🎉 Our Office 365 Reporting Tool is now available in Azure Marketplace 🚀
This website uses cookies to improve your experience. We'll assume you're ok with this. Know more.
Azure AD

How to Find Deleted Microsoft 365 Groups

Microsoft 365 groups are essential for collaboration within an organization. However, the accidental deletion of groups can disrupt workflows and lead to the loss of group-connected teams, SharePoint sites, and other resources. Prompt identification and restoration of these deleted groups is essential to prevent communication breakdowns and data loss. In this guide, we will show you how to effectively audit deleted groups in Microsoft 365.

Using Microsoft 365 Admin Center

Microsoft 365 Permission Required
Groups Admin Least Privilege
Global Admin Most Privilege
  • Log in to the Microsoft 365 admin center.
  • Navigate to Deleted groups under Teams & groups.
  • Here, you can view the Microsoft 365 groups that were deleted within the last 30 days.
Using Microsoft 365 Admin Center

Using Microsoft Entra Admin Center

Microsoft 365 Permission Required
Groups Admin Least Privilege
Global Admin Most Privilege
  • Sign-in to the Microsoft Entra admin center.
  • Navigate to Deleted groups under Identity»Groups to check the deleted groups in Microsoft Entra ID.
Using Microsoft Entra Admin Center

Using Microsoft Graph PowerShell

Microsoft 365 Permission Required
Groups Admin Least Privilege
Global Admin Most Privilege
  • Connect to the Microsoft Graph PowerShell module using the below cmdlet.
  • Windows PowerShell Windows PowerShell
     Connect-MgGraph -Scopes Group.Read.All
  • Run the below cmdlet to get the list of all deleted groups in Microsoft 365.
  • Windows PowerShell Windows PowerShell
     Get-MgDirectoryDeletedItemAsGroup
Using Microsoft Graph PowerShell

Audit deleted Microsoft 365 groups to investigate unintentional group deletions!

AdminDroid's Microsoft 365 group auditing tool offers detailed insights into various group-related activities like Microsoft 365 group creations, modifications, deletions, group setting changes, and more. Effortlessly monitor deleted groups to detect any unintentional removals and safeguard critical resources.

Group Dashboard for Visualizing Deleted Groups

With AdminDroid's Microsoft 365 group dashboard, visualize and check Microsoft 365 deleted groups to recover or permanently delete them to free up space.

Identify Inactive Group Mailboxes in M365

Track inactive group mailbox report to find last activity time of a group mailbox and delete the unused ones to optimize M365 environment.

Monitor Microsoft 365 Group Usage

Regularly monitor Microsoft 365 group usage and activities reports to ensure that only approved and active groups exist within your organization.

Manage Empty Groups in Microsoft 365

Investigate empty groups in Microsoft 365 and delete any unnecessary ones to maintain only essential groups in your M365 environment.

Get Instant Alerts on Group Deletion with AdminDroid

Receive real-time notifications with AdminDroid’s alerting whenever a Microsoft 365 group is deleted. This helps to take timely investigation to avoid unwanted deletions.

Get Group Audit Report in Microsoft 365

Regularly monitor Microsoft 365 group audit reports to ensure no accidental deletions or restorations occur and safeguard your organization’s group resources.

In conclusion, AdminDroid's Azure AD management tool provides a streamlined solution for tracking deleted groups. With its detailed reports and automated monitoring, you can easily identify accidental deletions and ensure critical group resources are preserved.

Explore a full range of reporting options

Important Tips

Monitor Microsoft 365 group creations to identify and delete unwanted groups, ensuring that only relevant groups remain in your organization.

Apply retention policies to Microsoft 365 groups to ensure that content is retained in the Preservation Hold Library of SharePoint Online and OneDrive, even after the group is deleted.

Audit Microsoft 365 file deletions when a group is deleted to check whether any critical file has been removed from the SharePoint Online.

Common Errors and Resolution Steps

The following are the possible errors and troubleshooting hints while exporting deleted groups in Microsoft 365.

Error Get-MgDirectoryDeletedItemAsGroup : Insufficient privileges to complete the operation. Status: 403 (Forbidden) ErrorCode: Authorization_RequestDenied

This error occurs when the 'Connect-MgGraph' cmdlet is executed without specifying the required scopes.

Fix Define the necessary scopes when connecting to the Microsoft Graph module.
Connect-MgGraph –Scopes Group.Read.All

Error Restore-MgBetaDirectoryDeletedItem : Invalid object identifier '4765-543587-5454-4522'. Status: 400 (BadRequest) ErrorCode: Request_BadRequest

This error occurs if the 'Restore-MgDirectoryDeletedItem' cmdlet is used with an incorrect object ID.

Fix Verify that the object ID is valid. Use the following cmdlet to list all deleted groups with their display names and object IDs.
Get-MgDirectoryDeletedItemAsGroup | Select DisplayName,Id
#After running the above cmdlet, execute the below cmdlet with the correct object ID obtained from the previous cmdlet.
Restore-MgDirectoryDeletedItem -DirectoryObjectId "<objectId>"

Error Write-ErrorMessage : Cannot process argument transformation on parameter 'EndDate'. Cannot convert value "31/10/2024" to type "Microsoft.Exchange.ExchangeSystem.ExDateTime".

This error occurs when you enter the date in the incorrect format while specifying the start date or end date in 'Search-UnifiedAuditLog' cmdlet.

Fix Enter the date in the MM/DD/YYYY format while executing 'Search-UnifiedAuditLog' cmdlet in Exchange Online PowerShell.

Error Failed to restore group. Insufficient privileges to restore some or all of the selected groups.

This error occurs in the Microsoft Entra admin center when attempting to restore a deleted group without the required admin permissions.

Fix Ensure you have sufficient permissions. Read-only roles cannot restore groups. You must have Global Admin or User Admin rights to restore a group.

Frequently Asked Questions

Promptly Recover Deleted Microsoft 365 Groups to Prevent Data Loss!

What happens when you delete a Microsoft 365 group?

What happens when you delete a Microsoft 365 group? +

Microsoft 365 admins may occasionally delete groups that are no longer needed while managing groups. However, deleting a group can have significant effects across various Microsoft 365 services.

Here's a detailed breakdown of what happens when a Microsoft 365 group is deleted.

  • Impact on group and its memberships: Deleting a Microsoft 365 group removes the group object from Microsoft Entra ID along with the memberships, roles, and permissions linked to the group.
  • Loss of shared inbox and calendar: The group's shared inbox and calendar are deleted. Any emails, events, or meeting schedules stored within these resources will be lost.
  • Removal of SharePoint team site access: Since the group-connected SPO site will be disconnected from the group, admins can't control the setting in Microsoft 365 admin center. They need to provide access to users again from the SharePoint admin center.
  • Impact on OneNote notebook: The OneNote notebook linked to the group remains stored in the SharePoint team site. However, users are able to access the notebook only based on the site's permission settings.
  • Deletion of Microsoft Teams workspace: If the group is associated with a Microsoft Teams workspace, deleting the group will remove the associated team, chats, files, and conversations within that team. However, data can be recovered if you restore the group or team within the soft deletion period (by default it is 30 days).
  • Removal of associated email addresses: All email addresses associated with the group, including the primary address and any aliases, will be deleted.

How to see who deleted a Microsoft 365 group?

How to see who deleted a Microsoft 365 group? +

As an admin, it's crucial to monitor Microsoft 365 group's activities to ensure effective collaboration and secure access to resources. Understanding who deleted a Microsoft 365 group allows you to identify admins who don't need deletion permissions and adjust their privileges to enhance security.

Tracking who deleted a user in Microsoft 365 can be done in the following ways.

Steps to find who deleted a M365 group using Microsoft Purview portal

  • Navigate to the Audit page, then specify the date and time range as per your requirements.
  • Click on the Activity-friendly names drop-down and select Deleted group under 'Microsoft Entra group administration activities'.
  • Then, click on Search. Once the search is completed, you can export the audit logs of Microsoft 365 deleted groups with the admins who performed the deletion operation.

Steps to find who deleted a M365 group using Exchange Online PowerShell

  • Connect to the Exchange Online PowerShell module using the cmdlet below.
    Connect-ExchangeOnline
  • Run the below cmdlet to get the audit logs of group deletion activity in Microsoft 365.
    Search-UnifiedAuditLog -StartDate MM/DD/YYYY -EndDate MM/DD/YYYY -Operations "Delete group" | Format-Table
deleted-groups-audit-log-output

Tracking deleted groups in Microsoft 365 audit logs can be time-consuming since the exported results are not user-friendly.

Effortlessly find who deleted a Microsoft 365 group with AdminDroid!

  • With AdminDroid's Audit Deleted Groups report, you can track the Microsoft 365 group deletion activities and their properties easily.
  • This report shows the group deletion activities in the organization with information like deletion time, deleted group name, who deleted the group, etc.
audit-deleted-groups-admindroid

How to restore a deleted Microsoft 365 group?

How to restore a deleted Microsoft 365 group? +

If a project group is accidentally deleted, team members may lose access to documents, group email messages, calendars, and channels. However, you can quickly restore a deleted Microsoft 365 group to regain access of removed resources and ensure the sensitive information are safe.

Steps to recover a deleted Microsoft 365 group in the Microsoft Entra admin center

  • Navigate to Deleted groups under Identity»Groups.
  • Select the group you want to restore and click the Restore group option.
  • Then, click 'Yes' in the pop-up menu to restore a deleted group in Microsoft 365.
restore-deleted-groups-entra

Steps to retrieve a deleted Microsoft 365 group using Microsoft Graph PowerShell

  • Connect to the Microsoft Graph PowerShell module and restore a group using the cmdlets below.
    Connect-MgGraph –Scopes Group.ReadWrite.All
    Restore-MgDirectoryDeletedItem -DirectoryObjectId "<objectId>"
    #Replace the "<objectId>" with the Id of the respective deleted group.

While Microsoft 365 admin portals lack dedicated reports to audit group restoration activities, AdminDroid offers a robust solution!

  • With AdminDroid's Restored Groups Audit report, you can effortlessly audit group restoration activities and ensure no unintended group restoration activities are performed.
  • This report includes details, such as the name of the restored group, the restoration time, the user who restored the group, and more.
restored-groups-audit-admindroid

Can admins retain Microsoft 365 groups resources for a specific period?

Can admins retain Microsoft 365 groups resources for a specific period? +

By configuring a retention policy, you can retain Microsoft 365 group resources for a specific period. This ensures that important data, such as emails, files, site access, and team conversations remains safe and prevent the permanent loss of valuable information.

Let's see how to configure a retention policy for group contents in Microsoft 365.

  • Log in to the Microsoft Purview portal and navigate to Data lifecycle management»Microsoft 365»Retention policies.
  • Click on '(+) New retention policy' option and give your policy a name and description.
  • If needed, choose specific 'Admin Units' to apply this retention policy. However, if you need to apply this policy organizational wide, just click 'Next'.
  • Select Static to manually assign it to specific groups or locations.
  • Enable the toggle for 'Microsoft 365 Group mailboxes & sites' in the locations and then click 'Next'.
  • In the retention settings, select 'Retain item for a specific period' and set how long the group's content should be retained.
  • Specify 'Start the retention period based on' when it was created or when it was modified.
  • Then, choose 'automatically delete the content after this period' or 'do nothing' after the retention period.
  • Review all the configured settings and click "Submit" to create the retention policy.

Note: Items that are currently older than the specified retention period will be deleted after you turn on this policy.

+

Kickstart Your Journey With
AdminDroid

Your Microsoft 365 Companion with Enormous Reporting Capabilities

Download Now
User Help Manuals Compliance Docs
x
Delivering Reports on Time
Want a desired Microsoft 365 reports every Monday morning? Ensure automated report distribution and timely delivery with AdminDroid's Scheduling to your email anytime you need.
Delivering Reports on Time
Schedule tailored reports to execute automatically at the time you set and deliver straight to the emails you choose. In addition, you can customize report columns and add inteligent filtering to the activities just from the previous day to suit your Microsoft 365 report requirements.
Set It, Schedule It, See Results- Your Reports, Your Way, On Your Time!
Time Saving
Automation
Customization
Intelligent Filtering
Give Just the Right Access to the Right People
Grant fine-tuned access to any Microsoft 365 user with AdminDroid’s Granular Delegation and meet your organization’s security and compliance requirements.
Give Just the Right Access to the Right People
Create custom roles loaded with just the right permissions and give access to admins or normal users within AdminDroid. The result? A streamlined Microsoft 365 management experience that aligns your organization's security protocols and saves your invaluable time and effort.
Align, Define, Simplify: AdminDroid's Granular Delegation
Smart Organizational Control
Effortless M365 Management
Simplified Access
Advanced Alerts at a Glance
Receive quick notifications for malicious Microsoft 365 activities. Engage with the AdminDroid’s real-time alert policies crafted to streamline your security investigations.
Advanced Alerts at a Glance
Stay informed of critical activities like suspicious emails and high-risk logins, bulk file sharing, etc. Through creating and validating ideal alert policies, AdminDroid provides a comprehensive approach to real-time monitoring and management of potential threats within your organization.
AdminDroid Keeps You Always Vigilant, Never Vulnerable!
Proactive Protection
Real-time Monitoring
Security Intelligence
Threat Detection
Merge the Required Data to One Place
Combine multiple required columns into one comprehensive report and prioritize the information that matters most to you with AdminDroid’s Advanced Column Customization.
Merge the Required Data to One Place
This column merging capability offers a flexible way to add different columns from various reports and collate all the essential data in one place. Want to revisit the customized report? Save it as a 'View’, and your unique report is ready whenever you need it.
Merge with Ease and Save as Views!
Custom Reporting
Unique View
Desired Columns
Easy Data Interpretation
Insightful Charts and Exclusive Dashboards
Get a quick and easy overview of your tenant's activity, identify potential problems, and take action to protect your data with AdminDroid’s Charts and Dashboards.
Insightful Charts and Exclusive Dashboards
With AdminDroid charts and dashboards, visualize your Microsoft 365 tenant in ways you've never thought possible. It's not just about viewing; it's about understanding, controlling, and transforming your Microsoft 365 environment.
Explore Your Microsoft 365 Tenant in a Whole New Way!
Executive overviews
Interactive insights
Decision-making
Data Visualization
Efficient Report Exporting for Microsoft 365
Downloading your reports in the right file format shouldn’t be a hassle with AdminDroid’s Report Export. Experience seamless report exporting in various formats that cater to your needs.
Efficient Report Exporting for Microsoft 365
Navigate through diverse options and export Microsoft 365 reports flawlessly in your desired file format. Tailor your reports precisely as you need them and save them directly to your computer.
Take Control, Customize and Deliver- Your Office 365 Data, Exported in Your Way!
Easy Export
Seamless Downloading
Data Control
Manage Microsoft 365

Get AdminDroid Office 365 Reporter Now!