Home > Microsoft 365 Groups/Microsoft Teams Provisioning and Management > Create Group Service
Export to PDFConfigure Create Group services to define the Create Group service request template for business users. You can customize the settings for Microsoft 365 Groups created by this service as well as configure available options for business users to choose from when requesting this service.
To create or manage services, click Service in the Request Management group within Settings. The Create Group service is integrated with the Create Group/Team/Community service. When you create a service, choose the service type Create Group/Team/Community.
Before you start the service configuration, please note the following:
All Microsoft 365 Groups newly created via Cloud Governance service requests will be registered into both AvePoint Online Services containers based on AvePoint Online Services scan rules and AvePoint Cloud Management default containers. For more details, refer to Manage Scan Profiles. The service account used by the scan profile in AvePoint Online Services will be added as the group team site administrator.
If you want to Automatically enable AvePoint Cloud Governance App, your tenant must have a Microsoft 365 service account profile. The Microsoft 365 service account profile is configured in AvePoint Online Services > Management > Service account. For details on configuring Microsoft 365 service account profiles, refer to Manage Service Account Profiles.
If you want to set settings for Subscribe Members and Outside Senders, you must configure an impersonation account in Settings > Impersonation Account Management. The impersonation account will be used to invoke Exchange Web Services APIs.
Without the impersonation account, AvePoint Cloud Governance will use Microsoft Graph APIs to manage groups. Note the following issues that are caused by Microsoft Graph APIs limitations:
Multiple domains are not supported. AvePoint Cloud Governance will create groups in your default domain.
AvePoint Cloud Governance cannot change the language of the welcome email that Microsoft sends to the group mailbox upon the group provisioning. The welcome email is in English.
AvePoint Cloud Governance cannot retrieve the last modified time of groups. Only the last modified time of group team sites can be retrieved.
On the interface for creating or editing a Create Group service, configure the following settings.
For information about common service settings that exist in all types of services, refer to Common Service Settings.
Workspace Type – Choose Microsoft 365 Group.
Tenant – Select a Microsoft 365 tenant where new Microsoft 365 Groups will reside. Your Microsoft 365 tenant is displayed here when your tenant has a Microsoft Entra ID app profile configured in AvePoint Online Services. For details, refer to Create App Profiles or Microsoft 365 Service Account Profiles.
People Picker Filter Profile – Select a people picker filter profile if you want to limit the users or groups that will be specified in the following people picker fields in the request form:
Primary group contact
Secondary group contact
Group owners
Group members
You can create a people picker filter profile in the modern Cloud Governance admin center > Management > Profiles & templates. For details, refer to Configure People Picker Filter Profiles.
Multi-Geo Locations – This section appears only when your Microsoft 365 tenant has the Multi-Geo Capabilities in Microsoft 365 service plan. If you want the group team sites for the new Microsoft 365 Groups to be created in different geo locations, select the Enable group team site provisioning in multi-geo locations checkbox. If you do not enable group team site provisioning in multi-geo locations, the group team sites will be created in the central location. The central location is the geo location where your tenant was originally provisioned.
If your Microsoft 365 tenant has the Multi-Geo Capabilities in Microsoft 365 service plan but you configure an impersonation account in AvePoint Cloud Governance (which means Exchange Web Services APIs are used to manage groups), this section is invisible. The preferred data location (PDL) property of the requester will determine the geo location where the group team site will be stored. If the requester does not have the PDL property, the group team site will be created in your tenant’s central location. For details on the impersonation account and Exchange Web Services APIs, see Required Permissions.
After you enable group team site provisioning in multi-geo locations, choose one of the following options:
Select specific geo locations – If you allow business users to choose geo locations or you want to select a geo location for group team sites created via requests for this service, choose this option.
If you want to select a geo location for all group team sites created via requests for this service, select a geo location in the table and select Assign by IT Admin. Then, select either Show as Read-Only to Business User or Hide from Business User.
Use the preferred data location of the selected user role to determine the geo location – If you want to assign the geo location according to the preferred data location (PDL) property of the requester or primary group/team contact, choose this option, and then select $Requester or $Primary Group Contact from the drop-down list.
If the requester or primary group contact does not have the PDL property, the group team site will be created in your tenant’s central location.
Outlook Experience – Choose whether to Hide the group/team from the Outlook client. If you enable this option, new Microsoft 365 Groups created via a request for the service will not be shown in the Outlook client.
Exchange Global Address List – Choose whether to Hide the group/team from the Exchange global address list. If you enable this option, new Microsoft 365 Groups created via a request for the service will not be shown in the Exchange global address list.
Welcome Email – Choose whether to Send a welcome email to users when they are added to the group created via a request for this service.
Privacy – Configure the privacy settings for new Microsoft 365 Groups. Choose one of the following privacy settings, or allow business users to configure this when submitting requests via this service:
Public – Anyone can see group/team content – Allows any user to see the group content.
Private – Only members can see group/team content – Only allows group members to see the group content.
Choose to apply the privacy settings to the request form or allow business users to configure this when submitting requests via this service. Choose from the following:
Assign by IT Admin – The privacy settings configured here will be applied to groups created via this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to configure the privacy settings when they submit requests for this service.
Once the integration with sensitivity labels is enabled for your tenant, the group’s privacy settings will be managed by the applied sensitivity label setting and do not require configuration in the policy.
Subscribe Members – Choose whether to allow Microsoft 365 Group members to receive copies of group conversations and events. Choose from the following options:
Send copies of conversations and events to group/team members’ inboxes – Choose this option to allow group members to receive copies of group conversations and events.
Don’t send copies of conversations and events to group/team members’ inboxes – Choose this option to not allow group members to receive copies of group conversations and events.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – Your option selected here will be applied to groups created via this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to configure this field when they submit requests for this service.
If the options are not available among the choices, it indicates that your tenant does not have any impersonation account configured in Settings > Impersonation Account Management. Without the impersonation account, group members cannot receive copies of conversations and events. For details on configuring an impersonation account, refer to Configure Impersonation Accounts.
Outside Senders – Choose whether to allow users outside the organization to send emails to Microsoft 365 Groups. Choose from the following options:
Allow outside senders – Choose this option to allow users outside the organization to send emails to groups.
Don’t allow outside senders – Choose this option to not allow users outside the organization to send emails to groups.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – Your option selected here will be applied to groups created via this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to configure the outside senders settings when they submit requests for this service.
If the options are not available among the choices, it indicates that your tenant does not have any impersonation account configured in Settings > Impersonation Account Management. Without the impersonation account, people outside the organization cannot email the groups. For details on configuring an impersonation account, refer to Configure Impersonation Accounts.
Language for Notifications Related to Group/Team – The language here is for the email notifications that Microsoft sends to Microsoft 365 Groups. Select one or more languages. If more than one language is selected, you must select a default language from the Default language drop-down list.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The language selected from the Default language drop-down list will be applied to groups created via this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to select languages when they submit requests for this service. The default language selected in this service will become the default option, and business users can change it to another language.
Group/Team Sensitivity Label – Select a sensitivity label for new Microsoft 365 Groups created by this service. If you select multiple sensitivity labels, you must select a default one from the Default sensitivity label drop-down list. You can also select None if you allow your business users not to select any sensitivity label in the service request form to apply to the group.
Note that this section appears only when the integration with sensitivity labels is enabled for your tenant in Settings > System settings > Sensitivity labels in the modern Cloud Governance admin center.
Choose whether to allow business users to select a sensitivity label in the request form. Choose from the following options:
Assign by IT Admin – You select the sensitivity label for groups created by the service. Choose from the following:
Show as Read-Only to Business User – The request form will show your selection, and users cannot change the sensitivity label.
Hide from Business User – The Sensitivity section will not be shown in the request form.
Assign by Business User – Business users are required to select a sensitivity label for the group in the request form.
Hub Site – Choose whether to enable hub site for group team sites that will be created along with Microsoft 365 Group provisioning. If you enable hub site, choose from the following options:
Register the group team site as a hub site
Associate the group team site with a hub site
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – Your configuration here will be applied to group team sites created by this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to choose whether to enable the hub site when they submit requests for this service.
Group/Team Classification – Select one or more classifications that you wish to apply to new Microsoft 365 Groups created via this service. If you select more than one classification, you must select a default classification from the Default group/team classification drop-down list.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The classification selected from the Default group/team classification drop-down list will be associated with groups created via this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to select from the classifications you have selected in this service when they submit requests for this service. The default classification selected in this service will become the default option, and business users can change it to another classification.
Note the following:
Once the integration with sensitivity labels is enabled in your tenant, the Group/Team Classification section will be hidden and no longer requires configuration.
Group classifications can be created in the modern Cloud Governance admin center > System settings > Group/Team advanced settings. You can refer to the instructions in the Configure Group/Team Advanced Settings section. You can also create group classifications by using Microsoft PowerShell. For details, refer to the Microsoft article Create classifications for Microsoft 365 Groups in your organization.
Time Zone – Select the checkbox and select a standard time zone for the group team site from the drop-down list.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The time zone selected here will be applied to group team sites. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to select the time zone.
Locale – Select the checkbox and select a locale for the group team site from the drop-down list. The selected locale specifies the way the group team site displays numbers, dates, and time.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The locale selected here will be applied to group team sites. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to select the locale.
Group Team Site Template – This field only appears when your Microsoft 365 environment has a custom team site template configured. Select a custom site template from the drop-down list.
For details about the custom site template, refer to the following Microsoft article: https://docs.microsoft.com/en-us/sharepoint/dev/declarative-customization/site-design-overview.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The site template selected here will be applied to group team sites created by this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to select the site template.
Click the arrow on the right-hand side to proceed to the next step.
Primary Group/Team Contact – The primary group contact will be the user designated to manage the new Microsoft 365 Groups created via this service. Assign a user to be the primary contact by entering their username into the text box. Press Enter to check if the name is valid.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The primary group contact assigned here will be associated with groups created via this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to assign the primary group contact when they submit requests for this service.
Choose whether to Notify the contact when group/team provisioning is completed. If you enable the notification, select an email template for the notification email from the drop-down list.
Secondary Group/Team Contact – The secondary group contact will be the user designated for managing the new Microsoft 365 Groups created via this service if the primary group contact is unavailable. Assign a user to be the secondary contact by entering the username into the text box. Press Enter to check if the name is valid.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The secondary group contact assigned here will be associated with groups created via this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to assign the secondary group contact when they submit requests for this service.
Choose whether to Notify the contact when group/team provisioning is completed. If you enable the notification, select an email template for the notification email from the drop-down list.
Group/Team Owners – Enter one or more usernames in the text box that will be assigned as the owners of new Microsoft 365 Groups. Then, press Enter to check if the names are valid. You can also enter the following roles in the text box to be the group owners:
$Requester
$Manager of requester
$Primary group/team/community/shared mailbox/resource mailbox/Power Platform object contact
$Secondary group/team/community/shared mailbox/resource mailbox/Power Platform object contact
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The users or roles assigned in this service will be the owners of groups created via this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows business users to assign the owners of groups when they submit requests for this service. You can also select the Require Business User Input checkbox to require business users to assign the owners in the service request.
Group/Team Members – Choose one of the following methods to assign group members:
Select group/team members manually – Add members for new Microsoft 365 Groups that will be created via this service. Enter one or more Microsoft 365 usernames, Microsoft 365 Group names, and/or security group names in the text box. Then, press Enter to check if the names are valid. You can also enter the following roles in the text box to be the group members:
$Requester
$Manager of requester
$Primary group/team/community/shared mailbox/resource mailbox/Power Platform object contact
$Secondary group/team/community/shared mailbox/resource mailbox/Power Platform object contact
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The users or roles assigned in this service will be members of groups created via this service. They will be shown as read-only to business users.
Assign by Business User – Allows business users to assign the members of groups when they submit requests for this service. You can also select the Require Business User Input checkbox to require business users to assign members in the service request.
Define rules to get group/team members dynamically – If you select this option, you can define dynamic group membership rules in the service or allow business users to define dynamic rules in the request form. Microsoft 365 users who meet the rules will automatically become group members. You can configure the following settings:
Logic option – If you add multiple rules to the list, select And or Or from the drop-down list. If you select And, the group members will be added based on all the rule conditions. If you select Or, the group members will be added based on any of the rule conditions. Let’s take an example for you to have a better understanding:
If you add multiple rules to the list with the logic order, for example, C1 Or C2 And C3. The users whose properties conform to either condition C1 or condition C2, as well as conform to condition C3 will be added as group members.
Category – Select a category for the dynamic group membership rule:
Contact information
License
Organization
Rule – Select a dynamic membership rule from the drop-down list.
Condition – Define the condition to Equals, Contains, or Is a certain value.
Value – Enter a value for the rule. Users whose properties conform to the value will be added to the group. You can choose whether to Allow requesters to define the value.
If you choose Group Assignment as the dynamic membership rule and Belongs to as the condition, you can enter multiple values for the rule.
If you want to reset the rule, click Clear Settings and set the rule settings above again. After you configure a rule, click Add to list to add it to the list. If you want to remove all the rules in the list, click Clear Table.
You can choose whether to Allow requesters to add or remove dynamic rules in the request form.
Note the following:
The dynamic membership feature was built by Cloud Governance. Cloud Governance did not leverage the dynamic membership feature of Microsoft Entra. Therefore, after a group with dynamic membership is created via a Cloud Governance request, the group membership type shown in the Microsoft Entra and Microsoft 365 admin center is Assigned, rather than Dynamic.
For inactive users who meet the dynamic membership rules but have been blocked in Microsoft Entra, they can still be added as group members. For inactive users that meet the rules but have been deleted in Microsoft Entra, they will not be added to the group.
You can also choose whether to Enable hidden membership to hide the members of the group from users who are not members of the group. With hidden membership enabled, when users view the group contact card in Outlook, they cannot see the members if they are not members of the group.
Only the membership of private groups can be hidden. Once a private group created via this service has hidden membership enabled, this private group cannot be changed to a public group.
Choose whether to allow business users to configure this option in the request form. Choose from the following:
Assign by IT Admin – The enabled or disabled hidden group membership will be applied to groups created via this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allow business users to choose whether to enable hidden group membership.
Group/Team Policy – Select one more policy that you wish to apply to this service by selecting the corresponding checkboxes. If you select more than one policy, you must select a default policy from the Default policy drop-down list.
Choose whether to allow business users to configure this field in the request form. Choose from the following:
Assign by IT Admin – The policy selected in the Default policy drop-down list will be associated with groups created by this service. Select either Show as Read-Only to Business User or Hide from Business User.
Assign by Business User – Allows the business user to select from the policies you have selected in this service when they submit requests for this service. The default policy selected in this service will become the default option, and business users can change it to another policy.
You can also choose whether to Allow requesters to configure the group/team lease period when they submit requests for this service.
Click the arrow on the right-hand side to proceed to the next step.
AvePoint Cloud Governance App and App Part – Choose to automatically enable the AvePoint Cloud Governance App during Microsoft 365 Group creation. The app provides Microsoft 365 end users with easier access to AvePoint Cloud Governance without having to leave the group team site interface.
Choose whether to Automatically add Cloud Governance Panel app part into the group team site.
For details, refer to Install the Cloud Governance Panel.
Group/Team Name andID – If names and/or IDs of your tenant’s Microsoft 365 Groups require rules, enable one or both of the following options: Construct group/team name and Set group/team ID rule. Otherwise, leave the checkbox as deselected and business users can enter desired content as group names and group IDs.
Construct group/team name – If you select this checkbox, refer to the following steps to construct a group name:
Click Add for the prefix and/or suffix of the group name.
Select Text, Metadata, or Attribute as a rule from the drop-down list, and then define the value for the selected rule.
The metadata with the type of Single line of text, Choice, Person or group, Managed metadata, or Microsoft Entra Property can be used to set the rule.
You can repeat the steps above to add more rules that will be used to build the group name.
Choose to define group names for Microsoft 365 Groups created via this service or allow business users to define group names based on the prefixes/suffixes in your rules. Choose from the following:
Assign by IT Admin – The prefixes/suffixes you set here will be used to build group names for Microsoft 365 Groups created via this service. Group names will be displayed to business users as read-only.
Assign by Business User – The prefixes/suffixes you set here will be displayed to business users as read-only. Apart from the prefixes/suffixes, business users can enter additional content to build group names. You can select the Require Business User Input checkbox to require business users to enter additional content for group names.
Set group/team ID rule – If you select this checkbox, you can choose to Construct group/team ID with prefix/suffix/sequence number or choose to Automatically populate group/team ID with group/team name and hide group/team ID from business users.
If you enable the Automatically populate group/team ID with group/team name and hide group/team ID from business users option, the group ID will not be shown in the request form and AvePoint Cloud Governance will set the group ID according to the group name.
If you choose to Construct group/team ID with prefix, suffix, or sequence number, complete the following steps:
Click Add for the prefix and/or suffix of the group ID.
Select Text, Metadata, or Attribute as a rule from the drop-down list, and then define the value for the selected rule.
The metadata with the type of Single line of text, Choice, Person or group, Managed metadata, or Microsoft Entra property can be used to set the rule.
You can repeat the steps above to add more rules that will be used to build the group ID.
You can choose to Automatically add a sequence number to the end of the group/team ID. Refer to the example below to enter the sequence number rule.
| Sequence Number | Note |
|---|---|
| {01} | The sequence number at the end of the group ID will increase from 01 to 99 in numerical value. |
| {01*} | The sequence number at the end of the group ID will increase from 01 to 999999999 in numerical value. |
Choose to define group IDs for Microsoft 365 Groups created via this service or allow business users to define group IDs based on the prefixes/suffixes in your rules. Choose from the following:
Assign by IT Admin – The prefixes/suffixes you set here will be used to build group IDs for Microsoft 365 Groups created via this service. Group IDs will be displayed to business users as read-only.
Assign by Business User – The prefixes/suffixes you set here will be displayed to business users as read-only. Apart from the prefixes/suffixes, business users can enter additional content to build group IDs. You can select the Require Business User Input checkbox to require business users to enter additional content for group IDs.
Do not allow duplicate group/team names – If you select this checkbox, requesters who submit a request via this service will not be allowed to create a group with a name that is the same as an existing one.
Links in Request/Task Details Page – Choose whether to display links of Planner, Site, Files, Conversations, and/or Notebook that will be created together with Microsoft 365 Groups.
When you have finished configuring settings for this service, choose one of the following options:
Click the arrow on the left-hand side to go to the previous steps to review and modify your configurations.
Click Save to save all of the configurations and return to the Service Management interface.
Click Save and Activate to save all of the configurations and activate this service, which allows users to submit requests for this service.
Click Cancel to return to the Service Management interface without saving any configurations.