• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

O365 Groups - Who invited dis guy?

ShowMe

Graduate Poster
Joined
Jul 25, 2001
Messages
1,350
Good day all.

Having worked infrastructure and networking for far too long I have recently taken the plunge into a new area, namely Cloud and Cloud based applications.

After being the grizzled vet for many years I suddenly find myself being the 55 year old rookie.

One question has recently been brought up to me that has defied my Google-Fu to find an answer, and I am reaching out to the folks on this board hoping to find a solution.

Here's the question:

Is it possible to see who invited a user to an Office365 group? We have a situation where there is one owner of a test group who suddenly had several new members that he did not invite. It’s my understanding that anyone can invite another user but only the owner can remove them. Is there a way to tell what user invited the other users?

I'm still learning the product so any insight is appreciated.
 
Good day all.



Having worked infrastructure and networking for far too long I have recently taken the plunge into a new area, namely Cloud and Cloud based applications.



After being the grizzled vet for many years I suddenly find myself being the 55 year old rookie.



One question has recently been brought up to me that has defied my Google-Fu to find an answer, and I am reaching out to the folks on this board hoping to find a solution.



Here's the question:



Is it possible to see who invited a user to an Office365 group? We have a situation where there is one owner of a test group who suddenly had several new members that he did not invite. It’s my understanding that anyone can invite another user but only the owner can remove them. Is there a way to tell what user invited the other users?



I'm still learning the product so any insight is appreciated.
JFC. What does the vendor say?

You can't possibly be using O365 without a support contract. Can you?

Also, you're a grizzled vet, but you still don't know to put the troubleshooting you've already done, and the results, in your ticket?
 
Last edited:
JFC. What does the vendor say?


Animosity out of the gate? Geez...was that your mountain dew I drank from the fridge?

We are the vendor. I am just beginning my training on the product, and am trying to familiarize myself with, well, everything. I work from home, it's after hours and this was an odd request in the support queue. I learn better with hands on experience and wanted to poke around, but didn't want to blow anything up. Since it was after hours I decided to reach out here.



You can't possibly be using O365 without a support contract. Can you?

Seriously, you know we're supposed to label everything in the fridge or they become community property.

As I mentioned above, we are kind of the support contract. When my mentor comes in today I'll work with her, but I'm trying to ramp up as fast as I can and wanted to do what I could last night.

Also, you're a grizzled vet, but you still don't know to put the troubleshooting you've already done, and the results, in your ticket?

I can only say I'm sorry so many times. I'll buy you another one, OK?

I'm pretty sure I mentioned I'm new at the product and Googling the question produced nothing. I was simply hoping to find the right place to look; I'm new enough at the product that I am still familiarizing myself with the interface, but have been around long enough to recognize an oddity when I see it.


You may consider my chops adequately busted.
 
https://docs.microsoft.com/en-us/of...arch-the-audit-log-in-security-and-compliance

Anything there that might help?

We haven't gone to O365 yet, but are moving some things there (primairly, we're going to a hybrid Exchange environment). But the data would likely be in audit logs somewhere.

You might also check the PowerShell gallery for similar tools...I did find one to detemrine who removed agorup member, might be able to modify it:
https://gallery.technet.microsoft.com/office/Who-removed-a-Group-Member-1a5e609b
 
I would try the lazy way while you wait for MS O365 to get back to you (they were usually pretty fast as I recall), search for who sent emails to teh new members, there should be an invite email
 
I would try the lazy way while you wait for MS O365 to get back to you (they were usually pretty fast as I recall), search for who sent emails to teh new members, there should be an invite email

I'm not sure they do send emails from the actual user that did the invite. It might just be a generic "you've been invited" from the "exchange admin" acct.

My few questions would be does the O365 have AD sync on? It could be the group was created\setup on the server, and someone added them on the AD server which then replicated up to O365.

Are they a "managed" client? We have a bunch of those and if you're in the O365 admin area there is an admin centers > exchange that has a bunch of further options. You might be able to find the logs there for the group.

Let me do some digging in our environment and I'll see if I can track more down.
 
Thanks all.

As it turns out the answer is to activate auditing. It's not activated by default, since it seems Microsoft doesn't want the overhead of tens of thousands of audit logs...most of which will never be used.

For those that are interested go into Security & Compliance, click on Search and choose Audit Log Search. If you get a band that says something to the effect of "To use this feature, turn on auditing so we can" blah blah..click the little grey box that says "turn on auditing".

Then go into Permissions and make yourself a member of every permission group; there's 12 or 13 of them.

Then wait 24 hours for everything to propagate.

After that there is all kinds of things you can search for in the audit log. Of course, it will only audit things from the time you activated it...so in this case it didn't do us much good since the user wanted to know what happened at the beginning of the month.

But if anything comes up from here on out, we'll be able to track it down.
 

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom