3.2. Users, Groups, Devices, and Licenses
💡 First Principle: Directory objects are only as trustworthy as their lifecycle: how they're created (accurately, at scale), how they're grouped (so access follows attributes, not tickets), and how they're retired. Automate attribute-driven behavior — dynamic membership, group-based licensing — and the directory maintains itself; manage by hand and it rots.
The operational payoff shows up everywhere downstream: CA policies scope to groups, access packages contain groups, licenses flow through groups. Get grouping and attributes right here, and Phases 2 and 5 inherit clean targeting; get them wrong and every policy needs exceptions.
⚠️ Common Misconception: Dynamic group membership updates the instant an attribute changes. Evaluation is asynchronous — minutes typically, longer under load — so access, licenses, and policy scoped through a dynamic group lag the attribute edit. Stems about "immediately" and dynamic groups are testing exactly this.