logo
search
Security Policy Errors

Fix Add Expression Disabled for Microsoft Entra Dynamic Group

Maira MehtabMaira Mehtab Sep 22, 2026 868 views

Question details

The user is unable to add an expression when editing dynamic membership rules in Microsoft Entra ID because the option is greyed out.

Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Editing dynamic membership rules in Microsoft Entra ID.
Observed behavior
The Add expression option is greyed out and unclickable despite having the required Entra ID P1 license and Global Administrator privileges.
Before you start

Ensure that your Microsoft Entra ID P1 or P2 license is currently active and assigned to your admin account before modifying dynamic group rules.

Solution 1Recommended

Verify Group Type and Membership Settings

Confirm that the group is properly configured to support dynamic membership rules and that privileges are actively recognized.

Dynamic group expressions require the group to be explicitly set as dynamic and rely on valid directory roles. Sometimes, session timeouts or misconfigurations can cause the interface to disable these options.

1
Log in to Entra Admin Center

Navigate to the Microsoft Entra admin center and log in with your Global Administrator credentials.

2
Locate the Group

Go to Groups > All groups and select the specific group you are trying to edit.

3
Check Membership Type

Check the Membership type property; ensure it is set to Dynamic User or Dynamic Device rather than Assigned.

4
Refresh Active Session

Log out and log back in to ensure your session has not timed out or lost its elevated administrative privileges.

Check Licensing Assignment: Even if the tenant has a P1 license, verify that the license is specifically assigned to the administrator account making the changes.
Free Microsoft Office alternative

Manage Your IT Documentation with WPS Office

While WPS Office cannot resolve Microsoft Entra ID cloud configuration issues, it is the perfect free, lightweight, and highly compatible alternative to Microsoft Office for writing your IT policies, troubleshooting guides, and infrastructure documentation.

  1. 1. Download WPS Office: Visit the official WPS website and download the free suite.
  2. 2. Install the Application: Run the installer and follow the on-screen instructions to set up WPS Office on your device.
  3. 3. Create IT Documentation: Open WPS Writer or Spreadsheet to start organizing your cloud architecture plans and policy guidelines.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation that runs smoothly on almost any desktop or mobile device.Familiar user interface for a seamless migration from Microsoft Office.Built-in PDF toolkit for securely sharing IT policies and compliance documents.Free to download and use for essential daily documentation needs.
microsoft office alternative - wps office

Frequently Asked Questions

Why is the dynamic group membership type greyed out in Entra ID?

The membership type cannot be changed for groups synced from on-premises Active Directory or for certain built-in directory roles. Ensure the group is entirely cloud-managed.

Does Microsoft Entra ID P1 guarantee access to all dynamic group features?

Yes, a P1 or P2 license is required to use dynamic groups, but the license must be properly applied to the tenant and assigned to the administrator making the changes.

Can I manage dynamic groups without Global Administrator rights?

Yes, users with the Groups Administrator or Intune Administrator roles can also manage dynamic groups, provided the tenant maintains the appropriate licensing.