Forum Discussion
Darryl Felstead
Jun 12, 2017Copper Contributor
Identify which user deleted an O365 group?
We recently had a group go AWOL, and though we were able to dig it up thanks to Restore-AzureADMSDeletedDirectoryObject, we are not able to identify how the group was deleted. Is there a way to pull relevant info from the site's settings (like a site collection's audit logs or similar)? I checked the version info for the pages/docs and nothing is listed at all.
AzureAD's audit logs should show who deleted a group.
- DouglasHamiltonBrass ContributorTo identify who deleted the M365 Group, you can open the group in Microsoft Entra and then access the Audit logs.
- Tilo SCopper ContributorSearched the log based on Activity: Deleted team
- Amish RajCopper Contributor
Hi ,
What kind of permission required to delete an sharepoint O365 group site.urgent please respond asap
Thnaks
Owners can delete their own group, or anyone with admin rights over your AzureAD.
In about 2 years of using Groups this has happened to us twice, simple to restore and then remove that user from having ownership.
- Darryl FelsteadCopper ContributorAnswered my own question after poking around this morning. Use the Audit Log Search from the "Security & Compliance" section of the admin console.
AzureAD's audit logs should show who deleted a group.
- Darryl FelsteadCopper ContributorDidn't see this reply. Thanks Steven!