Groups

Microsoft 365 groups, distribution groups, mail-enabled security groups and plain security groups — four different objects that Microsoft's own tooling splits across two portals.

The four types

The list shows the type of every group, and the type decides what the card can do — which system masters it, whether it has a recycle bin, and which of the three mail-settings bodies it gets.

What each group type supports.
Type Mastered by Mail settings Recycle bin
Microsoft 365 Microsoft Graph Privacy, external senders, subscription, visibility in Outlook, Teams and the address list 30 days
Distribution Exchange Addresses, external senders, moderation, accepted senders, join and leave rules, address-list visibility Removed outright
Mail-enabled security Exchange The same, but the join and leave rules are fixed by Exchange Removed outright
Security Microsoft Graph None — it has no address Removed outright

The list filters on type, membership and on-premises synchronisation, and searches names, addresses and the group's alias — which is what a distribution list usually gets referred to by.

The group card

Six sections: General, Members, Owners, Member Of, Mail settings, Attributes.

General

Display name, description, alias, and membership type. Members and owners are added and removed on their own sections and write immediately, so Save covers only the properties here.

Assigned or dynamic membership

A dropdown, with the rule box appearing when you choose Dynamic. Converting a group to dynamic is destructive and asks for confirmation: the rule takes over the membership entirely and members added by hand are dropped. Converting back leaves the members it currently has, so that direction is not confirmed.

Dynamic membership requires Microsoft Entra ID P1. Nothing queryable tells the app whether your tenant has it, so the confirmation states the requirement rather than checking it — if the tenant is not licensed, Microsoft refuses the change.

The field is locked, with the reason shown under it, for the Exchange types — a dynamic distribution group is a different object with a different rule language — and for directory-synced groups.

Mail settings

One section that renders one of three bodies, because the underlying system differs by type. A security group gets a single line explaining that it has no address and therefore nothing to configure.

Microsoft 365 groups — privacy, whether people outside the organisation can email it, whether new members are subscribed, and whether it is hidden from Outlook and Teams or from the address list. This half needs no Exchange role, so it works in a customer tenant whose GDAP relationship does not include one.

Distribution and mail-enabled security groups — email addresses with alias management and a primary, external senders, moderation and moderators, accepted senders, join and leave restrictions, and address-list visibility. This half runs Exchange cmdlets, so it needs an Exchange role.

On a mail-enabled security group both join and leave restrictions are locked: Exchange forces them closed and refuses to open them. The card says so rather than showing a greyed control with no explanation.

A newly created Microsoft 365 group may not have these settings yet — several of them only exist once Exchange has provisioned the group's mailbox. That is a normal state, not an error, and revisiting the section retries the read.

Why some writes go through Exchange

Microsoft Graph refuses to edit a distribution or mail-enabled security group, or change its members and owners — they originate in Exchange. So for those two types the card routes its writes through Exchange cmdlets instead, while the reads still come from Graph.

Two consequences you will see:

  • Editing them needs an Exchange role rather than a directory one, and the most common failure is not a permissions problem at all: Exchange objects if the signed-in admin is not one of the group's own managers. The app bypasses that check explicitly, so if you still get a refusal it really is a role gap.
  • Changes take a few minutes to appear in the directory. The app updates its own view immediately instead of re-reading, because a re-read would show the old state and look like a silent failure. The success message says the directory may lag.

Members, Owners, Member Of, Attributes

  • Members and Owners — add and remove, writing immediately.
  • Member Of — the groups this group belongs to.
  • Attributes — the read-only dump of everything Graph knows, with search and a Hide empty toggle.

Creating a group

Pick the type first, since it decides everything else — and which system the group is created in. You can set the name, description, alias and initial members. A distribution or mail-enabled security group is created through Exchange and then re-read, because the creation response does not carry enough to populate a card.

Deleting a group

The delete panel is a preflight report, not a list of options — what deleting a group costs depends entirely on its type, and none of that is visible on the card. So the panel states it: who loses their membership, what licences the group hands out, whether the deletion can be undone, and which system will perform it. Then it offers one destructive button.

Group-based licensing is the consequence people miss

If the group assigns licences, every member who holds a licence only through this group loses it. Restoring the group later does not reassign those licences, even though everything else about the group comes back. This is the one line the panel highlights, and it is repeated in the confirmation.

Only a Microsoft 365 group is soft-deleted and restorable for 30 days. Security groups have no recycle bin, and the two Exchange types are removed outright — so the Deleted groups list can only ever contain Microsoft 365 groups, and it says so rather than letting a missing group read as a bug.

A group synchronised from on-premises AD cannot be deleted in the cloud at all. A role-assignable group — one that can hold directory roles — can only be deleted by a Privileged Role Administrator, which is why one group can fail while others delete fine.