Dynamic Groups are updated daily at 3:00am by default.
There are 2 scheduled tasks that run in tandem, which are:
During this time you may see event IDs 2523 or 2524 logged in the Active Roles event log if an error occurs in updating the group.
Active Roles Dynamic Group updater is designed to stop if such an error occurs, such as in this example:
Error when updating Dynamic Group.
Failed to update membership list of Dynamic Group.
Details: Administration Service encountered an error when making changes to the object 'CN=group,OU=Group,DC=mydomain,DC=com'. The specified account does not exist. (Exception from HRESULT: 0x80070525).
This functionality is by design.
If Active Roles detects an error when updating the Dynamic Group, it halts the update and the group may end up in an incorrect membership state. The Dynamic Group must be manually rebuilt by opening the group and clicking Rebuild.
For reference, the membership list of a Dynamic Group is updated in any of these cases:
If error 2523 or 2524 occurs, open the Dynamic Group and click the Rebuild button on the Members tab. It is recommended to also review and validate the configured rules.