First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation, Data & AI Microsoft partner since 2006 1,100+ organizations under management

Microsoft 365 Groups vs Security Groups vs Distribution Lists vs Dynamic Groups: Which One for Which Job

2026-09-20·IT PartnerNewMicrosoft 365Microsoft Entra IDArchitecture

Most help-desk tickets that mention "a group" are really about the wrong object type: a distribution list asked to hold a calendar, a Microsoft 365 group created for what should have been a permission, a security group nobody owns. Here is what each object is for, where it is created, what it can be used in, and which one to reach for when the request lands.

The objects, one paragraph each

Microsoft 365 group. A membership object in Microsoft Entra that arrives with resources attached: a group mailbox and calendar in Exchange Online, a SharePoint site, a Planner plan and optionally a team. Every team in Microsoft Teams is backed by one.

Security group. A membership object with no mailbox and no site. It exists to be referenced by something else: a Conditional Access policy, a license assignment, a SharePoint permission, an Intune assignment, an application role.

Mail-enabled security group. A security group that also has an email address, so one membership can receive mail and hold permissions. At the time of writing it is created from the Exchange or Microsoft 365 admin center, not the Entra admin center.

Distribution list. An Exchange object whose only job is delivering mail to its members. No site, no calendar, and it cannot be granted permissions or targeted by a policy. Exchange's dynamic distribution groups compute recipients from a filter at send time and are unrelated to Entra dynamic groups.

Dynamic group. Not a fifth type but a membership mode. A security group or a Microsoft 365 group can have its members computed from a rule on user or device attributes (department, job title, device operating system). Dynamic membership is a Microsoft Entra ID P1 feature; P1 vs P2 covers which plans carry it.

Shared mailbox. Not a group at all: an Exchange mailbox without its own sign-in, with a calendar, that named people are given Full Access and Send As permissions to. Below a mailbox size threshold Microsoft publishes it needs no license; check the current figure.

Where each is created, and what it can be used in

Microsoft 365 groups come from Outlook, Teams (creating a team), SharePoint (a team site), Planner, the Microsoft 365 admin center or the Entra admin center. Security groups come from the Entra or Microsoft 365 admin center, or from on-premises Active Directory. Distribution lists, mail-enabled security groups and shared mailboxes come from the Exchange or Microsoft 365 admin center.

What each can be used in, per Microsoft's documentation at the time of writing:

  • Conditional Access policies target security groups and Microsoft 365 groups; distribution lists are not policy targets.
  • Group-based licensing assigns licenses to security groups; nested groups are not evaluated, and a distribution list cannot carry a license.
  • SharePoint permissions can be granted to security groups (including mail-enabled ones) and, through the site, to a Microsoft 365 group's members; distribution lists cannot hold permissions.
  • Only a Microsoft 365 group backs a team. Adding a security group or a distribution list when creating a team copies its members at that moment; it does not stay linked.
  • Intune assignments target Entra groups, usually dynamic device groups by operating system or ownership.
  • Microsoft 365 groups, distribution lists, mail-enabled security groups and shared mailboxes have email addresses; plain security groups do not.

Ownership, expiry, naming and nesting

Microsoft 365 groups are the only type with a full lifecycle model. Owners are required, and at the time of writing an ownerless group policy can ask active members to take over when the last owner leaves. An expiration policy renews groups with recent activity automatically and deletes the group when nobody renews; per Microsoft's documentation at the time of writing, a deleted Microsoft 365 group can be restored for 30 days. A naming policy adds prefixes or suffixes and blocks words. Expiration, naming and dynamic membership all require Entra ID P1 for the users involved. Microsoft Teams Governance and Sprawl Cleanup ($2,950 per project) implements naming, creation governance, expiration with activity-based renewal and an ownerless-team cleanup.

Security groups and distribution lists have owners but no expiration. Their cleanup is an access review (Entra ID P2 or Entra ID Governance) or a manual cadence; access reviews, PIM and lifecycle workflows recommends starting with the groups that grant sensitive access.

Nesting, at the time of writing: security groups can contain security groups; Microsoft 365 groups cannot contain groups and cannot be members of other groups. Which consumers honor nesting varies (group-based licensing, for one, does not evaluate nested groups), so keep nesting shallow and check Microsoft Learn before relying on it.

Sensitivity labels can be applied to Microsoft 365 groups, teams and sites to control privacy, guest access and unmanaged-device behavior, as law-firm SharePoint structure describes.

Three help-desk requests, and the right object

"We need a security group for a SharePoint folder." The request is usually for a permission on part of a site. First ask whether the folder is really a separate workstream; if so, a private or shared channel or a separate site gives it its own membership boundary instead of broken inheritance. If it stays a folder, grant it to a security group with a named business owner and a review date, never to a distribution list.

"The distribution list should also have a shared calendar." A distribution list has no calendar. Two paths: upgrade the list to a Microsoft 365 group, which the Exchange admin center offers for eligible cloud-managed lists at the time of writing, keeping the address and adding a calendar, a site and a Planner; or create a shared mailbox for the calendar and keep the list for mail. Choose the upgrade when the members also need files and Teams, the shared mailbox when they only need the calendar.

"Why can't I assign licenses to a distribution list?" Because it is an Exchange recipient, not a security principal. Create a security group, assigned or dynamic by department or job title, assign the licenses to it, and watch its license page for errors. What a clean Microsoft tenant should look like maps group-based licensing to license personas and HR status.

A model that stays clean

Decide who can create Microsoft 365 groups (restrict creation to an approved security group or a request path), set the naming and expiration policies, apply sensitivity labels to the groups that need them, and use dynamic membership wherever the rule can be written from HR attributes. Review the security groups that grant sensitive access on a cadence, and inventory everything: the Tenant Optimizer scan reads all groups and memberships into an Excel workbook.

For the operations layer, Managed Entra ID Identity Hygiene and Access Reviews ($3 per user per month) runs the quarterly access-review campaigns and stale-account cleanup; Microsoft Entra ID Governance Implementation (from $6,950) configures access reviews, access packages and lifecycle workflows; the SharePoint Governance and Information Architecture Review ($2,450 per project) maps every site and its permission structure; and Microsoft Entra Administrator on Demand ($175 per hour) handles the one-off change.

Frequently asked questions

Can a Microsoft 365 group be used in a Conditional Access policy?

Yes. Conditional Access targets security groups and Microsoft 365 groups, including dynamic ones; distribution lists are not policy targets at the time of writing.

Can I convert a security group into a Microsoft 365 group, or the reverse?

Not directly, at the time of writing. Create the new object and move the members. Eligible distribution lists can be upgraded to Microsoft 365 groups from the Exchange admin center.

Do dynamic groups need a license for every member?

Dynamic membership is an Entra ID P1 feature, licensed for the users who are members of dynamic groups. Business Premium, E3 and E5 carry P1; Business Basic and Standard do not.

What happens when a Microsoft 365 group expires?

If no owner renews it, the group is deleted together with its mailbox, site, Planner and team, and per Microsoft's documentation at the time of writing it can be restored within 30 days. Groups with recent activity renew automatically.

When is a shared mailbox the right answer instead of a group?

For a role inbox or calendar that needs no files, no Teams and no membership object, such as a sales or support address. Block direct sign-in to it; shared mailboxes that allow sign-in are a warning sign.

Sources

  • IT Partner subscription pages under content/subscriptions: CFQ7TTC0LFLS (Microsoft Entra ID P1), CFQ7TTC0LCHC (Microsoft 365 Business Premium)
  • IT Partner blog posts linked above: Entra ID P1 vs P2; Entra ID Governance; law-firm SharePoint structure; the clean tenant baseline
  • IT Partner service pages under content/services: ITPWW820IMPOT, ITPWW400MSPRC, PRP-IDG-001, ITPWW310CONOT, ITPWW260MSPRC; src/app/tools/tenant-optimizer/page.tsx
  • IT Partner engineering notes, September 2026 (the help-desk patterns, anonymized)
  • Statements marked "at the time of writing" describe Microsoft product behavior we are confident of but could not verify against Microsoft Learn from this environment; confirm in the admin center before designing around them.
Job Right object Notes
Send mail to a set of people, nothing else Distribution list Dynamic distribution group when membership follows attributes
A team in Microsoft Teams Microsoft 365 group Created by Teams; owners required
A department or project workspace with files, calendar and Planner Microsoft 365 group Apply a sensitivity label where needed
Permissions on a SharePoint site, library or folder Security group, or the site's own Microsoft 365 group Never a distribution list; prefer a separate site or channel over broken inheritance
Target or exclude a Conditional Access policy Security group or Microsoft 365 group Assigned membership for exclusions, with an owner and review date
Assign licenses Security group Dynamic by department or job title; no nesting
Assign Intune policies and apps Security group Dynamic device group by operating system or ownership
Membership that must receive mail and hold permissions Mail-enabled security group Created from the Exchange admin center
Shared inbox or calendar for a role Shared mailbox Not a group; no license below the published size threshold
Membership that should follow HR attributes Dynamic group (Entra ID P1) Members cannot be added by hand
Guest collaboration with an outside party Microsoft 365 group or team with guest settings Set an owner, purpose and review date

Key takeaways

  • A Microsoft 365 group brings resources (mailbox, calendar, site, Planner, team); a security group brings none and exists to be referenced by policies, licenses and permissions.
  • Distribution lists deliver mail and nothing else: no calendar, no permissions, no licenses, no Conditional Access.
  • Dynamic membership is a mode, not a type, and needs Entra ID P1 for the users involved; use it wherever a rule can be written from HR attributes.
  • Only Microsoft 365 groups have expiration, naming and ownerless policies; security groups need access reviews or a manual cadence.
  • Most group tickets are solved by picking the object first: a separate site or channel for a workstream, a shared mailbox for a role calendar, a security group for licensing.

If group sprawl or unowned security groups are already the problem, Microsoft Teams Governance and Sprawl Cleanup ($2,950 per project) puts naming, expiration and ownerless cleanup in place, and Managed Entra ID Identity Hygiene and Access Reviews ($3 per user per month) keeps the membership honest afterwards. Licensing for dynamic groups, expiration and naming is Entra ID P1 at Microsoft's list price, carried by Business Premium and E3.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.