MS-102 · Question #536
Your company has a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com. A user named User1 is a member of a dynamic group named Group1. User1 reports…
The correct answer is B. User administration activities ?Updated user. Group1 is a dynamic group, meaning membership is determined automatically by Azure AD based on user attribute rules (e.g., department, job title, location). No administrator directly removes a member from a dynamic group - membership changes happen automatically when a user's…
Question
Your company has a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com. A user named User1 is a member of a dynamic group named Group1. User1 reports that he cannot access documents shared to Group1. You discover that User1 is no longer a member of Group1. You suspect that an administrator made a change that caused User1 to be removed from Group1. You need to identify which administrator made the change. Which audit log activity should you search in the Security & Compliance admin center?
Options
- AAzure AD group administration activities ?Removed member from group
- BUser administration activities ?Updated user
- CAzure AD group administration activities ?Updated group
How the community answered
(36 responses)- A14% (5)
- B78% (28)
- C8% (3)
Explanation
Group1 is a dynamic group, meaning membership is determined automatically by Azure AD based on user attribute rules (e.g., department, job title, location). No administrator directly removes a member from a dynamic group - membership changes happen automatically when a user's attributes change. Therefore, if User1 was removed from Group1, an administrator must have modified one of User1's attributes so they no longer match the dynamic group's membership rule. Searching 'User administration activities – Updated user' in the audit log will reveal which administrator changed User1's attributes and what was changed. Searching for group administration activities would not show the root cause because no admin directly touched the group membership.
Topics
Community Discussion
No community discussion yet for this question.