A cloud-based identity and access management service for securing user authentication and resource access
There's a built-in condition for that "Direct Reports for". Details are here: https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-membership#create-a-direct-reports-rule