Reference
Group
All Entra ID groups in your Tenant (Security groups, Microsoft 365 groups)
Part of the Microsoft 365 inventory.
Scan settings
| Default scanning interval | Allowed scanning intervals | Data removal during incremental scan |
|---|---|---|
| Daily | Daily, Weekly, Bi-Weekly, Monthly, Never, Initial | No |
Properties
| Property | Type | Description | Automation placeholder |
|---|---|---|---|
| Classification | String | Describes a classification for the group (such as low, medium or high business impact) | {{Group.Classification}} |
| Initially Scanned | DateTime | Shows when this object was initially found in a scan. | {{Group.CreatedTime}} |
| Description | String | An optional description for the group | {{Group.Description}} |
| Display Name | String | {{Group.DisplayName}} | |
| String | The SMTP address for the group, for example | {{Group.Email}} | |
| Email enabled | Boolean | Specifies whether the group is mail-enabled | {{Group.EmailEnabled}} |
| Expiration Date | DateTime | Timestamp of when the group is set to expire | {{Group.ExpirationDate}} |
| Created Date | DateTime | Timestamp of when the group was created | {{Group.GroupCreatedTime}} |
| Group Id | String | The unique identifier for the group | {{Group.GroupId}} |
| Group Privacy | String | Specifies the group join policy and group content visibility for groups Allowed values: Hidden Membership, Private, Public. | {{Group.GroupPrivacy}} |
| Group Type | String | Specifies the group type and its membership Allowed values: Distribution Group, Microsoft 365, Security Group. | {{Group.GroupType}} |
| onPremises Sync Enabled | Boolean | true if this user object is currently being synced from an on-premises Active Directory (AD); otherwise the user isn't being synced and can be managed in Microsoft Entra ID. | {{Group.InCloud}} |
| Last scan update | DateTime | Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. | {{Group.LastModifiedTime}} |
| MailNickname | String | The mail alias for the group, unique for Microsoft 365 groups in the organization. Maximum length is 64 characters. | {{Group.MailNickname}} |
| Membership Type | String | Specifies the group membership type. Allowed values: Assigned, Dynamic. | {{Group.MembershipType}} |
| Preferred Data Location | String | The preferred data location for the Microsoft 365 group. By default, the group inherits the group creator's preferred data location. | {{Group.PreferredDataLocation}} |
| Risk Score | Int32 | Stores risk score | {{Group.RiskScore}} |
| Risk Score Update | DateTime | Stores risk score update | {{Group.RiskScoreLastUpdate}} |
| Risk Score Value | String | Stores risk score value like Low_Low | {{Group.RiskScoreValue}} |
| Security Identifier | String | Contains the on-premises security identifier (SID) for the group that was synchronized from on-premises to the cloud. | {{Group.SecurityIdentifier}} |
| Team Connected | Boolean | Specifies Team as group resources that are provisioned as part of creating a Microsoft 365 group | {{Group.TeamConnected}} |
| SharePoint Site | Site | Default scanning interval: Monthly. | {{Group.Web}} |
| SharePoint Site Url | String | {{Group.WebName}} |
Relations
| Relation | Service | Description |
|---|---|---|
| App Role Assignment | Entra ID | All app role assignments in Entra ID |
| Directory Role | Entra ID | Memberships of the groups in directory roles |
| Group | Microsoft 365 | |
| Sensitivity Label | Microsoft 365 | Sensitivity label of the group |
| User | Microsoft 365 | Users which are members of the group |
| User | Microsoft 365 | Users which are owners of the group |
| File Sharing | OneDrive | File sharing shared with the group |
| Plan | Planner | All Planner plans |
| Power App (Canvas App) | Power Apps | PowerApps used by the Group |
| Power App (Canvas App) | Power Apps | PowerApps owned by the Group |
| Flow | Power Automate | Flows owned by the group |
| Flow | Power Automate | Flows used by the group |
| Workspace | Power BI | Workspaces in which group is admin |
| Workspace | Power BI | Workspaces in which group is contributor |
| Workspace | Power BI | Workspaces in which group is member |
| Workspace | Power BI | Workspaces in which group is viewer |
| SharePoint Group | SharePoint | SharePoint Group with an access |
| File Sharing | SharePoint | File sharing that invites group |
| List/Library | SharePoint | Lists which group has access to |
| File | SharePoint | File in which Group has access to |
| Folder | SharePoint | Folder in which group has access to |
| Site Collection | SharePoint | Site collection of the group |
| Site Collection | SharePoint | Site which group has access to |
| Site Collection | SharePoint | Site collections in which group is admin |
| Site Collection | SharePoint | Site collections in which group is member |
| Site Collection | SharePoint | Site collections in which group is owner |
| Site Collection | SharePoint | Site collections in which group is visitor |
| Site | SharePoint | All root site and subsites of a SharePoint site collection |
| Site | SharePoint | Sites in which group is admin |
| Site | SharePoint | Sites in which group is member |
| Site | SharePoint | Sites in which group is owner |
| Site | SharePoint | Sites in which group is visitor |
| Site | SharePoint | Web which group has access to |
| Team | Teams | All teams in your tenant |
| Community | Viva Engage | All Viva Engage communities in your tenant |
Segments
| Segment | Description |
|---|---|
| Distribution Groups | All active distribution groups |
| Groups with Teams | All groups with Teams connected |
| Microsoft 365 Groups | All active Microsoft 365 groups |
| Private Groups | All private groups |
| Public Groups | All public groups |
| Security Groups | All active security groups |
Actions
- Set Sensitivity Label for a Microsoft 365 Group
- Delete group
- Add or remove owner group to/from a Flow
- Add or remove run-only group to/from a Flow
- Add group to a group
- Add user to a group
- Remove group from a group
- Remove user from a group
- Add or remove owner group to/from a Power App
- Add or remove run-only group to/from a Power App
- Add or remove admin group to/from a Workspace
- Add or remove contributor group to/from a Workspace
- Add or remove member group to/from a Workspace
- Add or remove viewer group to/from a Workspace
- Add or remove group to/from a SharePoint File with a specified permission
- Add or remove group to/from a SharePoint File Sharing
- Add or remove group to/from a SharePoint Folder with a specified permission
- Add or remove group to/from a SharePoint List with a specified permission
- Add or remove group to/from a SharePoint Site with a specified permission
- Add or remove group to/from a SharePoint Site Collection with a specified permission
Policies that check this object
| Policy | Severity | Description |
|---|---|---|
| Groups with disabled user accounts | Medium | Shows groups with users (owners and members) that have disabled accounts |
| Groups with external users | Medium | Shows groups that have external users |
| Groups with external owners | High | Shows groups that have external users as owners |
| Groups with very few owners | Medium | Shows Groups which have fewer owners than defined threshold (default 2 owners) |