logo
search
Others

Fix Manager Property Missing in Dynamic Microsoft 365 Groups

Maira MehtabMaira Mehtab Sep 28, 2026 868 views

Question details

The user is attempting to create dynamic Microsoft 365 or security group membership rules using a manager relationship, but is encountering issues combining the rule or facing validation errors because the manager property appears missing.

Product
Microsoft 365
Device & OS
not provided
Scenario
Configuring dynamic security and Microsoft 365 group membership rules based on a manager's direct reports.
Observed behavior
Dynamic membership rules based on the 'Manager' (Direct Reports) property cannot be combined with other rules by design, and rule validation fails if the correct manager object ID or user profile attributes are missing.
Before you start

Ensure you have Global Administrator or Groups Administrator privileges in your Microsoft Entra ID (Azure AD) tenant, and verify that the 'Manager' attribute is properly populated in the relevant user profiles.

Solution 1Recommended

Configure the Direct Reports Dynamic Rule

Use the Direct Reports rule syntax properly with the manager's exact Object ID, keeping in mind that it cannot be combined with other logical rules.

Dynamic group membership rules allow administrators to automatically add direct reports of a specific manager to a group.

By design, the 'Direct Reports' rule is standalone and cannot be combined with other membership rules (using AND/OR operators). If you need complex groupings, you may need to reconsider your grouping strategy or submit feedback to the Microsoft feedback portal.

1
Create the Group

Navigate to the admin center, create a new Microsoft 365 or Security group, assign an owner, and set the Membership type to Dynamic User.

2
Add Dynamic Query

Select 'Add dynamic query' under the membership options to open the rule configuration interface.

3
Configure the Direct Reports Rule

Choose the 'Direct Reports' rule type. When prompted for a value, input the exact Object ID of the manager (do not use the manager's display name or email address).

4
Validate the Rule

Use the 'Validate rules' feature by adding a few test users (who are direct reports) to ensure the system evaluates the membership correctly without errors.

5
Save the Configuration

Once validation passes, save the dynamic query and finish creating the group. Allow some time for the group membership to populate based on the user profiles.

Manager Attribute Verification: If direct reports are not populating, double-check that the 'Manager' field is actually filled out in each user's profile within Microsoft Entra ID.
Free Microsoft Office alternative

Need a Reliable Desktop Office Suite? Try WPS Office

While advanced group administration must be handled in the Microsoft 365 Admin Center, your daily document creation doesn't require a heavy, expensive subscription. WPS Office offers a free, lightweight, and incredibly fast alternative for all your Word, Excel, and PowerPoint needs.

  1. 1. Download WPS Office: Visit the official WPS Office website and download the installer for your specific operating system.
  2. 2. Install the Application: Run the setup file and follow the on-screen instructions to install the lightweight suite.
  3. 3. Open Your Office Files: Launch WPS Office and instantly open, edit, or save your existing Microsoft Office documents seamlessly.
Fully compatible with Microsoft Office document formats (.docx, .xlsx, .pptx).Lightweight design with fast installation and quick app loading times.Familiar tabbed user interface minimizes the learning curve.Built-in PDF editing tools included at no extra cost.
microsoft office alternative - wps office

Frequently Asked Questions

Why can't I combine a Direct Reports rule with other dynamic group rules?

By Microsoft's design, dynamic membership rules based on the manager relationship (Direct Reports) are standalone. You cannot use logical operators like AND or OR to combine a manager-based rule with other user attribute rules.

What should I enter in the manager value field during setup?

You must enter the manager's unique Object ID, which can be found in their Entra ID (Azure AD) user profile. Do not enter their display name or email address, as this will cause a validation error.

Why are direct reports not appearing in the dynamic group after setup?

Ensure that the 'Manager' attribute is correctly populated in each direct report's user profile. If the manager field is empty for a user, the dynamic rule will not evaluate them as a direct report.

How can I request the ability to combine manager rules in the future?

You can submit a feature request or upvote existing requests regarding dynamic group rule combinations through the official Microsoft feedback portal.