The five group types in Microsoft 365
Microsoft 365 has five distinct group types. Each serves a different purpose. Confusing them creates sprawl, security gaps, and wasted licenses.
Microsoft 365 Group
Project teams, departments, ongoing collaboration
Includes
- Shared mailbox
- Shared calendar
- Teams chat
- SharePoint site
- Planner
- OneNote
Governance Note
Creates multiple assets. Requires ownership and lifecycle management.
Microsoft Teams
Real-time collaboration, chat-based teamwork
Includes
- Chat channels
- File storage (SharePoint)
- Meetings
- Apps and tabs
Governance Note
Creates underlying M365 Group. Monitor for sprawl.
Distribution List
Email-only broadcasting, announcements
Includes
- Email distribution only
Governance Note
Low overhead. Suitable for static groups like "All Staff" or "Building A Occupants".
Security Group
Access control, permissions assignment
Includes
- Azure AD security principal
Governance Note
Use for resource access, not collaboration. Often synced from on-prem AD.
Shared Mailbox
Departmental inboxes (info@, hr@, sales@)
Includes
- Shared email inbox
- No login credentials
Governance Note
Free up to 50GB. Requires licensed user as owner. No direct login.
Which group type for which scenario
Use this decision tree when staff request new groups or collaboration spaces.
| Scenario | Recommended | Why |
|---|---|---|
| Need to email a static list of people | Distribution List | Simple, low overhead, no collaboration assets created |
| Department needs shared inbox (info@, hr@) | Shared Mailbox | Free, multiple users can access, no license needed |
| Project team needs chat, files, and meetings | Microsoft Teams | Real-time collaboration with full M365 suite |
| Ongoing department collaboration | Microsoft 365 Group | Persistent workspace with email, calendar, and files |
| Need to grant access to a resource or app | Security Group | Designed for permissions, not collaboration |
| External contractors need limited access | Guest in M365 Group or Teams | Controlled external collaboration with audit trail |
Governance implications for Australian businesses
Unmanaged groups create security, compliance, and licensing problems. Five issues we see repeatedly in Australian SMBs. The ACSC Essential Eight requires restricting administrative privileges and monitoring for unauthorised access, both impossible with poor group governance.
Group Sprawl
The Problem
Every Teams or M365 Group creates underlying assets (SharePoint site, Exchange mailbox, Planner). Unchecked creation leads to hundreds of orphaned groups consuming licenses and creating security risk.
The Fix
Implement group creation policies. Require approval for external sharing. Set expiration policies (e.g., groups expire after 365 days unless renewed). Review quarterly using Microsoft 365 admin centre.
Permission Creep
The Problem
Users accumulate access across multiple groups over time. Departing staff may retain access if group membership is not reviewed.
The Fix
Assign at least two owners per group. Review membership quarterly. Use Access Reviews in Entra ID for automated recertification. Remove leavers within 24 hours.
External Sharing Risk
The Problem
Guests added to Teams or M365 Groups gain access to all underlying assets including SharePoint files and conversations. Often overlooked during offboarding.
The Fix
Set external sharing to "Existing guests only" or require approval. Audit guest access monthly. Document which groups allow external members.
Data Residency
The Problem
Australian businesses under the Privacy Act must know where data is stored. M365 Groups create SharePoint sites that default to Australian data centres but can be misconfigured.
The Fix
Verify tenant data location in Microsoft 365 admin centre. Document which groups store sensitive data. Apply sensitivity labels where required.
Naming Conflicts
The Problem
Inconsistent naming (e.g., "Marketing", "Marketing Team", "Marketing 2026") makes search and governance difficult.
The Fix
Implement naming policy (e.g., "DEPT-Project-YYYY"). Use prefixes for departments. Document in onboarding materials.
Privacy Act and data residency
Australian businesses under the Privacy Act must know where personal information is stored. Every M365 Group and Teams creates a SharePoint site. Verify your tenant data location is set to Australia. Document which groups store sensitive data (HR, Finance, Client records). Apply sensitivity labels where required. External guests must be tracked and reviewed quarterly.
The OAIC can impose penalties for serious or repeated breaches of the Privacy Act. In recent reporting periods, a significant share of notifiable data breach reports came from organisations with fewer than 50 staff, most involving unauthorised access due to poor access controls.
Seven-step group cleanup for Australian SMBs
Follow this process to clean up group sprawl. Expect to find 20 to 40 percent of groups are orphaned or duplicated in typical Australian SMBs with 50 to 200 staff.
Inventory all groups
Export all M365 Groups, Teams, and Distribution Lists from Microsoft 365 admin centre. Include owner count, member count, creation date, and last activity date.
Identify orphaned groups
Flag groups with zero owners, zero members, or no activity in 180+ days. These are candidates for deletion or archival.
Review external guests
Export all guest users. Verify each guest still requires access. Remove guests associated with completed projects or departed contacts.
Consolidate duplicates
Merge groups serving the same purpose (e.g., "Marketing" and "Marketing Team"). Migrate files and conversations to the primary group, then delete the duplicate.
Document ownership
Assign at least two owners per active group. Document in a central register. Include purpose, expected lifespan, and data classification.
Implement expiration policy
Configure group expiration in Entra ID (e.g., 365 days). Owners receive renewal notices 30, 15, and 7 days before expiration. Groups not renewed are deleted.
Set up quarterly reviews
Schedule recurring Access Reviews in Entra ID. Owners must certify group membership quarterly. Unresponsive owners trigger admin review.
Related: SharePoint Information Architecture, M365 Security Baseline, Entra ID Deep Dive.
Common questions
What is the difference between a Microsoft 365 Group and a distribution list?
Does every Microsoft Team have an underlying Microsoft 365 Group?
When should I use a shared mailbox instead of a Microsoft 365 Group?
How do I stop group sprawl in Microsoft 365?
Do Microsoft 365 Groups store data in Australia?
How often should I review external guest access in Microsoft 365 Groups?
Need help cleaning up your Microsoft 365 groups
We audit Microsoft 365 tenants for Australian SMBs and provide a prioritised remediation plan. Typical engagements find 20 to 40 percent of groups are orphaned, duplicated, or misconfigured.

Remote Support