Solution · Dynamic Group Management

Dynamic Group Management

Automate group membership and resource collections with ABAC policies—sync populations to Microsoft Entra ID and SAP IAS, scope authorization to dynamic resource sets, and fulfill changes through governed orchestration with Proof Chain evidence.

Collections & Dynamic Group Engine on Identity Fabric

Policy-driven membership—not manual group spreadsheets

The Collections & Dynamic Group Engine (DGE) keeps external group memberships and resource collections aligned with identity attributes. Administrators define External Sync Policies with ABAC rule expressions; when profiles change, the engine evaluates rules, computes add/remove deltas, and drives fulfillment into target systems. Resource Collections group applications, servers, and other resources for authorization policies—static lists or dynamic rules—so access stays consistent as the estate grows.

Deterministic membership from attributes, with auditability from policy change to fulfilled receipt.

Core capabilities

External Sync Policies

Define which identities belong in an external group (for example Entra ID or SAP IAS) using attribute rules such as country, department, or job code. Preview affected identities before enabling, then let the engine sync membership automatically.

Resource Collections

Group resources by type—applications, groups, servers—for authorization scoping. Use static membership or dynamic rules so policies reference collections instead of naming every asset.

Dynamic Group Engine

Evaluate ABAC rules on policy and identity attribute events, compute membership deltas, and emit governed access directives for orchestrated add/remove operations.

Proof Chain assurance

Policy changes and membership operations flow through fulfillment with receipts and proof records—supporting audit, correlation, and separation of duties for policy authors and operators.

How it works

From policy definition through governed fulfillment—without manual group edits in target directories.

  1. Step 1

    Define policy

    Author External Sync Policies or dynamic Resource Collections with reviewed ABAC expressions in Identity Fabric governance administration.

  2. Step 2

    Preview impact

    See how many identities or resources match before activation—narrow rules when populations are unexpectedly large.

  3. Step 3

    React to change

    When identity attributes or collection rules change, DGE recomputes membership and determines adds and removals.

  4. Step 4

    Fulfill with evidence

    Orchestration executes target-system operations; Proof Chain captures the path from directive to receipt.

Platform depth

ABAC rule expressions

Combine conditions with and/or—equals, in, contains, comparisons, and null checks—against authoritative identity and resource attributes.

Entra ID & SAP IAS sync

Target external groups in cloud identity systems with configured add/remove operations—eliminating manual membership churn for location and role cohorts.

Profile-driven updates

When identity attributes change, DGE recomputes membership. Most updates propagate within a few minutes; higher volume or target API rate limits can extend timing.

Authorization scoping

Reference Resource Collections in policies so roles like finance analyst access a collection of finance applications—not a brittle list per app.

Static and dynamic collections

Mix manually curated resource sets with rule-based collections that expand or contract as attributes change.

Governed policy lifecycle

Enable, pause, or retire policies with clear behavior; high-impact rules can follow approval workflows before activation.

Example scenarios

Regional support groups

Automatically maintain an Entra security group for employees where country and department match—e.g. German Helpdesk staff—without ticket-driven group edits.

Department transfer

When department changes, remove old cohort memberships and add new ones so access tracks the current role—not the previous one.

Finance application portfolio

Grant read access to a Finance-Applications collection; new apps added to the collection inherit policy without rewriting every rule.

For administrators & IGA teams

Identity governance and IT operations teams configure External Sync Policies, Resource Collections, monitoring, and recompute when migrating legacy group membership.

For workforce users

Workforce users can review static vs. dynamic group membership in the Identity Fabric portal (My Access), see which attributes drive dynamic membership, and use standard access requests when an exception is required.

Deploy Collections & DGE with Identity Governance on Identity Fabric, or discuss scope with Sales.

Get Started

Plan Collections & DGE on Identity Fabric

Work with our team on policy design, Entra and SAP IAS targets, coexistence with static groups, and phased rollout with Identity Governance.

Request Demo See the platform in action
Talk to an Expert Technical consultation
EmpowerID AI

EmpowerID AI Assistant

Online

EmpowerID AI
EmpowerID AI
Hello! How can I help you today?
05:10 PM

Suggested questions:

Powered by EmpowerID AI