> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/unified-identities/azure-identities/entra-id/groups.md).

# Groups

The `Groups` page provides a list of enumerated groups in entire Azure. The list contains the `Assignable To Role`, `Security Enabled`, `On Prem Sync Enabled`, `Group Type`, `Privileged`, `Member Count`, `Tier 0`, `Risk Score`, `Exposure Point` and `Issue Counts`.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-025fe060521c0d46b75777127f729e35f871be2e%2Fgroup-1.png?alt=media" alt=""><figcaption><p>Groups</p></figcaption></figure>

## Group Details

Details page contains the `Risk Score` of the group,`Exposure Point`, `Information`, and `Issues` panes.

{% hint style="info" %}
You can analyze objects in the `Graph module` by clicking the `Visualize` button on the upper left side of the `Information Pane`.
{% endhint %}

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-af831cb047e3cbfa02f0878cf86215d1769eb279%2Fazure-identities-groups-image-1.png?alt=media" alt=""><figcaption><p>Group Details</p></figcaption></figure>

## Information

`Information Pane` can contain different badges to highlight important attributes.

| Badge          | Description                                                                           |
| -------------- | ------------------------------------------------------------------------------------- |
| **Privileged** | Indicates that the object is Privileged.                                              |
| **Stealth**    | Indicates that the object can compromise admin objects with at least one attack path. |
| **Tier**       | Indicates that the object tier according to risk score and importance.                |

`Information Pane` contains `Details`, `Parent Groups`, `Child Groups`, `Child Users`, `Child Devices`, `Child Service Principals`, `Child Administrative Units`, `Owner Users`, `Owner Service Principals`, `ARM Roles` and `Policies` tabs respectively. Each tab carries the number of rows it holds in its label.

## Details

Details tab contains attributes below about group object.

| Attribute                 | Description                                                                                                                                |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| **Name**                  | The unique name or alias of the group, used for identification and referencing within Azure AD.                                            |
| **Description**           | A user-defined text field describing the group's purpose or membership.                                                                    |
| **Display Name**          | The name shown in the directory, often used in address books and group listings.                                                           |
| **Tenant ID**             | The globally unique identifier (GUID) of the Azure AD tenant to which the group belongs.                                                   |
| **Security Enabled**      | Indicates whether the group is a security group, which can be used to manage access to resources like SharePoint, Teams, or applications.  |
| **Group Type**            | Defines the type of group—**Security** for access control or **Microsoft 365** for collaboration (this group is a **Security group**).     |
| **When Created**          | The date and time when the group was created in the Azure Active Directory.                                                                |
| **Is Assignable To Role** | Indicates whether this group can be assigned to Azure AD roles (role-assignable groups must be security-enabled and marked as assignable). |
| **On Prem SID**           | The security identifier (SID) for the group from the on-premises Active Directory, used during synchronization.                            |
| On Prem Sync Enabled      | Specifies whether the group was synchronized from an on-premises Active Directory via Azure AD Connect.                                    |
| Security Identifier       | A unique SID assigned by Azure AD for the group object, used in access control and permissions.                                            |
| Object ID                 | A unique object identifier (GUID) assigned to the group by Azure AD, used to reference the group programmatically or in logs.              |

## Parent Groups

Parent Groups tab contains a list of groups that the group is a member of. This list also contains `Enabled` and `On Prem Sync Enabled` columns to identify the status of these groups.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-66503c451be763a3df4bf44d99bdbdd50375cff0%2Fazure-identities-groups-image-2.png?alt=media" alt=""><figcaption><p>Parent Groups</p></figcaption></figure>

## Child Groups

Child Groups tab contains a list of groups that are children of the group. This list also contains `Privileged` and `Admin` columns to identify the privilege levels of these groups.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-4df0a97f0948bd8ec2521caff6ca50e85112f293%2Fazure-identities-groups-image-3.png?alt=media" alt=""><figcaption><p>Child Groups</p></figcaption></figure>

## Child Users

The Child Users tab displays a list of user accounts associated with the group.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-e89486930634ba968c61f68da1c1f142c3879096%2Fazure-identities-groups-image-4.png?alt=media" alt=""><figcaption><p>Child Users</p></figcaption></figure>

## Child Devices

The Child Devices tab displays a list of devices objects associated with the group.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-d4ab1d8c1a8b3834a5a3afef3fdb33043f96e459%2Fazure-identities-groups-image-5.png?alt=media" alt=""><figcaption><p>Child Devices</p></figcaption></figure>

## Child Service Principals

The Child Service Principals tab displays a list of Service Principals associated with the group.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-67e7924ddc984141956697c81c1f67691f9464e6%2Fazure-identities-groups-image-6.png?alt=media" alt=""><figcaption><p>Child Service Principals</p></figcaption></figure>

**Name**: The name of the Service Principals.

**Enabled**: Indicates whether the Service Principals is active.

**App Display Name:** The display name of the Azure AD application that this service principal is associated with.

**Service Principal Type:** The type of the service principal, which defines its origin.

Common types include:

* `Application` – a service principal created for an Azure AD application.
* `ManagedIdentity` – for system- or user-assigned managed identities.
* `Legacy` – for older service principal objects.
* `Federated` – for service principals from external identity providers

## Child Administrative Units

The Child Administrative Units tab displays a list of Administrative Units associated with the group.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-b8a0633c4a955ee00dafe83a6ed35988e63fe7d1%2Fazure-identities-groups-image-7.png?alt=media" alt=""><figcaption><p>Child Administrative Units</p></figcaption></figure>

**Display Name**: The display name of the Administrative Unit, used to identify it within Azure AD.

**Member Management Restricted**: Indicates whether non-global administrators are restricted from managing members of this Administrative Unit. When set to `true`, only scoped-role assignments can manage its members.

**Visibility**: Determines whether the Administrative Unit is visible to users in the directory. Values can be:

* `Public` – visible to all users.
* `HiddenMembership` – members are not visible to non-admin users.
* `Private` – not visible unless explicitly granted access.

## Owner Users

The Owner Users tab displays a list of Owner Users associated with the group.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-8ad6ea88b4909f21212241839d37588310c31dbc%2Fazure-identities-groups-image-8.png?alt=media" alt=""><figcaption><p>Owner Users</p></figcaption></figure>

## Owner Service Principals

Owner Service Principals tab contains a list of service principals that the group is a member of.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-74c9ecf3cfb7754345734cd05c9689dd445026da%2Fazure-identities-groups-image-9.png?alt=media" alt=""><figcaption><p>Owner Service Principals</p></figcaption></figure>

## ARM Roles

ARM Roles tab contains a list of the Azure Resource Manager role assignments held by the group. Every member of the group inherits these, so a group with resource-plane roles widens the blast radius of each membership.

## Policies

Policies tab lists the Conditional Access policies that apply to the group.

**Name:** The policy the row is about, linking to its [Conditional Access Policy](/forestall/unified-identities/azure-identities/entra-id/conditional-access-policies.md) page.

**State:** Whether the policy is `Enabled`, `Disabled` or `Report-only`.

Because Conditional Access is usually assigned to groups rather than to individual users, this tab is the quickest way to see what a group actually grants or demands before changing its membership. [CAP Audit](/forestall/cap-audit.md) reports the same relationship from the policy side.

## Issues

Issues pane contains identified issues on the group object.

![Issues](https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-72c88396232e83c9bc36e3696a0d514fce96fb4c%2Fgroup-issues.png?alt=media)
