Entra

What admins can learn from the new Entra ID Groups Insights blade

· 3 min read · Entra

Microsoft released a new overview in Entra ID: Entra ID Groups Insights.

Screenshot from the article

Currently in preview, it has some limitations, but what caught my attention is the new Graph API endpoint that this report is using: beta/reports/identityAnalytics/groups

There is a ton of valuable info in there, so apart from the UX report, you can build great custom reports using this data. Let me show you how I found these in the first place:

In your browser’s DevTools, open the Network tab, filter for Fetch/XHR, and search for ‘batch’. Expand the calls, and look for the ones that point to beta/reports/identityAnalytics/groups

Screenshot from the article

Now, the real value is in understanding the API, so I used AI to extract all endpoints. and correlate them with the UX dashboard. Use this to learn and understand the visuals, and use them in your own reporting to tweak the calls to your needs.

Example: Groups with Complicated Rules shows all the dynamic groups with more than 10 membership rules. So Microsoft defined that 10 or more rules constitute a complex rule set. But maybe you want to find groups with 5 rules or more, so you are using the same API to find those:

GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=membershipRuleExpressionCount gt 5&$orderby=membershipRuleExpressionCount desc

Here’s the full extract, captured from the portal on Feb 18, 2026.

Owner#

UI LabelAPI CallExplanation
Groups with No OwnersGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=guestOwnerCount eq 0 and memberOwnerCount eq 0 and servicePrincipalOwnerCount eq 0Groups where all three owner count properties are zero — no user, guest, or app owns them.
Groups with Service Principals as OwnersGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=servicePrincipalOwnerCount gt 0&$orderby=servicePrincipalOwnerCount descGroups where at least one app/service principal is listed as owner, sorted by most SPs first.
Groups with Guest Users as OwnersGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=guestOwnerCount gt 0&$orderby=guestOwnerCount descGroups where at least one external/guest user is an owner.
Groups with Service Principals as Owners or Members (chart)GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=servicePrincipalOwnerCount gt 0 or transitiveServicePrincipalCount gt 0&$select=id,servicePrincipalOwnerCount,transitiveServicePrincipalCountGroups where an app is either an owner or a member — including via nested group membership.

Member#

UI LabelAPI CallExplanation
Groups with Complicated RulesGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=membershipRuleExpressionCount gt 10&$orderby=membershipRuleExpressionCount descDynamic groups with more than 10 expressions in their membership rule, hence complex.
Groups with Low Efficient OperatorsGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=(membershipRuleContainsCount gt 0) or (membershipRuleMatchCount gt 0)&$orderby=membershipRuleContainsCount descGroups with Low-Efficiency Operators

Lifecycle#

UI LabelAPI CallExplanation
Newly created groupsGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=createdDateTime ge 2026-01-19T13:18:40.174Z&$orderby=createdDateTime descGroups created in the last 30 days, newest first.
Expiring groupsGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=groupExpirationDateTime le 2026-03-20T... and groupExpirationDateTime gt 2026-02-18T...&$orderby=groupExpirationDateTime ascGroups expiring within the next 30 days, excluding already-expired ones, sorted most urgent first.
Soft deleted groupsGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=softDeletionDateTime ge 2026-01-19T13:18:40.175Z&$orderby=softDeletionDateTime descGroups deleted in the last 30 days that are still recoverable.
Restored groupsGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=lastRestorationDateTime ge 2026-01-19T13:18:40.175Z&$orderby=lastRestorationDateTime descGroups restored from soft-delete in the last 30 days.

Security & Compliance#

UI LabelAPI CallExplanation
Groups without Sensitivity LabelsGET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=sensitivityLabelCount eq 0Groups with no sensitivity label applied, meaning data protection policies may not be enforced.

Happy learning!

Comments

Comments load when you scroll here.