How to Create Microsoft Entra Dynamic Groups for Indirect Reports
Question details
The user needs to create a Microsoft Entra dynamic group that includes everyone in a manager's entire reporting chain, encompassing both direct and indirect reports.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Configuring organizational user groups based on full reporting hierarchy and manager relationships.
- Observed behavior
- Microsoft Entra's built-in dynamic group rules can only identify direct reports via the user.manager attribute and fail to evaluate or traverse the complete organizational hierarchy for indirect reports.
Ensure you have the Groups Administrator or Global Administrator role in Microsoft Entra ID and access to an administrative PowerShell environment for executing Microsoft Graph automation scripts.
Use PowerShell and Microsoft Graph Automation
Since built-in dynamic rules cannot traverse reporting hierarchies, creating a custom PowerShell script using Microsoft Graph is the most effective way to automate group membership for indirect reports.
This approach bypasses the limitations of native dynamic group rules by recursively querying the directory to map out the entire reporting chain and then explicitly adding those users to a designated security group.
Open PowerShell as an administrator and run 'Connect-MgGraph' specifying the necessary scopes such as 'User.Read.All' and 'Group.ReadWrite.All'.
Write a recursive script using 'Get-MgUserManager' and 'Get-MgUserDirectReport' to query the manager attribute, looping through all levels to fetch both direct and indirect reports for the specified top-level manager.
Use the 'New-MgGroupMember' cmdlet within your script to add the Object IDs of the retrieved indirect and direct reports into your target Microsoft Entra group.
Schedule your PowerShell script to run periodically using Azure Automation or Windows Task Scheduler to ensure the group remains accurate as employees change roles.

Create Separate Groups for Direct Reports
If scripting automation is not feasible, you can manually create separate dynamic groups for each manager's direct reports to assign resources.
Boost Organizational Productivity with WPS Office
While you manage complex IT administration tasks like Entra hierarchy groups, ensure your entire organization has the tools they need to succeed. WPS Office is a free, lightweight, and incredibly powerful alternative to Microsoft Office, designed for seamless enterprise deployment and daily document management.
- 1. Download and Install: Deploy WPS Office across your organizational devices quickly due to its lightweight installer.
- 2. Open Existing Files: Access all your legacy Microsoft Office files seamlessly without any formatting loss or compatibility issues.
- 3. Collaborate Instantly: Use WPS Office's built-in sharing and cloud collaboration features to connect managers and indirect reports.

Frequently Asked Questions
Can Microsoft Entra dynamic groups natively include indirect reports?
No, the built-in dynamic group rule syntax in Microsoft Entra ID can only evaluate direct reports using the user.manager attribute. It does not support recursive evaluation for traversing indirect reports.
Are nested dynamic groups supported in Microsoft Entra ID?
Microsoft Entra ID currently does not support creating dynamic groups where the members are other groups (nested dynamic groups). Dynamic group rules can only evaluate user or device objects directly.
Do I need a specific license to use dynamic groups?
Yes, utilizing dynamic groups in Microsoft Entra ID requires an active Microsoft Entra ID P1 or P2 license for each unique user that is a member of one or more dynamic groups.
How quickly do Microsoft Entra dynamic groups update when user attributes change?
Microsoft Entra typically processes dynamic group changes within a few minutes, but for large organizations with complex directory structures and numerous rules, it can take up to 24 hours to fully populate.




