- Advanced settings of Dynamic Groups
Each Membership rule includes membership rule commands that define the type of included objects and the conditions these objects must meet. See Membership Rule Commands for Active Directory and Microsoft 365 Dynamic Groups .
Create a Dynamic Group
- Open the Cayosoft Administrator Console.
-
Click NEW+ > Dynamic Group.
- At the top of the object select dialog, select Extension (Active Directory or Microsoft Office 365) and the type of group to be populated. For example, the Active Directory extension is selected.
- In the Name begins with field, enter the first few letters of the group's name, then click Search.
- Select the group from the search results.
-
The new Dynamic Group appears and the Membership Rules can now be added.
- If you create a Dynamic Group that is based on an Active Directory group, you can check Add change details to Change History and Execution History to track Dynamic Group changes and scope in Auditing Cayosoft Administrator with Change History and Execution History .
Automatically Manage Group Membership Based on User Attributes
You can use membership rules to automatically include or exclude users based on attribute values. For example, you can maintain membership for users in a specific department, location, or other supported attribute value.
The following example creates a query-based membership rule for Active Directory users.
-
Click Add Membership Rule.
- In the Name field, enter a descriptive name for the rule.
- Select the membership type Include Query or Exclude Query, depending on the operation you want to perform.
- Click Add on the membership rule.
- Select AD Users. The lower half of the dialog box displays the query configuration.
- Click the picker button to the right of the Query Criteria field.
- Click Add Condition.
- Enter the attribute name, condition operator, and value that must be met for the rule to include or exclude a user.
- Click OK. The criteria appear in the Query Criteria field.
- Click OK.
- Click Save Changes.
- Click Preview to verify that the query returns the expected users.
Schedule the Dynamic Group Rule
Configure a schedule to determine when Cayosoft Administrator evaluates the Dynamic Group rules and updates the target group's membership.
- In the Enforce/Schedule section, click Enable.
- Select the settings that determine when the Dynamic Group rule runs and updates membership.
- Click Save.
Create a Runbook from Existing Dynamic Groups
When you need to run Dynamic Groups in a specific order and do not want to configure schedules for each Dynamic Group separately, you can create a Runbook from existing Dynamic Groups.
- In the Cayosoft Administrator Console, click New, then select Runbook.
- Provide a name and folder for the Runbook.
- After the Runbook is created, select Link to existing in the Sequence section.
- Select the Dynamic Groups you want to include in the Runbook.
- Schedule the Runbook as required.
Considerations and limitations
- Dynamic Groups populate an existing target group; they do not create the target group.
- Dynamic Group membership is updated when the configured rule runs.
- Use Preview to verify query results before relying on a scheduled membership update.
- Add-member and remove-member thresholds can prevent unexpectedly large membership changes.
- When many Dynamic Groups are configured, review scheduling and performance recommendations to avoid unnecessary load on the Cayosoft Administrator service.
Related articles
- Advanced settings of Dynamic Groups
- Membership Rule Commands for Active Directory and Microsoft 365 Dynamic Groups
- Configuring Alert when Dynamic Group Threshold is Crossed
- Recommendations for Dynamic and Family Groups
Comments
0 comments
Please sign in to leave a comment.