question

LeeWil-9733 avatar image
0 Votes"
LeeWil-9733 asked ·

Dynamic Group Question - How can I remove a user from a dynamic group on specified date and time?

Hi,

I have created a dynamic group, and setup my dynamic membership rule so that my user gets added to the group.

But, I want to put something in there that removes them from the group at a certain date and time.

Is this possible?

So what I am trying to say is :

  1. Add Bob into the Dynamic Sales group based on his department value of Sales.

  2. And then Remove Bob from the Dynamic Sales group after 01/05/2020 12:00PM

Thanks



azure-active-directory
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

michev avatar image
1 Vote"
michev answered ·

The way to remove someone from a Dynamic group is to adjust the membership filter/rule. The way to perform this on a given date/time is to schedule it via PowerShell script or similar.

· 1 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks Michev

0 Votes 0 ·
thgibard avatar image
0 Votes"
thgibard answered ·

I've not done such script based on the time but I think you should take a look on Azure Automation. It could be executed directly in Azure rather than use a PowerShell script deployed on a server - https://azure.microsoft.com/fr-fr/services/automation/.


· 1 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi thgibard,

Yes but I would have to write the logic and then have azure automation run the script or workbook on a scheduled basis and it costs.

I was hoping that MS would have built the logic into dynamic groups already because some of my users only need to be in there for a couple of days and it would be neat if they could drop out at a pre-defined time without me having to go in there and maintain it.

Thanks

0 Votes 0 ·
amanpreetsingh-msft avatar image
0 Votes"
amanpreetsingh-msft answered ·

@LeeWil-9733 You should consider using Access Review. Check https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review for more details.


Please "Accept as answer" wherever the information provided helps you to help others in the community.

· 1 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi Aman,

I have never used Access Review before and it looks quite good. I have been after something like this for some time too.

It may not meet the requirements for what I am looking for here. But at least I can get the owner to go through the membership and add/remove users on their own without having to do it myself.

I will explore this avenue for now until I can find a way for users to drop out of a group based on a date/time value.

Thanks

0 Votes 0 ·