Said It Here

How to figure out what M365 or AD groups actually do

Microsoft lacks built-in reports showing what specific permissions or resources a group manages, forcing administrators to manually query every underlying file share, application, and service. This makes it impossible to determine if groups are actually needed or safe to delete without risking system disruptions.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Building a custom inventory from Microsoft Graph covering owners, members, permissions, last activity, SharePoint association, and creation date, then checking audit logs.
  2. 2
    Manually checking system descriptions, file shares, and ACL permissions
  3. 3
    Searching through Git repositories and M365 configurations for hits
  4. 4
    Relying on log collectors and group membership change auditing

In their words

Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.

r/sysadmin3 people · September 2026

“They wanted to know how would i cleanup messy AD environment and figure out which AD groups are safe to delete, without absolutely no disruption to anything”source ↗

wrootlt · r/sysadmin · 19 upvotes

“I was hoping there was some Powershell command, or menu somewhere, that basically tells me "Group A manages permissions for SharePoint Site B and C, Policy D" and so on. But I literally can't find anything at all.”source ↗

“How have you dealt with sorting through a big list of Groups in M365 and finding out if they're actually needed?”source ↗

“I'm surprised Microsoft doesn't have these kind of reports available”source ↗

jactheblock · r/sysadmin · 2 upvotes

“To understand what groups are in use, you actually need to query the services, File shares, applications etc to know what groups are in use. This is not an AD question at all.”source ↗

Asleep_Spray274 · r/sysadmin · 1 upvotes

Where this came up

People with this problem also raised