Northwind Traders
Groups with no members at all. Delete the ones nobody needs; a dynamic group here has a rule that matches nobody. Empty groups older than 30 days are flagged.
| Group | Kind | Membership | Created | |
|---|---|---|---|---|
| Group creators low | Security group | Assigned | 10 Jan 2025 |
Groups with other groups as members. Everyone in the inner groups gets what the outer group gives, which is easy to miss; 3 or more levels are flagged.
| Group | Kind | Groups inside | Inside of | Levels below | Members |
|---|---|---|---|---|---|
| Finance alerts | Mail-enabled security group | VPN Users | Info | 2 | 2 |
| Info low | Distribution list | Finance alerts | 3 | 2 | |
| VPN Users | Security group | Group creators | Finance alerts | 1 | 2 |
Groups whose members Entra ID works out from a rule (needs Entra ID P1). A paused rule stops adding joiners and removing leavers, so it's flagged.
| Group | Kind | Rule | Processing | Members |
|---|---|---|---|---|
| All Staff | Security group | (user.userType -eq "Member") | Running | 2 |
Teams and Microsoft 365 groups the expiration policy will delete within 90 days. One that's used renews itself; otherwise its owners are emailed to renew it, so a group with no owner who can sign in is flagged, as is one due within 30 days. A deleted group can be restored for 30 days.
Groups that can be given admin roles, so being a member of one is being an admin. Their owners can add anyone; a guest in one is flagged.
| Group | Kind | Members | Guests | Owners | Created |
|---|---|---|---|---|---|
| Helpdesk admins medium | Security group | 2 | 1 | 10 Jan 2025 |
Groups that still hold accounts whose sign-in is blocked, usually leavers. Access the group gives is handed back the moment the account is unblocked, and the member counts others see are wrong; blocked accounts in a role-assignable group are flagged higher.
| Group | Kind | Blocked accounts | Blocked | Members |
|---|---|---|---|---|
| Marketing low | Microsoft 365 group | Robert Hughes | 1 | 12 |
| Project Phoenix low | Team | Robert Hughes | 1 | 3 |
Every group in the tenant, with its direct members (people, devices, apps and groups).
| Group | Kind | Membership | Members | Groups inside | Inside of | Created | Expires |
|---|---|---|---|---|---|---|---|
| Operations | Team | Assigned | 11 | 4 Mar 2024 |
Members are direct members. Teams and Microsoft 365 groups can't contain other groups. Delete or change groups in the Microsoft Entra admin center (Groups), or in on-premises AD for synced groups; Office Sentry only reads them.
Data from Group nesting (), Groups and Teams (), Users ().