How to Fix Direct Reports Dynamic Groups Not Updating in Microsoft Entra ID
Question details
Users are not being added to Microsoft Entra ID dynamic groups based on the Direct Reports rule after a manager change.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Managing automated user group memberships and reporting structures in Microsoft Entra ID.
- Observed behavior
- Dynamic groups fail to update and populate correctly after a manager change due to syntax errors, processing delays, or backend throttling.
Ensure you have the Global Administrator or Groups Administrator role assigned in Microsoft Entra ID to view and edit dynamic group membership rules.
Correct the Dynamic Rule Syntax (Remove Curly Braces)
Fixing formatting errors in the rule syntax is the most common solution, as Microsoft documentation previously contained misleading syntax formatting.
Dynamic group rules will fail to process if the manager's Object ID is enclosed in curly braces. The system expects a raw GUID string inside the quotation marks.
Log in to the Microsoft Entra admin center and navigate to 'Identity' > 'Groups' > 'All groups'.
Search for and select the dynamic group that is not updating, then click on 'Dynamic membership rules' in the left-hand menu.
Click on 'Edit' and locate the rule syntax. Remove the curly braces {} surrounding the manager's Object ID. For example, change 'Direct Reports for "{aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb}"' to 'Direct Reports for "aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb"'.
Save the changes to the rule. The group will automatically trigger a new evaluation process. Wait a few minutes for the membership list to refresh.

Allow Time for Service-Side Processing
Wait for Microsoft's backend to process the membership changes, especially during known regional throttling events.
Open a Microsoft 365 Service Request
If the rule is perfectly formatted and processing is stuck for over 24 hours, escalate the issue to Microsoft Support.
Keep Your Team Productive with WPS Office
While waiting for Microsoft Entra ID backend issues to be resolved by server administrators, ensure your team's day-to-day work remains uninterrupted. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office, allowing your users to seamlessly create, edit, and collaborate on documents.
- 1. Download the Installer: Visit the official WPS Office website and download the correct version for your operating system.
- 2. Install WPS Office: Run the downloaded installation file and follow the quick setup wizard to install the software.
- 3. Start Collaborating: Open WPS Office and immediately begin working on your existing .docx, .xlsx, and .pptx files with your team.

Frequently Asked Questions
How long does a dynamic group typically take to update in Entra ID?
Depending on the size of your Azure AD organization and the complexity of your rules, it can take anywhere from a few minutes to up to 24 hours for dynamic group memberships to fully populate.
Can I manually force a dynamic group to update its membership?
There is no direct 'force update' button. However, you can trigger a re-evaluation by slightly modifying the rule (such as adding and removing a space) and saving it again, or by pausing and resuming dynamic group processing.
Where can I find the correct Object ID for a manager?
You can find the Object ID by navigating to 'Users' > 'All users' in the Microsoft Entra admin center, searching for the manager's name, clicking on their profile, and copying the 'Object ID' from the Overview tab.




