All Guides
Microsoft 365 Governance

Microsoft 365 Groups vs Teams vs Distribution Lists

Five group types, each with a specific purpose. Australian SMBs often use the wrong ones, creating sprawl, security gaps, and licensing waste. This guide explains when to use each and how to clean up the mess.

Last updated October 20268 min read

The five group types in Microsoft 365

Microsoft 365 has five distinct group types. Each serves a different purpose. Confusing them creates sprawl, security gaps, and wasted licenses.

Microsoft 365 Group

Project teams, departments, ongoing collaboration

Includes

  • Shared mailbox
  • Shared calendar
  • Teams chat
  • SharePoint site
  • Planner
  • OneNote

Governance Note

Creates multiple assets. Requires ownership and lifecycle management.

Microsoft Teams

Real-time collaboration, chat-based teamwork

Includes

  • Chat channels
  • File storage (SharePoint)
  • Meetings
  • Apps and tabs

Governance Note

Creates underlying M365 Group. Monitor for sprawl.

Distribution List

Email-only broadcasting, announcements

Includes

  • Email distribution only

Governance Note

Low overhead. Suitable for static groups like "All Staff" or "Building A Occupants".

Security Group

Access control, permissions assignment

Includes

  • Azure AD security principal

Governance Note

Use for resource access, not collaboration. Often synced from on-prem AD.

Shared Mailbox

Departmental inboxes (info@, hr@, sales@)

Includes

  • Shared email inbox
  • No login credentials

Governance Note

Free up to 50GB. Requires licensed user as owner. No direct login.

Which group type for which scenario

Use this decision tree when staff request new groups or collaboration spaces.

ScenarioRecommendedWhy
Need to email a static list of peopleDistribution ListSimple, low overhead, no collaboration assets created
Department needs shared inbox (info@, hr@)Shared MailboxFree, multiple users can access, no license needed
Project team needs chat, files, and meetingsMicrosoft TeamsReal-time collaboration with full M365 suite
Ongoing department collaborationMicrosoft 365 GroupPersistent workspace with email, calendar, and files
Need to grant access to a resource or appSecurity GroupDesigned for permissions, not collaboration
External contractors need limited accessGuest in M365 Group or TeamsControlled external collaboration with audit trail

Governance implications for Australian businesses

Unmanaged groups create security, compliance, and licensing problems. Five issues we see repeatedly in Australian SMBs. The ACSC Essential Eight requires restricting administrative privileges and monitoring for unauthorised access, both impossible with poor group governance.

Group Sprawl

The Problem

Every Teams or M365 Group creates underlying assets (SharePoint site, Exchange mailbox, Planner). Unchecked creation leads to hundreds of orphaned groups consuming licenses and creating security risk.

The Fix

Implement group creation policies. Require approval for external sharing. Set expiration policies (e.g., groups expire after 365 days unless renewed). Review quarterly using Microsoft 365 admin centre.

Permission Creep

The Problem

Users accumulate access across multiple groups over time. Departing staff may retain access if group membership is not reviewed.

The Fix

Assign at least two owners per group. Review membership quarterly. Use Access Reviews in Entra ID for automated recertification. Remove leavers within 24 hours.

External Sharing Risk

The Problem

Guests added to Teams or M365 Groups gain access to all underlying assets including SharePoint files and conversations. Often overlooked during offboarding.

The Fix

Set external sharing to "Existing guests only" or require approval. Audit guest access monthly. Document which groups allow external members.

Data Residency

The Problem

Australian businesses under the Privacy Act must know where data is stored. M365 Groups create SharePoint sites that default to Australian data centres but can be misconfigured.

The Fix

Verify tenant data location in Microsoft 365 admin centre. Document which groups store sensitive data. Apply sensitivity labels where required.

Naming Conflicts

The Problem

Inconsistent naming (e.g., "Marketing", "Marketing Team", "Marketing 2026") makes search and governance difficult.

The Fix

Implement naming policy (e.g., "DEPT-Project-YYYY"). Use prefixes for departments. Document in onboarding materials.

Privacy Act and data residency

Australian businesses under the Privacy Act must know where personal information is stored. Every M365 Group and Teams creates a SharePoint site. Verify your tenant data location is set to Australia. Document which groups store sensitive data (HR, Finance, Client records). Apply sensitivity labels where required. External guests must be tracked and reviewed quarterly.

The OAIC can impose penalties for serious or repeated breaches of the Privacy Act. In recent reporting periods, a significant share of notifiable data breach reports came from organisations with fewer than 50 staff, most involving unauthorised access due to poor access controls.

Seven-step group cleanup for Australian SMBs

Follow this process to clean up group sprawl. Expect to find 20 to 40 percent of groups are orphaned or duplicated in typical Australian SMBs with 50 to 200 staff.

1

Inventory all groups

Export all M365 Groups, Teams, and Distribution Lists from Microsoft 365 admin centre. Include owner count, member count, creation date, and last activity date.

2

Identify orphaned groups

Flag groups with zero owners, zero members, or no activity in 180+ days. These are candidates for deletion or archival.

3

Review external guests

Export all guest users. Verify each guest still requires access. Remove guests associated with completed projects or departed contacts.

4

Consolidate duplicates

Merge groups serving the same purpose (e.g., "Marketing" and "Marketing Team"). Migrate files and conversations to the primary group, then delete the duplicate.

5

Document ownership

Assign at least two owners per active group. Document in a central register. Include purpose, expected lifespan, and data classification.

6

Implement expiration policy

Configure group expiration in Entra ID (e.g., 365 days). Owners receive renewal notices 30, 15, and 7 days before expiration. Groups not renewed are deleted.

7

Set up quarterly reviews

Schedule recurring Access Reviews in Entra ID. Owners must certify group membership quarterly. Unresponsive owners trigger admin review.

Related: SharePoint Information Architecture, M365 Security Baseline, Entra ID Deep Dive.

Common questions

What is the difference between a Microsoft 365 Group and a distribution list?
A distribution list only forwards emails to members and creates no other assets, while a Microsoft 365 Group gives members a shared mailbox, shared calendar, SharePoint site, Planner plan and optional Teams team for full collaboration.
Does every Microsoft Team have an underlying Microsoft 365 Group?
Yes. Every Teams team is backed by a Microsoft 365 Group, which creates the SharePoint site, mailbox and other connected services. You can have a group without Teams, but you cannot have Teams without a group.
When should I use a shared mailbox instead of a Microsoft 365 Group?
Use a shared mailbox when a department needs a single email address like info@ or hr@ that multiple staff can monitor, and you do not need the SharePoint site, calendar or Teams collaboration that comes with a full Microsoft 365 Group.
How do I stop group sprawl in Microsoft 365?
Enable group creation policies so only approved staff can create groups, set an expiration policy in Entra ID so inactive groups are flagged for deletion after a set period, and run quarterly reviews using Access Reviews to certify membership.
Do Microsoft 365 Groups store data in Australia?
Microsoft 365 Groups create SharePoint sites that default to your tenant data location, which you can verify is set to Australia in the Microsoft 365 admin centre, but misconfiguration can place data elsewhere so verify the setting and apply sensitivity labels to groups holding personal information.
How often should I review external guest access in Microsoft 365 Groups?
Review guest access at least quarterly by exporting guest users from the admin centre and removing any associated with completed projects or departed contacts, and set external sharing to existing guests only or require approval for new guests.

Need help cleaning up your Microsoft 365 groups

We audit Microsoft 365 tenants for Australian SMBs and provide a prioritised remediation plan. Typical engagements find 20 to 40 percent of groups are orphaned, duplicated, or misconfigured.