
Explanation:

Step 1 - Scenario
A user named User1 was a member of a dynamic security group (Group1).
User1 is no longer a member of that group.
You need to determine why User1 was removed by searching the audit log.
Step 2 - How group membership changes are logged in Microsoft 365 audit logs Microsoft 365 audit logs record group membership activities in Azure AD. The most relevant activities for a user disappearing from a group are:
Removed member from group - Directly indicates that a user was removed from a group.
Updated group - Logged when group properties or membership rules (for dynamic groups) are modified. If Group1 is a dynamic group, changes to membership rules could have caused User1 to no longer qualify, and this would appear as an Updated group event.
Step 3 - Why not other options
Deleted user / Deleted group: Would mean the entire user or group object was deleted, not just removal.
Changed user password, Reset user password, Set license properties, Changed user license: These are account- related, not group membership-related.
Added member to group: The opposite action.
Step 4 - Microsoft Reference
From Microsoft documentation:
Audit logs include events such as when a member is added or removed from a group, and when group properties or membership rules are updated.
Reference: Search the audit log in the Microsoft Purview compliance portal