Export (0) Print
Expand All
Expand Minimize

Get-MsolGroup

Published: March 22, 2013

Updated: September 17, 2014

Applies To: Azure, Office 365, Windows Intune

noteNote
  • This topic provides online help content for cloud services, such as Windows Intune and Office 365, which rely on Microsoft Azure Active Directory for identity and directory services.

  • The Microsoft Azure Active Directory Module for Windows PowerShell cmdlets were previously known as the Microsoft Online Services Module for Windows PowerShell cmdlets.

The Get-MsolGroup cmdlet is used to retrieve groups from the connected Microsoft Online Services tenant. This cmdlet can be used to return a single group, if ObjectId is passed in, or to search within all groups.

Get-MsolGroup [-GroupType <string>] [-HasErrorsOnly] [-IsAgentRole] [-MaxResults <int>] [-SearchString <string>] [-TenantId <Guid>] [-UserObjectId <Guid>] [-UserPrincipalName <string>] [<CommonParameters>]

    -All [<SwitchParameter>]
        If present then all results will be returned.  Cannot be used with 
        MaxResults parameter.
        
        Required?                    false
        Position?                    named
        Default value                
        Accept pipeline input?       false
        Accept wildcard characters?  false
        
    -GroupType <string>
        The filter to return only groups of the specified type. Valid values 
        are Security, MailEnabledSecurity, and DistributionList.
        
        Required?                    false
        Position?                    named
        Default value                
        Accept pipeline input?       false
        Accept wildcard characters?  false
        
    -HasErrorsOnly [<SwitchParameter>]
        The filter for only groups with validation errors.
        
        Required?                    false
        Position?                    named
        Default value                
        Accept pipeline input?       false
        Accept wildcard characters?  false
        
    -IsAgentRole [<SwitchParameter>]
        The filter for only agent groups. Used by partners only.
        
        Required?                    false
        Position?                    named
        Default value                
        Accept pipeline input?       false
        Accept wildcard characters?  false
        
    -MaxResults <int>
        The maximum number of results returned for a search. If not specified, 
        250 results will be returned.
        
        Required?                    false
        Position?                    named
        Default value                250
        Accept pipeline input?       false
        Accept wildcard characters?  false
        
    -ObjectId <Guid>
        The unique ID of the group to retrieve.
        
        Required?                    true
        Position?                    named
        Default value                
        Accept pipeline input?       true (ByPropertyName)
        Accept wildcard characters?  false
        
    -SearchString <string>
        The string to search on. Only groups with a display name or email 
        address starting with this string will be returned.
        
        Required?                    false
        Position?                    named
        Default value                
        Accept pipeline input?       false
        Accept wildcard characters?  false
        
    -TenantId <Guid>
        The unique ID of the tenant to perform the operation on. If this is 
        not provided, then the value will default to the tenant of the current 
        user. This parameter is only applicable to partner users.
        
        Required?                    false
        Position?                    named
        Default value                
        Accept pipeline input?       true (ByPropertyName)
        Accept wildcard characters?  false
        
    -UserObjectId <Guid>
        The unique ID of a user. If provided, only groups that this user 
        belongs to will be returned. This parameter must be used along with 
        IsAgentRole.
        
        Required?                    false
        Position?                    named
        Default value                
        Accept pipeline input?       false
        Accept wildcard characters?  false
        
    -UserPrincipalName <string>
        The user ID of a user. If provided, only groups that this user belongs 
        to will be returned. This must be used along with IsAgentRole.
        
        Required?                    false
        Position?                    named
        Default value                
        Accept pipeline input?       false
        Accept wildcard characters?  false
        
    <CommonParameters>
        This cmdlet supports the common parameters: Verbose, Debug,
        ErrorAction, ErrorVariable, WarningAction, WarningVariable,
        OutBuffer and OutVariable. For more information, type,
        "get-help about_commonparameters".

The output is provided by Microsoft.Online.Administration.Group. The cmdlet returns a list of groups, which include the following information:

  • CommonName: The group's common name.

  • Description: A description of the group.

  • DisplayName: The group's display name.

  • EmailAddress: The group's email addresses. This is not returned for security groups.

  • Errors: A list of errors for the group.

  • GroupType: The group's type. Types can be SecuityGroup, Distributionlist or MailEnabledSecuirtyGroup.

  • IsSystem: Whether or not this group is a system group (created by Microsoft Online Services). These groups cannot be updated or removed.

  • LastDirSyncTime: The date and time that the group was last synched.

  • ManagedBy: The owner of the group.

  • ObjectId: The group's unique object ID.

  • ValidationStatus: Whether or not the group has any errors.

The following command returns the entire set of groups for the tenant (up to 250).

Get-MsolGroup

This command returns the agent groups that a user is a member of. This only applies for companies that have partner privileges.

Get-MsolGroup -isAgentRole -UserPrincipalName user@contoso.com

The following command displays the information of the group that is specified by the GUID of the ObjectID in list format.

Get-MsolGroup -ObjectId fd65dbac-5c7a-4596-815f-e8457eb6173f | format-list

The following command displays all the security groups in list format.

Get-MsolGroup -GroupType Security | format-list

See Also

Was this page helpful?
(1500 characters remaining)
Thank you for your feedback
Show:
© 2014 Microsoft