Mail-enabled security groups

%3CLINGO-SUB%20id%3D%22lingo-sub-1420423%22%20slang%3D%22en-US%22%3EMail-enabled%20security%20groups%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1420423%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3EI%20have%20several%20questions%20regarding%20mail-enabled%20security%20groups.%3C%2FP%3E%3CP%3E1.)%20can%20I%20use%20local%20AD%20groups%20%26amp%3B%20cloud-only%20groups%20for%20granting%20access%3CBR%20%2F%3Eto%20SPO%20or%20I%20have%20to%20use%20cloud-only%3F%3CBR%20%2F%3E2.)%20are%20there%20any%20reasons%20not%20to%20use%20local%20sec%20groups%3F%3C%2FP%3E%3CP%3EAre%20local%20sec%20groups%2C%20not%20mail-enabled%20%26amp%3B%20can%20or%20can't%20you%20use%20them%20as%20DL's%3F%3CBR%20%2F%3E3.)%20if%20I%20buy%20EMS%20E3%20licenses%2C%20could%20I%20do%20%22dynamic-attribute%20based%20sec%3CBR%20%2F%3Egroup%20assignment%3F%20Would%20that%20only%20work%20for%20Azure%20cloud-only%2C%20or%20could%20it%20work%3CBR%20%2F%3Elocal%20sec%20groups%20synced%20to%20azure%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20regards%2C%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1420423%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Contributor

Hi all,

I have several questions regarding mail-enabled security groups.

1.) can I use local AD groups & cloud-only groups for granting access
to SPO or I have to use cloud-only?
2.) are there any reasons not to use local sec groups?

Are local sec groups, not mail-enabled & can or can't you use them as DL's?
3.) if I buy EMS E3 licenses, could I do "dynamic-attribute based sec
group assignment? Would that only work for Azure cloud-only, or could it work
local sec groups synced to azure?

 

Kind regards,

2 Replies

You should be able to use synced ones just fine, but only mail-enabled ones. Dynamic membership is only for cloud-created ones.

@DiVojich 

 
PFA answer to your questions and a recommended solution:
 
1.) Can I use local AD groups & cloud-only groups for granting access to SPO or I have to use cloud-only?
 
Sharepoint Online only links to cloud groups (exchange online).
 
2.) Are there any reasons not to use local sec groups?
You can certainly use local security groups to manage access for all on-premise resources.
 
2)Are local sec groups, not mail-enabled & can or can't you use them as DL's?
 
Local security groups can be mail-enabled via Power Shell, Provisioning new security groups can be mail-enabled upon creation. These groups can be used for emails like a Distribution List. In Fact Microsoft started to promote the use of mail-enabled security groups but the adaption rate did not turn that well.
 
3.) if I buy EMS E3 licenses, could I do "dynamic-attribute based sec group assignment? Would that only work for Azure cloud-only, or could it work local sec groups synced to azure?
 
Microsoft will only allow dynamic group memberships for a certain group type and it's available only for Cloud Groups (Exchange Online), With on-premise Exchange there is the option of QBDL (Query-Based Distribution List) that provides similar features, however, its limited in functionality as opposed to a regular DL or Security Group.
 
I have used multiple third-party platforms, which offers the capabilities to automate building dynamic-attribute based Security Groups (Mail-Enabled) / Distribution List or cloud-only Microsoft 365 Groups and Azure AD Security Groups.
 
Moreover,  their automate features can convert existing Groups into Smart Groups where memberships can be based on an LDAP filter. It can also plug two sources to feed the LDAP filter for accurate memberships. Let me know if you have any further questions.