Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use an Active Directory (AD DS) security group to grant permissions or user rights to on-premises resources. Use a Microsoft 365 Group when people need a shared collaboration space—such as a group inbox and calendar, SharePoint document library, Planner plan, or Teams membership. The choice depends on the resource, required membership and nesting, who manages the group, and the organization’s Microsoft 365 configuration.

What is the difference between a security group and a Microsoft 365 Group?

An AD DS security group is primarily an access-control tool: administrators assign permissions to a group instead of managing them for each person or computer. A Microsoft 365 Group connects members to collaboration services. Microsoft describes Microsoft 365 Groups as groups “used for collaboration between users, both inside and outside your company.” Microsoft’s group comparison distinguishes that collaboration role from security groups used to manage resource access.

Group type Designed for Typical outcome
AD DS security group Permissions and user rights in an on-premises directory environment Members receive access to a resource, such as a shared folder or printer, through permissions assigned to the group.
Microsoft 365 Group Membership-based collaboration across Microsoft 365 services Members can share connected services such as a group inbox and calendar, SharePoint library, or Planner plan; a Team also uses a Microsoft 365 Group for membership.

These roles can overlap in certain cloud access-control scenarios, but the group types are not interchangeable for every resource. The target application’s supported group types matter.

When should I use an Active Directory security group?

Choose an AD DS security group when you need to assign permissions to an on-premises resource or assign an AD user right. For example, an administrator can grant a group access to a file share or printer and then manage access by changing the group’s membership. Microsoft documents security groups as a way to assign permissions to shared resources. Learn about AD DS security groups.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the scope to fit the directory and resource design

AD DS provides Global, Universal, and Domain Local group scopes. Scope governs which accounts and groups can belong to a group and where it can be used to grant permissions. The right scope depends on the forest and resource design; there is no single scope that is correct for every organization. Check the intended membership and permission target before creating the group. Microsoft’s AD DS scope guidance explains these distinctions.

When should I use a Microsoft 365 Group?

Choose a Microsoft 365 Group when the goal is to give a defined set of people a shared Microsoft 365 collaboration space, rather than only to assign access to one resource. Depending on the organization’s subscription and configuration, group-connected services can include shared email and calendar, a SharePoint document library, and Planner. Microsoft’s comparison of group types describes these connected services.

Use one when creating a Team with linked membership

Teams uses a Microsoft 365 Group for its membership. Members of the Team also get access to its parent SharePoint site. This links collaboration membership with access to the Team’s associated site, rather than requiring you to treat those memberships as unrelated. Microsoft explains the Teams and SharePoint relationship.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can a Microsoft 365 Group also be used for access control?

In documented scenarios, a security-enabled Microsoft 365 Group can support both collaboration and access-control use cases. That overlap does not make it a universal replacement for other group types. Microsoft says security-enabled Microsoft 365 Groups are not supported for assigning permissions to Exchange shared mailboxes; use mail-enabled security groups for that purpose. Check the target resource’s supported group types before relying on a Microsoft 365 Group for access. Microsoft’s group concepts guidance covers group types and their use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should I check before choosing a group?

  • Target resource: Identify whether the permission is for an on-premises AD DS resource, a Microsoft Entra or SaaS resource, or Microsoft 365 collaboration services. Microsoft Entra security groups are used to manage access to shared resources, but resource support varies. Review Microsoft Entra group concepts.
  • Required outcome: Decide whether access alone is enough, or whether members also need a shared inbox, calendar, SharePoint library, Planner, or Teams membership.
  • Membership: Confirm which member types the design requires. Supported member types differ across Microsoft Entra group types; do not assume a group can include users, devices, service principals, or nested groups in every combination. Check supported Microsoft Entra group membership.
  • Scope and nesting: For AD DS, match Global, Universal, or Domain Local scope to the directory and resource design. For Microsoft Entra groups, verify that the application recognizes nested-group membership as intended; do not assume nesting automatically grants effective access.
  • Management authority: Establish whether the group is cloud-managed or synchronized from on-premises AD. Microsoft says groups synchronized from on-premises AD can only be managed on-premises. Follow the source-of-authority guidance for the specific group type and scenario. Read about group source of authority.
  • Services and governance: Verify that the organization’s subscription and configuration include the Microsoft 365 services the group is meant to provide. Also consider who can create and manage groups. Microsoft’s group comparison describes service connections and configuration context.

Quick decision guide

Need Start with Check
Grant a shared folder or printer permission in an on-premises AD DS environment AD DS security group Group scope, membership, and the resource’s permission model.
Give a group of people connected Microsoft 365 collaboration services Microsoft 365 Group Required services, subscription and configuration, and group governance.
Create a Team and connect its membership to its parent SharePoint site Microsoft 365 Group through Teams That Team members need the corresponding site access.
Control access to a cloud or SaaS resource Microsoft Entra security group, where supported The application’s accepted group type, member types, and nested-group behavior.
Manage a group synchronized from on-premises AD Manage it at its authoritative source For synchronized groups, management remains on-premises; confirm the exact source-of-authority scenario.
Assign permissions to an Exchange shared mailbox Mail-enabled security group Security-enabled Microsoft 365 Groups are not supported for this permission assignment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.