Creating a dynamic group for Purview policies to apply to E3/E5 users

Shane Remelt 20 Reputation points
2025-03-05T14:25:18.06+00:00

I am working on configuring a Purview Exchange policy to encrypt data shared outside our organization. I want to include users through a dynamic security group specifically for E3 and E5 licensed users. The challenge is that the group needs to automatically update as user licenses change, but currently, Purview only supports mail-enabled groups or distribution groups for policy application.

Unfortunately, converting this dynamic security group into a mail-enabled group is not feasible in our setup. Could you advise on any potential workarounds for this limitation? How do other organizations manage to apply Purview policies to all new users with assigned licenses without manually adding them to a distribution group every time a license is assigned?

Additionally, if I were to apply the policy broadly to all users, are there any implications for those who do not have the necessary licenses? I'm concerned about the impact this might have on users who aren't covered under the appropriate licensing terms.

Thank you for any insights or advice you can provide.

Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,450 questions
0 comments No comments
{count} votes

Accepted answer
  1. Vasil Michev 115.3K Reputation points MVP
    2025-03-05T16:39:25.15+00:00

    You should be able to also use Microsoft 365 Groups for scoping, including those with dynamic membership. Have you tried that?


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.