Groups, Groups, Groups!

๐Ÿงฉ Understanding Microsoft 365 Group Types

SharePoint Groups vs Microsoft 365 Groups vs Security Groups vs Contact Lists

๐ŸŽฏ Purpose

This article explains the different types of groups in Microsoft 365, what they are used for, and when to use each one. Understanding these differences helps ensure proper access control, governance, and collaboration across BYU-Idaho systems.

๐Ÿง  Quick Summary (Recommended Model)

Layer Group Type Purpose
Identity / Access Control Security Groups (Roles) Manage access to systems, apps, and data
Collaboration Microsoft 365 Groups Work together (Teams, email, files, Planner)
Site Permissions SharePoint Groups Control access within a SharePoint site
Personal Use Contact Lists Send emails to a personal list

๐Ÿ“Š Full Comparison Table

Feature SharePoint Groups Microsoft 365 Groups Security Groups (Roles) Contact Lists
Primary Purpose Site permissions Collaboration Access control Personal email
Created In SharePoint site settings Outlook, Teams, Planner, Admin Center Entra ID / Admin Center Outlook
Scope One site only Organization-wide Organization-wide One user only
Used for Permissions โœ… SharePoint only โœ… (indirectly via connected resources) โœ… Broad (apps, sites, etc.) โŒ No
Used for Teams โŒ โœ… Required โœ… Can grant access โŒ
Email Enabled โŒ โœ… โœ… (optional) โœ…
Dynamic Membership โŒ โœ… โœ… โŒ
Best Use Case Site-level access Departments / teams Roles & automation Personal lists

๐Ÿ” Group Types Explained

1. SharePoint Groups (Site-Level Permissions)

What they are

  • Groups that exist inside a SharePoint site
  • Automatically created as:
    • Owners
    • Members
    • Visitors&wdpartid={c6c0f267-c91d-4ded-a1f9-a5a10db1c25b}{1}&wdsectionfileid={bc490b79-26f2-459f-a461-9efbc839af25})

What theyโ€™re used for

  • Granting access to:
    • Sites
    • Document libraries
    • Lists

Key characteristics

  • Not visible outside the site
  • Cannot be used in Teams or apps
  • Managed by site owners

โœ… Best Practice

Use SharePoint Groups only as permission containers, and add other group types into them.

๐Ÿ“Œ Example (Music Department Site)

SharePoint Site: BYU Idaho Music Department

Owners Group
  โ†’ Luana (Office Manager)
  โ†’ Megan (Assistant)

Members Group
  โ†’ Security Group: Music Employees (Full Access)

Visitors Group
  โ†’ Security Group: Adjunct Faculty (Read Only)

2. Microsoft 365 Groups (Collaboration Groups)

What they are

A group that automatically provides:

  • Shared mailbox
  • SharePoint site
  • Planner plan
  • Teams (if enabled)

Adding a user gives access to all of the above at once&wdpartid={a540723d-d331-4f85-9030-4cc76010bc85}{153}&wdsectionfileid={d9f8ec3a-e305-4fa9-906e-ec761bdf6bd5})

What theyโ€™re used for

  • Department collaboration
  • Projects
  • Committees
  • Classes

๐Ÿ“Œ Example (Music Faculty Team)

Microsoft 365 Group: Full-Time Music Faculty

Members:
  โ†’ Faculty users

Resources automatically created:
  โ†’ Team (chat + meetings)
  โ†’ SharePoint site (files)
  โ†’ Outlook inbox
  โ†’ Planner board

โœ… Best Practice

Use Microsoft 365 Groups when people need to:

  • Communicate (chat/email)
  • Share files
  • Assign tasks

3. Security Groups (Entra ID Roles / โ€œModern Groupsโ€)

What they are

  • Centralized identity groups in Entra ID (Azure AD)
  • Used for controlling access across systems

What theyโ€™re used for

  • Assigning access to:
    • Applications
    • SharePoint sites
    • Teams
    • Licensing
    • Conditional Access policies

โœ… Key Advantage

  • Can be automated (dynamic membership)
  • Supports future HR integration (e.g., Workday)
  • Central source of truth

๐Ÿ“Œ Example (Role-Based Access Model)

Security Group: Music Employees
  โ†’ All full-time faculty

Security Group: Adjunct Faculty
  โ†’ Part-time instructors

Security Group: Music Admin Staff
  โ†’ Office assistants

Then:

SharePoint Members
  โ†’ Music Employees

SharePoint Visitors
  โ†’ Adjunct Faculty

โœ… Best Practice (Recommended Governance Model)

Use Security Groups as the foundation:

Security Group (who should have access)
        โ†“
Added to
        โ†“
SharePoint Group (what access they get)

4. Contact Groups (Contact Lists)

What they are

  • Personal email lists created in Outlook

What theyโ€™re used for

  • Quick email distribution (personal use only)

๐Ÿšซ Limitations

  • Not visible to IT
  • Not reusable by others
  • Cannot assign permissions

๐Ÿ“Œ Example

Tonyโ€™s Outlook Contact List:
  โ€œMusic Leadershipโ€

Used for:
  โ†’ Sending email to same group quickly

โœ… Recommendation

Avoid using Contact Lists for:

  • Departments
  • Permissions
  • Shared workflows

Instead use:

  • Microsoft 365 Groups (collaboration)
  • Mail-enabled Security Groups (distribution)

๐Ÿงญ Putting It All Together (Visual Model)

            +-----------------------------+
            |   Security Groups (Roles)   |
            |  "Who should have access?"  |
            +-------------+---------------+
                          โ†“
        +-------------------------------------+
        | SharePoint Groups (Permissions)     |
        | "What level of access?"             |
        +-------------------------------------+

        OR

        +-------------------------------------+
        | Microsoft 365 Groups (Collaboration)|
        | "Work together"                     |
        +-------------------------------------+

โš ๏ธ Common Mistakes to Avoid

Mistake Why itโ€™s a problem
Using SharePoint groups across multiple systems They only work within one site
Using Contact Lists for teams Not governed or shared
Managing users manually everywhere Hard to scale and maintain
Not using role-based groups Prevents automation and HR alignment

โœ… Recommended BYU-Idaho Approach

Based on current practices and future scalability:

  1. Create Security Groups for roles

    • Tied to departments (Music Employees, Adjunct Faculty)
  2. Use those groups in SharePoint

    • Assign permission levels
  3. Use Microsoft 365 Groups for collaboration

    • When Teams / Planner / email are needed

This supports:

  • Cleaner governance
  • Easier onboarding/offboarding
  • Future automation with HR systems

๐Ÿ“Œ Final Takeaway

  • Security Groups = who gets access
  • SharePoint Groups = what access they get
  • Microsoft 365 Groups = how they collaborate
  • Contact Lists = personal convenience only

Contact Us

If you still need help, call us at (208) 496-9009 or start a Live Chat with us.

Hours of Operation: Mon - Fri 7:30 AM - 8:00 PM, Sat 10:00 AM - 4:00 PM Mountain Time

(excluding weekly devotional, forum hour and University Recognized holidays)

Interested in learning more or getting your questions answered face-to-face?
Join our weekly Office Hour every Monday from 2โ€“3 PM!
We meet at: https://itOfficeHour.byui.edu 

Everyone is welcomeโ€”bring your questions, ideas, or just drop in to connect!