hardMultiple Choice
MS-102 Practice Question: The Microsoft 365 administrator for Contoso Ltd.,…
You are the Microsoft 365 administrator for Contoso Ltd., a company with 500 users. The company uses a hybrid identity with Microsoft Entra Connect. You have a dynamic group named 'SalesGroup' that includes all users with department attribute equal to 'Sales'. Recently, the HR system updated the department for 20 users from 'Sales' to 'Marketing'. The Microsoft Entra Connect sync completed successfully, and the attribute changes are reflected in Microsoft Entra ID. However, after 48 hours, these users are still members of 'SalesGroup'. You need to ensure that the group membership accurately reflects the department attribute within the next hour. The solution must use minimal administrative effort. What should you do?
⚠ Common exam trap
Watch out — candidates often assume dynamic groups are evaluated immediately after an attribute sync, but Microsoft deliberately tests the understanding that dynamic group membership evaluation is asynchronous and can take up to 24 hours unless manually triggered.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trigger a manual evaluation of the dynamic group in Microsoft Entra ID
Microsoft Entra ID dynamic groups are not automatically re-evaluated immediately after a sync; they rely on a periodic background evaluation process that can take up to 24 hours. By triggering a manual evaluation in the Microsoft Entra ID admin center or via PowerShell (using the `Invoke-MgGraphRequest` or `Update-MgGroup` cmdlet), you force an immediate recalculation of group membership based on the current attribute values, ensuring the 20 users are removed from SalesGroup within the hour with minimal administrative effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the users from the group manually
Why it's wrong here
Dynamic group membership is computed exclusively by Microsoft Entra ID using the configured rule; the service does not allow manual edits to membership for dynamic groups. Even if you remove a user from a dynamic group, the next automatic evaluation will likely re-add the user if they still match the rule attributes. Manual removal is also blocked in the Azure portal because the group's membership is read-only, so this action is not a viable fix.
- ✗
Delete and recreate the dynamic group with the same rule
Why it's wrong here
Deleting and recreating the dynamic group with the same rule is a heavy-handed approach that introduces significant risk. The group's object ID changes, breaking any access packages, conditional access policies, licensing assignments, or applications that reference the old group. In addition, the same asynchronous evaluation delay applies to the new group, and a brief window of uninterrupted access or governance is created without solving the root cause of the stale membership.
- ✓
Trigger a manual evaluation of the dynamic group in Microsoft Entra ID
Why this is correct
Triggering a manual evaluation of the dynamic group in Microsoft Entra ID forces the membership processing engine to run immediately, updating the group's membership in near real time. This is done by selecting the 'Reprocess' option in the Dynamic group rules pane or via Microsoft Graph, which is the recommended resolution when membership is stale and time is critical. It does not change the rule, but it accelerates the evaluation that would otherwise happen on the next automatic cycle.
- ✗
Wait another 24 hours for the next automatic evaluation
Why it's wrong here
Microsoft Entra ID automatically evaluates dynamic group rules on a background cycle, often every 24 hours, but the exact interval can vary based on tenant load and the complexity of the rule. Waiting another 24 hours provides no guaranteed fix because the group may have been skipped due to a known issue or because the rule has not been marked for evaluation after the underlying user attribute change. For time-sensitive membership updates, relying on the automatic cycle is not the optimal choice.
Visual reference
Go deeper
Related to this question
Learn chapter
Global Administrator Best Practices
Key term
Hybrid identity
Hybrid identity is an approach that synchronizes and manages user identities across both on-premises directories and cloud-based services, allowing seamless access to resources in both environments.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.