What admins can learn from the new Entra ID Groups Insights blade
Microsoft released a new overview in Entra ID: Entra ID Groups Insights.
Currently in preview, it has some limitations, but what caught my attention is the new Graph API endpoint that this report is using: beta/reports/identityAnalytics/groups
There is a ton of valuable info in there, so apart from the UX report, you can build great custom reports using this data. Let me show you how I found these in the first place:
In your browser’s DevTools, open the Network tab, filter for Fetch/XHR, and search for ‘batch’. Expand the calls, and look for the ones that point to beta/reports/identityAnalytics/groups
Now, the real value is in understanding the API, so I used AI to extract all endpoints. and correlate them with the UX dashboard. Use this to learn and understand the visuals, and use them in your own reporting to tweak the calls to your needs.
Example: Groups with Complicated Rules shows all the dynamic groups with more than 10 membership rules. So Microsoft defined that 10 or more rules constitute a complex rule set. But maybe you want to find groups with 5 rules or more, so you are using the same API to find those:
GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=membershipRuleExpressionCount gt 5&$orderby=membershipRuleExpressionCount desc
Here’s the full extract, captured from the portal on Feb 18, 2026.
Owner#
| UI Label | API Call | Explanation |
|---|---|---|
| Groups with No Owners | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=guestOwnerCount eq 0 and memberOwnerCount eq 0 and servicePrincipalOwnerCount eq 0 | Groups where all three owner count properties are zero — no user, guest, or app owns them. |
| Groups with Service Principals as Owners | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=servicePrincipalOwnerCount gt 0&$orderby=servicePrincipalOwnerCount desc | Groups where at least one app/service principal is listed as owner, sorted by most SPs first. |
| Groups with Guest Users as Owners | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=guestOwnerCount gt 0&$orderby=guestOwnerCount desc | Groups where at least one external/guest user is an owner. |
| Groups with Service Principals as Owners or Members (chart) | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=servicePrincipalOwnerCount gt 0 or transitiveServicePrincipalCount gt 0&$select=id,servicePrincipalOwnerCount,transitiveServicePrincipalCount | Groups where an app is either an owner or a member — including via nested group membership. |
Member#
| UI Label | API Call | Explanation |
|---|---|---|
| Groups with Complicated Rules | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=membershipRuleExpressionCount gt 10&$orderby=membershipRuleExpressionCount desc | Dynamic groups with more than 10 expressions in their membership rule, hence complex. |
| Groups with Low Efficient Operators | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=(membershipRuleContainsCount gt 0) or (membershipRuleMatchCount gt 0)&$orderby=membershipRuleContainsCount desc | Groups with Low-Efficiency Operators |
Lifecycle#
| UI Label | API Call | Explanation |
|---|---|---|
| Newly created groups | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=createdDateTime ge 2026-01-19T13:18:40.174Z&$orderby=createdDateTime desc | Groups created in the last 30 days, newest first. |
| Expiring groups | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=groupExpirationDateTime le 2026-03-20T... and groupExpirationDateTime gt 2026-02-18T...&$orderby=groupExpirationDateTime asc | Groups expiring within the next 30 days, excluding already-expired ones, sorted most urgent first. |
| Soft deleted groups | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=softDeletionDateTime ge 2026-01-19T13:18:40.175Z&$orderby=softDeletionDateTime desc | Groups deleted in the last 30 days that are still recoverable. |
| Restored groups | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=lastRestorationDateTime ge 2026-01-19T13:18:40.175Z&$orderby=lastRestorationDateTime desc | Groups restored from soft-delete in the last 30 days. |
Security & Compliance#
| UI Label | API Call | Explanation |
|---|---|---|
| Groups without Sensitivity Labels | GET https://graph.microsoft.com/beta/reports/identityAnalytics/groups?$filter=sensitivityLabelCount eq 0 | Groups with no sensitivity label applied, meaning data protection policies may not be enforced. |
Happy learning!


Comments
Comments load when you scroll here.