logo
search
Account Security Problems

How to Create Microsoft Entra Dynamic Groups for Indirect Reports

Muhammad TalhaMuhammad Talha Sep 30, 2026 868 views

Question details

The user needs to create a Microsoft Entra dynamic group that includes everyone in a manager's entire reporting chain, encompassing both direct and indirect reports.

How to Create Microsoft Entra Dynamic Groups for Indirect Reports
Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Configuring organizational user groups based on full reporting hierarchy and manager relationships.
Observed behavior
Microsoft Entra's built-in dynamic group rules can only identify direct reports via the user.manager attribute and fail to evaluate or traverse the complete organizational hierarchy for indirect reports.
Before you start

Ensure you have the Groups Administrator or Global Administrator role in Microsoft Entra ID and access to an administrative PowerShell environment for executing Microsoft Graph automation scripts.

Solution 1Recommended

Use PowerShell and Microsoft Graph Automation

Since built-in dynamic rules cannot traverse reporting hierarchies, creating a custom PowerShell script using Microsoft Graph is the most effective way to automate group membership for indirect reports.

This approach bypasses the limitations of native dynamic group rules by recursively querying the directory to map out the entire reporting chain and then explicitly adding those users to a designated security group.

1
Connect to Microsoft Graph

Open PowerShell as an administrator and run 'Connect-MgGraph' specifying the necessary scopes such as 'User.Read.All' and 'Group.ReadWrite.All'.

2
Retrieve the reporting hierarchy

Write a recursive script using 'Get-MgUserManager' and 'Get-MgUserDirectReport' to query the manager attribute, looping through all levels to fetch both direct and indirect reports for the specified top-level manager.

3
Update group membership

Use the 'New-MgGroupMember' cmdlet within your script to add the Object IDs of the retrieved indirect and direct reports into your target Microsoft Entra group.

4
Automate the execution

Schedule your PowerShell script to run periodically using Azure Automation or Windows Task Scheduler to ensure the group remains accurate as employees change roles.

Use PowerShell and Microsoft Graph Automation
Script Maintenance: Custom scripts require periodic maintenance. Ensure your Azure App Registrations or managed identities used for authentication have their secrets and certificates rotated regularly.
Free Microsoft Office alternative

Boost Organizational Productivity with WPS Office

While you manage complex IT administration tasks like Entra hierarchy groups, ensure your entire organization has the tools they need to succeed. WPS Office is a free, lightweight, and incredibly powerful alternative to Microsoft Office, designed for seamless enterprise deployment and daily document management.

  1. 1. Download and Install: Deploy WPS Office across your organizational devices quickly due to its lightweight installer.
  2. 2. Open Existing Files: Access all your legacy Microsoft Office files seamlessly without any formatting loss or compatibility issues.
  3. 3. Collaborate Instantly: Use WPS Office's built-in sharing and cloud collaboration features to connect managers and indirect reports.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation and low system requirements, ideal for large organizational deployments.Familiar user interface ensuring zero learning curve for direct and indirect reports alike.Built-in advanced PDF editing and seamless team collaboration tools.
microsoft office alternative - wps office

Frequently Asked Questions

Can Microsoft Entra dynamic groups natively include indirect reports?

No, the built-in dynamic group rule syntax in Microsoft Entra ID can only evaluate direct reports using the user.manager attribute. It does not support recursive evaluation for traversing indirect reports.

Are nested dynamic groups supported in Microsoft Entra ID?

Microsoft Entra ID currently does not support creating dynamic groups where the members are other groups (nested dynamic groups). Dynamic group rules can only evaluate user or device objects directly.

Do I need a specific license to use dynamic groups?

Yes, utilizing dynamic groups in Microsoft Entra ID requires an active Microsoft Entra ID P1 or P2 license for each unique user that is a member of one or more dynamic groups.

How quickly do Microsoft Entra dynamic groups update when user attributes change?

Microsoft Entra typically processes dynamic group changes within a few minutes, but for large organizations with complex directory structures and numerous rules, it can take up to 24 hours to fully populate.