How to get all groups that multiple users belong to at once

BCAzure01 25 Reputation points
2025-10-28T04:12:42.59+00:00

As employees transfer departments, I need to identify the following MS365 groups they belong to:

  • MS365 groups - Security groups - Email-enabled security groups

Nearly 100 employees transfer each month, so each time we need to do this, it increases the workload and time required for our team members. How can I bulk extract groups to which multiple users belong?

*This assumes the execution of PowerShell commands.

[Current Method]

  • Log in to the entra Management Center and search for the target user.
  • Select the group to which the user belongs from the screen and paste it into the work Excel file.
  • After pasting, copy and paste the data into the Excel file for each management ledger for each group to identify the target user.

[Verification Status]

Based on desktop research, I executed the following command. Although multiple lines were returned, I was unable to obtain the target group name, associated ID, email address, etc.

====================

▼ 1. Graph Connection

Write-Host "Connecting to Microsoft Graph..."

Connect-MgGraph -Scopes "User.Read.All","Group.Read.All" | Out-Null

▼ 2. Input/Output Path Settings (Change as needed)

$inputPath = "C:\Users\kmorikawa\Desktop\Account Improvement Project\202510_Employee Permission Bulk Identification\Input\TransferList.csv"

$outputPath = "C:\Users\kmorikawa\Desktop\Account Improvement Project\202510_Employee Permission Bulk Identification\Output\GroupMembershipList.csv"

Initialize Output File

if (Test-Path $outputPath) { Remove-Item $outputPath }

New-Item -Path $outputPath -ItemType File | Out-Null

▼ 3. Load Transferee List

$users = Import-Csv $inputPath -Delimiter "," # If the separator is a tab, use "`t"

▼ 4. Get group information for each user

foreach ($user in $users) {

if (-not $user.Email -or [string]::IsNullOrWhiteSpace($user.Email)) {

Write-Warning "Emailが空の行をスキップしました: $($user.DisplayName)"

continue
```}

$email = $user.Email.Trim()

Write-Host "処理中: $($user.DisplayName) ($email)..."

try {

```powershell
# EmailをキーにuserPrincipalName/mail属性の両方で検索

$userObj = Get-MgUser -Filter "startswith(userPrincipalName,'$email')" -Property Id,DisplayName,Mail

if (-not $userObj) {

    $userObj = Get-MgUser -Filter "startswith(mail,'$email')" -Property Id,DisplayName,Mail

}

if ($userObj) {

    $groups = Get-MgUserMemberOf -UserId $userObj.Id -All

    foreach ($group in $groups) {

        # グループ種別分類

        $type = if ($group.GroupTypes -contains "Unified") {"M365 Group"}

                elseif ($group.MailEnabled -and $group.SecurityEnabled) {"Mail-enabled Security Group"}

                elseif ($group.SecurityEnabled) {"Security Group"}

                else {"Other"}

        # 結果出力

        [PSCustomObject]@{

            EmployeeID      = $user.EmployeeID

            DisplayName     = $user.DisplayName

            Email           = $email

            GroupName       = $group.DisplayName

            GroupType       = $type

            MailEnabled     = $group.MailEnabled

            SecurityEnabled = $group.SecurityEnabled

        } | Export-Csv -Path $outputPath -Append -NoTypeInformation -Encoding UTF8

    }

}

else {

    Write-Warning "ユーザー未検出: $email"

}
```}

catch {

```yaml
Write-Warning "エラー: $email - $_"
```}

}

▼ 5. Completion notification

Write-Host "`n処理完了しました。結果: $outputPath"

★★★★★★★★★★★★★★★★★★★★★★★★
Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
Rukmini 43,995 Reputation points Microsoft External Staff Moderator
2025-10-29T12:38:49.4466667+00:00

Hello @BCAzure01,

To get all groups that multiple users belong to at once, make use of below script:


# Connect to Microsoft Graph

Connect-MgGraph -Scopes "User.Read.All","Group.Read.All" | Out-Null

# Input CSV of users (must have column: Email)

$inputPath = "C:\Users\rukmini\Downloads\importfile.csv"

# Output CSV path

$outputPath = "C:\Users\rukmini\Downloads\GroupMembershipReport.csv"

# Initialize output file (clear if exists)

if (Test-Path $outputPath) { Remove-Item $outputPath }

# Create the header for the CSV file

"EmployeeEmail,GroupName,GroupID,Mail,MailEnabled,SecurityEnabled,GroupType" | Out-File -FilePath $outputPath -Encoding UTF8

# Load users from the input CSV

$users = Import-Csv $inputPath

foreach ($user in $users) {

    $email = $user.Email.Trim()

    Write-Host "`nProcessing user: $email..."

    try {

        # Get user information by email

        $userObj = Get-MgUser -Filter "userPrincipalName eq '$email'" -Property Id, DisplayName, Mail

        if (-not $userObj) { $userObj = Get-MgUser -Filter "mail eq '$email'" -Property Id, DisplayName, Mail }

        if ($userObj) {

            # Get all groups the user is a member of

            $groups = Get-MgUserMemberOfAsGroup -UserId $userObj.Id -Property "id,displayName,mail,mailEnabled,securityEnabled,groupTypes"

            foreach ($group in $groups) {

                # Classify the group type

                $type = if ($group.GroupTypes -contains "Unified") { "Microsoft 365" }

                        elseif ($group.MailEnabled -and $group.SecurityEnabled) { "Mail-enabled Security" }

                        elseif ($group.SecurityEnabled) { "Security" }

                        elseif ($group.MailEnabled) { "Distribution" }

                        else { "Other" }

                # Prepare the output as a CSV row

                $row = "$email,$($group.DisplayName),$($group.Id),$($group.Mail),$($group.MailEnabled),$($group.SecurityEnabled),$type"

                # Append the row to the CSV file

                $row | Out-File -FilePath $outputPath -Append -Encoding UTF8

            }

        } else {

            Write-Warning "User not found: $email"

        }

    }

    catch {

        Write-Warning "Error processing $($email): $_"

    }

}

Write-Host "`nProcessing complete for all users. Results saved to: $outputPath"

User's image

The exported output CSV file:

User's image

The import file looks like below:

User's image

Hope this helps!

If this answers your query, do click Accept Answer and Yes, if you have any further queries do let us know.

User's image

If you have any other questions, let me know in the “comments” and I would be happy to help you.

Was this answer helpful?


2 additional answers

Sort by: Newest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.