My Groups in Microsoft 365 shows “This functionality is not enabled” for admin accounts

Entra ID accounts can view their groups as group members at myaccount.microsoft.com/groups and manage the groups as owners.

Administrators can disable this possibility in Entra ID. The groups self-service is inactive for accounts without an admin role in this configuration.

Group settings in Entra ID

The system informs normal user accounts that the functionality is not enabled.

Meine Gruppen ist nicht aktiviert
Groups self-service is not enabled

A tests confirms the restriction in Entra ID does not apply to accounts with one of the admin roles:

  • Global Administrator
  • Groups Administrator
  • User Administrator

As a simulation, I use Group-based Role Assignments to assign the admin role Groups Administrator. Alex Wilber is a member of the group and is assigned the Admin role via the group.

Groups Administrator wird über Group-based Role Assignment zugewiesen
Groups Administrator is assigned via group-based role assignment

Alex still cannot access My Groups self-service. The self-service is still inactive for his account.

Fehlender Zugriff trotz der Admin Rolle Groups Administrator
No access despite the Groups Administrator admin role

In the second test, I try a direct assignment of the Groups Administrator role. Alex Wilber has been assigned the role with both types.

Zuweisung der Rolle Groups Administrator
Assignment of the Groups Administrator role

Interestingly, groups self-service works for Alex Wilber with the direct assignment. If I remove the direct assignment, Alex can no longer access My Groups.

Meine Gruppen unterstützt kein Group-based Role Assignment
My Groups does not support group-based role assignment

I also tried the scenario with User Administrator. Same result, but only if the role is assigned via group-based role assignments.
Therefore, My Groups self-service does not support group-based role assignments. The admin role must be assigned directly to an account.

Admin roles activated via Privileged Identity Management (PIM) are not affected by this. My Groups self-service works even if the role is assigned with group-based role assignments and activated via PIM.

Share
Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with around ten years of professional experience with Microsoft 365 products such as SharePoint Online, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Reply

Your email address will not be published. Required fields are marked *