I am starting to implement RBEs mostly for use as dynamic groups that
sync membership to an AD group.

If I create or modify the query of an Entitlement policy, I would like
that policy to be re-evaluated and users granted/revoked based on the
new query in the policy, but that doesn't seem to be how it works.

I have to specify users (or containers of users) to be re-evaluated
which means I may have to re-evaluate all users anytime I create or
modify a policy in order to make sure the right users have the modified

Am I understanding this correctly?

