Missing group members

Jimmy Zheng 0 Reputation points
2025-10-27T22:01:18.3233333+00:00

We have a group that we utilize for VPN access. Over the weekend, we discovered all members got deleted from the group. When we looked at the audit logs, there were no deletion of any accounts. Has anyone experienced this issue? Is there another system logs I might be able to look why this is happening?

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. JasonTranNguyen-3858 1,240 Reputation points Independent Advisor
    2025-10-28T04:51:37.3033333+00:00

    Hi Jimmy Zheng,

    Based on your description, If the audit logs don’t show any deletion activity, I recommend checking the Azure AD sign-in logs and group activity reports for any anomalies, especially around automated processes, conditional access policies, or identity governance tools like access reviews or entitlement management. Also, if the group is synced from on-premises AD, it’s worth reviewing the synchronization logs and rules in Azure AD Connect to ensure no misconfigurations or sync errors occurred.

    Another possibility is that a dynamic group rule may have changed, causing members to be removed automatically. Reviewing the group type and membership rules could help clarify that.

    Let me know what you find, and feel free to share any additional details. I’m happy to dig deeper with you. If this answer helps, please hit "Accept Answer" so others can benefit too 😊

    Jason,

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.