In Exchange Online, MyDistributionGroups lets users create, view, and edit distribution groups they own. It also lets them add, remove, and manage members for those groups.
What the MyDistributionGroups role actually allows
Default scope is broad
- Can create new distribution groups.
- Can modify owned groups beyond membership in many cases.
- Can access settings that may be too permissive for end users.
Granular restriction is limited
the documented behavior points to simple on or off controls for this user role, not a detailed permission matrix. That means the exact goal of “owners and members only” may not be fully enforceable through a native toggle alone.
- Proxy addresses may still be exposed under broader role behavior.
- Approval and delivery settings may remain editable if the role is too open.
- Creating new groups is a separate concern to verify during testing.
Observed editable areas
Proxy addresses, membership approval, delivery management, message approval, and email options.
Too much owner control can create future governance and support issues after migration.
MyDistributionGroups is the main mechanism to inspect, but it is not clearly granular enough for this exact requirement.
Why this matters more after Microsoft’s 2023 change

Microsoft stated that beginning in August 2023, distribution groups could no longer be managed from Outlook on the web. Management moved to the Exchange admin center, which makes Exchange role behavior the practical control point for this scenario.
- Reference: Microsoft distribution groups guidance.
- End-user portal: Exchange admin center groups page.
The permission model the tenant is trying to reach
End users should be able to manage only owners and members for distribution groups they already own. They should not be able to change broader configuration settings or create new groups if that behavior causes governance problems.
- Add or remove members.
- Add or remove owners.
- Proxy address changes.
- Approval, delivery, and email option changes.
- Creation of new distribution groups.
Suggested workflow in Exchange admin center
The source proposes testing a custom role group together with a custom role assignment policy. This is a practical workflow to validate, but available documentation does not prove that Exchange Online can fully restrict every non-membership setting in the exact way requested.
Create a custom role group
Open the Exchange Admin Center at admin.exchange.microsoft.com. In the left pane, go to Permissions and then Admin roles, then use the + button to create a new role group.
- Name the role group clearly for testing.
- Keep the scope limited to the users who need group management.
Add role assignments carefully
Use the Distribution Groups role for group management, but avoid adding broader roles that obviously permit unrelated changes. The source also notes that this role can still allow owners to manage many aspects of groups they own, so this step alone may not be restrictive enough.
- Review whether proxy address and approval-related capabilities are still exposed.
- Do not assume the Distribution Groups role limits users to members and owners only.
Check whether User roles exposes a custom policy option
The proposed path is to return to Permissions, open User roles, and create a new policy with the + button. In that policy, allow only add or remove owners and add or remove members, then clear options that permit other changes.
- If the section or button is missing in your tenant, do not invent a workaround in production.
- That absence is a real limitation reported in the source and may reflect current Exchange Online UI behavior.
Assign to a test user and verify the result
Assign the new configuration only to a test user first. Then sign in through the Exchange admin center groups page and confirm exactly what that user can still edit on a distribution group they own.
- Expected result: the user can update owners and members.
- Verification: check whether proxy addresses, approval settings, delivery management, email options, or new group creation are still available.
- If broader access remains, the exact restriction goal is not achieved by the tested configuration.
What the documented behavior supports vs. what remains uncertain
| Area | Supported by source | Practical meaning |
|---|---|---|
| MyDistributionGroups exists | Yes | It is the relevant end-user role area for owned distribution groups. |
| Owners can manage members | Yes | This part of the requirement is aligned with the default role behavior. |
| Owners can be limited to members and owners only | Not proven | The source suggests testing a custom policy, but does not confirm a successful granular restriction. |
| Custom role assignment policy is visible in EAC | Inconsistent | The requester reported they could not find that section in their tenant. |
| Outlook on the web remains the management path | No | Microsoft moved distribution-group management to the Exchange admin center. |
What to do if the custom policy section is missing
The source explicitly reports that the Permissions > User roles path for creating a custom role assignment policy could not be found. If that matches your tenant, the safest conclusion is that the UI path is unavailable or changed for your environment.
- Do not assume a missing menu means you overlooked a hidden toggle.
- Validate in a test account whether current Exchange Online behavior can meet the requirement at all.
- Use the related reference only as background: granular permissions article. The source already notes it was not restrictive enough for this exact goal.
Exchange Online can be tested for tighter group ownership, but the exact lock-down is not confirmed
the documented behavior supports a careful EAC workflow using role groups and user-role policy checks, but it also shows a key limitation: the tenant may not expose the custom policy path, and native controls may still be too broad. Test with a pilot user before assuming owners can be limited to members and owners only.
Use WPS Office as a Free Microsoft Office Alternative
This permission issue is controlled by Microsoft 365 and Exchange Online, so WPS Office cannot change tenant roles, admin-center menus, or Microsoft-side distribution-group controls.
WPS Office is still useful around this workflow when you need a free, lightweight tool to document your test matrix, compare permission results in XLSX sheets, prepare rollout notes in DOCX, or review exported PDFs. It has a familiar interface, PDF tools, and WPS AI features that can help summarize validation notes, though complex Microsoft 365 admin behavior must still be verified in Exchange Online itself.

Restrict MyDistributionGroups Permissions in Exchange Online FAQs
Why can’t I find Permissions > User roles > create policy in the Exchange admin center?
The evidence shows that this section was suggested, but the requester could not find it. That means the option may not be exposed in the current tenant experience, may differ by interface version, or may not be available as assumed.
How do I verify whether a test user still has too much group access?
Assign the intended role setup, sign in as the test user, open the Exchange admin center groups page, and inspect every editable area. If the user can still change proxy addresses, approval settings, delivery controls, or create new groups, the restriction is broader than you need.
What does the default MyDistributionGroups role allow in Exchange Online?
By default, the MyDistributionGroups role allows users to create, view, and modify distribution groups they own. It also permits them to add, remove, and review members for those groups.
Can I restrict distribution group owners to only manage members and owners?
Based on the provided evidence, Exchange Online does not clearly expose a supported, fine-grained MyDistributionGroups setting that limits owners to only adding or removing owners and members while blocking all other group settings.




