Microsoft 365 group access analysis

One "add to group" can open 40,000 files. See the 40,000 before you approve.

Groups are how access multiplies quietly in Microsoft 365: groups contain groups, a guest sits three levels down, and a membership approved in ten seconds unlocks sites nobody mentioned. 1Security resolves every group to what it actually grants - total effective users, external users among them, and the files, sites and mailboxes behind it - so you approve, scope down or retire with a number in front of you.

  • 6
    group types kept distinct: Microsoft 365 groups, security groups, SharePoint groups, directory roles, distribution lists and mail-enabled security groups
  • 10 s
    how long a membership approval usually takes - here it comes with the sites, mailboxes and files it opens
  • 30-50%
    of groups in a typical tenant that carry an orphan signal: no owner, no members or no files behind them

The problem

A member list answers who. The question is what it opens.

A group membership list answers who is in the group. The question that matters is what being in it opens.

Approving a membership request is one of the most consequential things an admin does in a week, and it is normally done blind. The request says "add Anna to Marketing Collaboration". It does not say the group is nested inside two others, that the chain ends at a site holding 40,000 contract PDFs, or that three of the effective members are guests from a partner. Microsoft 365 group access analysis is the step missing between the request and its consequence.

Nesting is the mechanism. A guest added to one small group inherits reach across the tenant because that group sits inside a bigger one. A member list shows the small group with its 12 direct members. The consequence lives three hops away. 1Security joins the two on one row: the group, its total effective users, and the sites and files behind it.

Meanwhile the tenant fills with groups nobody governs. It is common for 30-50% of groups to have no owner, no members or no files behind them, and for distribution lists everyone forgot to keep receiving mail from outside. Their permissions keep working; nobody approves new members and nobody reviews why the group exists.

What you get

Every group row answers "what does this unlock?" before you open anything.

Sort by accessible files, filter by external users, walk the nesting in both directions - the Groups screen turns a membership list into a consequence list.

  • Direct members vs total users

    Both columns on every row. When 12 direct members become 340 total users, nesting is in play, and you know before you approve anything.

  • Reach in files, sites and mailboxes

    Accessible files, accessible sites and affected items per group, so a membership decision is made with a number - "this group opens 40,000 files, 2,100 with sensitive data".

  • External users inside the effective membership

    Guests counted through nesting, not just on the direct list. One guest in one small nested group is exactly how reach crosses the company boundary unnoticed.

  • Directory roles treated as privilege

    Admin role groups are their own type here. Every membership in one is privileged access, and the row reads that way - with external and total counts beside it.

  • The nesting chain, walkable both ways

    Contained groups and parent groups on the same row, so you move up toward what a group unlocks or down toward where a user's access came from.

  • Orphan filters

    No owners, no members, no files - one click each. The dead distribution list still receiving external mail shows up here with its last inbound date.

How deep it goes

Three questions worth asking this week - each under a minute.

The filter drawer narrows by group type, external membership, a specific user's groups, orphan indicators, sensitive info, alerts, sharing links and email activity.

Privilege check: filter type to Directory Role and read the external and total user counts. Every membership here is an admin privilege. If a role group has effective members you cannot name - it is common to find a guest or a service account inherited through nesting - that is the first finding of the review, and it takes about a minute to reach.

Guest reach audit: filter to groups with external users, sort by accessible files descending. This ranks your partner and vendor invitations by how much data each one actually opened. In a typical tenant the top ten groups on that list account for most of the externally reachable files.

Dead lists that still receive: filter to distribution lists with external members and recent inbound email. Mail keeps flowing to the outside through a list everyone forgot existed. Here it is one filter, with a last-received date on the row.

In practice

Before you approve the request: a 30-second read.

The four things to look at on the group row before clicking Approve.

  1. 01

    Open the group in Groups

    Total users versus direct members tells you immediately whether nesting is in play. "12 direct, 340 total" means the group is inside something bigger, and so is the new member.

  2. 02

    Read what it unlocks

    Accessible files and sites, plus how many carry sensitive information or a sensitivity label. That is what the new member inherits on day one - and what a compromised member could walk out with.

  3. 03

    Check the boundary

    External users in the effective membership. If the group already crosses the company boundary, adding reach to it compounds; if the new member is a guest, you now know exactly what you are opening.

  4. 04

    Approve, scope down or split

    Approve because the number is fine, ask for a narrower group, or split the group with an automation - staged behind the 72-hour review window like every other change, and logged in Actions.

What 1Security adds

From membership to consequence

A membership tool answers who is in the group. This is a consequence tool: what being in it opens.

  • Total effective membership with nesting resolved to any depth, next to the direct count
  • External users counted inside the effective membership, not only on the direct list
  • How many files, sites and mailboxes a single group grants access to
  • Whether sensitive information or labelled files sit behind that access
  • Parent groups as well as contained groups, so the chain walks both ways
  • Groups with no owners at all, still granting live access - filtered in one click
  • Sharing links granted to a group rather than to a person
  • Distribution lists with external members and recent inbound mail, with the last-received date

Scale

Nesting is a graph problem, and it is kept solved.

Resolving effective membership properly means traversing the whole group graph, not sampling two levels - and doing it across every group in a tenant with tens of thousands of them and 40 million files. 1Security keeps that computation current instead of running it as a report you wait for.

  • 500M+
    files in the largest production tenants for which group reach is resolved and kept current
  • 6
    group types resolved to any nesting depth, without a level limit or a sampling cap
  • 3
    orphan signals on every row - no owners, no members, no files - one filter each

Related

Where this fits

Groups grant the access; users hold it and files receive it. The three screens are three views of the same permission graph, and an investigation usually touches all of them.

  • User access review

    What one identity can open - the 200,000 files behind its 11 groups - and whether the account should still exist.

    See users
  • File permissions

    The other end of the chain: who can open a given document, through which group or link, and why.

    See files
  • Access management

    Turning findings into least privilege across the tenant, with staged, reviewable changes.

    See access management

FAQ

Questions teams ask first

Which group types are covered?

All six that carry security weight in Microsoft 365: Microsoft 365 groups, security groups, SharePoint groups, directory roles, distribution lists and mail-enabled security groups. They are kept distinct, because a distribution list and a directory role are not the same kind of object.

How deep does nesting resolution go?

To the end of the chain. Effective membership is computed over the whole group graph, so a user four groups deep counts in the total the same way a direct member does. There is no level limit and no sampling.

Can I see which groups a specific person is in?

Yes. Filtering by a specific user is built into the filter drawer and returns inherited memberships, not only direct ones. That is the filter most offboarding reviews actually need.

Why do ownerless groups matter so much?

Because nobody approves new members and nobody reviews the purpose, but the permissions keep working indefinitely. An ownerless group with sensitive information within reach is access with no accountable human attached to it. It is common for a third of a tenant's groups to carry at least one orphan signal.

Does it show SharePoint groups too?

Yes. SharePoint groups are a separate type here because they grant site access on their own, outside the directory - including them is what keeps site permissions and directory governance in one review.

See what your groups actually unlock.

Connect read-only and every group arrives with its total users, external users and reachable files the same day. Directory roles are usually the first surprise.

Or keep approving membership requests by the name of the group.