What it's for
"Why does this account behave differently from that one?" and "what's actually different between these two groups?" are hard to answer by opening two cards and reading them side by side from memory. Compare reads the whole property set of two objects at once and lines them up in one grid, so a difference — a blocked sign-in, a missing licence, a group's mail settings — is something you can see rather than something you have to remember to check.
Picking what to compare
Choose Users or Groups first, then pick one object into each of the two boxes. Both boxes filter as you type, matching anywhere in the name or address — not just the beginning of a word — the same substring search every list in the app uses. Switching between Users and Groups clears both picks and any comparison already on screen.
Reading the result
The result is a grid with one row per property: Attribute (the underlying
Microsoft Graph name, such as mailNickname, rather than a friendly label),
Value A and Value B — headed with the two objects' own
display names so it is always clear which side is which — Type, and a
Values button on rows that need it (below). A row where the two sides differ
is tinted in the app's standing colour for "this changed."
Every readable property from both objects is included — a property present on only one side counts as a difference too — plus a handful of rows Compare adds because they answer questions a raw property never could: group and role memberships, admin roles and authentication methods for a user; members and owners for a group; and a friendly licences (names) row that turns subscription GUIDs into the product names you actually recognise.
A search box above the grid filters by attribute name, and a Differences only checkbox hides everything that matches. A status line reports the totals — for example, "42 attributes · 5 differ."
Looking inside a multi-valued property
Some properties are not one value but a list — proxy addresses, assigned licences, a nested object. Cramming those onto one line would be unreadable, so a row like that gets a Values button instead, which opens the entries as their own list: one line per sub-property for a nested object, one line per entry for a collection. An entry present on only one side is checked off and tinted, the same "this changed" convention as the main grid. Order is never treated as a difference — a reordered collection with the same entries on both sides is not flagged.
What Compare does not do
- Only users and groups. They are the two kinds of object with a full, comparable Graph property set. Devices, mailboxes, contacts and admin roles are not offered here — see Directory & search for those.
- It never writes anything. Compare only reads; there is nothing on this page that changes either object. To act on what you find, open the object's own card from Users or Groups.
- A property neither side could be read for is shown, not hidden — with a note explaining why, and it is never counted as a difference either way.
Compare needs nothing beyond the baseline User.Read.All /
Directory.ReadWrite.All every install already has — see
Sign-in & permissions.