The group expiration policy is an Entra ID lifecycle feature that gives Microsoft 365 groups a lifetime: groups must be renewed before expiry, and inactive ones are deleted, with a restoration window, unless someone acts. It is Microsoft's built-in answer to collaboration group sprawl.

What it covers, and what it does not#

Scope matters more than most teams expect:

  • It applies to Microsoft 365 groups, the collaboration kind Teams creates, not to security groups.
  • Activity-based auto-renewal keeps used groups alive without owner action.
  • Expired groups are deleted with a limited restoration window, after which the group and its workloads are gone.
  • Security groups, where access and licensing structure lives, have no expiration mechanism and still need deliberate cleanup.

Where it fits#

Expiration handles the volume problem for collaboration groups. The structural problems this site covers, nesting defects, licensed group hygiene, ownerless security groups, sit outside its scope, which is why enabling expiration does not end the cleanup conversation.

VisualizerEngine

Alongside VisualizerEngine

Expiration prunes the collaboration layer automatically; VisualizerEngine covers the layer expiration cannot touch: security group structure, license placement, orphan and overlap detection, and the policies that keep the access-bearing hierarchy governed.