---
title: Groups
description: See what membership in any group actually unlocks - nested members, hidden external users, and the files and sites a single group grants access to.
icon: Users
---

# Groups

The Groups screen answers a question most organizations can't: **"If someone lands in this group, what do they actually get?"** Groups are how access multiplies silently in Microsoft 365: groups contain groups, which contain more groups, and a single membership change can unlock thousands of files without any admin approving - or even noticing - the outcome.

## What You Can Achieve

<Cards>
  <Card
    title="See effective membership, not the illusion"
    description="Microsoft shows you direct members. 1Security also resolves nesting - total users and total external users including everyone inherited through contained groups, however deep."
  />
  <Card
    title="Measure a group's blast radius"
    description="Before approving a membership request or cleaning up an old group, see exactly how many files and sites it grants access to - and whether sensitive data is behind it."
  />
  <Card
    title="Find external users hiding in groups"
    description="A guest added to one nested group can quietly inherit reach across your tenant. Surface every group whose effective membership crosses the organization boundary."
  />
  <Card
    title="Retire ownerless groups"
    description="A group with no owners has nobody approving members or reviewing purpose. Find them, along with groups holding no files or no users, and clean up ungoverned access."
  />
</Cards>

## Group Types, Untangled

Microsoft 365 runs on six kinds of groups with very different security weight, and 1Security keeps them distinct: **Microsoft 365 groups**, **security groups**, **SharePoint groups**, **directory roles** (admin privileges - membership here is privileged access), **distribution lists**, and **mail-enabled security groups**.

For every group the screen separates **direct members** from **total users** (nesting resolved), and shows both **contained groups** and **parent groups** - so you can walk the inheritance chain in either direction.

## The Group List

Each row answers "what does this group unlock?" at a glance: member counts (direct, total, external), nesting depth in both directions, **accessible files** and **accessible sites**, affected items, sensitivity labels and sensitive info reachable through the group, sharing links granted to it, email traffic for mail-enabled groups, security alerts, and an activity sparkline. Click a group to open its drawer and see the members, resources, and activity behind those numbers.

The filter drawer narrows by group type, external vs. internal membership, a specific user's groups, **orphaned indicators** (no owners, no files, no users), sensitive info presence, security alerts, sharing-link characteristics, and email activity dates.

## Investigative Patterns

<Callout type="info">
  **Privilege check**: filter type **Directory Role** and scan the external and
  total user counts. Every membership here is an admin privilege - if a role
  group's effective membership includes anyone you can't name, you've found your
  first finding.
</Callout>

- **Guest reach audit** - groups with **external users** sorted by **accessible files**: the exact groups where one guest invitation translates into the widest data reach.
- **Ungoverned access** - **no owners** + sensitive info present: access that keeps working with nobody responsible for it.
- **Dead lists that still receive** - distribution lists with external members and recent **emails received**: mail flowing to the outside through a list everyone forgot.
