Link: https://azure.microsoft.com/en-us/documentation/articles/active-directory-accessmanagement-simplerulegroup/
To enable dynamic membership for a particular group, perform the following steps:
- In the Azure portal, under the Groups tab, select the group you want to edit, and then in this group’s Configure tab, set the Enable Dynamic Memberships switch to Yes.
- You can now set up a simple single rule for the group that will control how dynamic membership for this group functions. Make sure the Add users where option is selected, and then select a user property from the list (for example, department, jobTitle, etc.),
- Next, select a condition (Not Equals, Equals, Not Starts With, Starts With, Not Contains, Contains, Not Match, Match), and finally specify a value for the selected user property. For example, if a group is assigned to a SaaS application and you enable dynamic memberships for this group by setting a rule whereby Add users where is set to the jobTitle that Equals(-eq)Sales Rep, all users within your Azure AD directory whose job titles are set to Sales Rep will have access to this SaaS application.
- Note that you can set up a rule for dynamic membership on security groups or Office groups. Dynamic Memberships for Groups require an Azure AD Premium license to be assigned to the administrator who manages the rule on a group and to all users who are selected by the rule to be a member of the group.
Here you can learn more about complex rules for dynamic group membership:
These articles provide additional information on Azure Active Directory.