How to Update Mail-Enabled Security Groups with Python and Microsoft Graph
Question details
The user needs to know how to update mail-enabled security groups using a Python application connected to the Microsoft Graph REST API.

- Product
- Microsoft Graph API
- Device & OS
- not provided
- Scenario
- Developing a Python application to programmatically manage Microsoft 365 groups and mail-enabled security groups.
- Observed behavior
- Mail-enabled security groups and distribution groups appear as read-only via the standard Microsoft Graph Groups API, preventing direct updates from the Python application.
Before attempting to modify groups via the API, verify the specific group type in your Azure AD portal and ensure your registered application has the necessary Group.ReadWrite.All permissions granted.
Use Exchange Online PowerShell for Mail-Enabled Groups
Since Microsoft Graph treats mail-enabled security groups as read-only, using Exchange Online PowerShell is the officially supported method for making updates.
The Microsoft Graph REST API restricts write access to mail-enabled security and distribution groups because they are primarily managed by Exchange Online. To modify these groups, you must bypass the standard Graph REST API and utilize Exchange Online PowerShell commands.
Open a PowerShell window as an administrator and execute the 'Connect-ExchangeOnline' cmdlet to authenticate with your Microsoft 365 admin credentials.
Use the 'Set-DistributionGroup' cmdlet to modify the mail-enabled security group's properties, or 'Update-DistributionGroupMember' to change its membership.
To maintain automation within your Python app, use Python's built-in 'subprocess' module to call your PowerShell scripts and pass the necessary group update variables.

Manage Standard Microsoft 365 Groups via Python
If you are not strictly required to use mail-enabled security groups, switch to standard Microsoft 365 or Security groups which are fully supported for read/write operations via Microsoft Graph.
Manage Your IT Documentation seamlessly with WPS Office
While managing Microsoft 365 groups requires specific APIs and PowerShell scripts, WPS Office offers a free, lightweight, and highly compatible alternative for handling your IT documentation, scripting notes, and administrative spreadsheets.
- 1. Download WPS Office: Visit the official WPS website to download and install the free WPS Office suite on your machine.
- 2. Open Your Documentation: Use WPS Writer to document your Python API scripts or WPS Spreadsheet to view CSV exports of your group members.
- 3. Save in Standard Formats: Save your work seamlessly in .docx or .xlsx formats to share with other members of your IT team.

Frequently Asked Questions
Why do I get a read-only error when updating a mail-enabled group via Microsoft Graph?
Mail-enabled security groups and distribution lists are primarily managed by Exchange Online infrastructure. The Microsoft Graph Groups API generally exposes these specific group types as read-only, preventing direct property or membership updates via REST requests.
Where can I get support for Microsoft Graph API development with Python?
For detailed questions regarding Microsoft Graph functionality, permissions, or API development, it is highly recommended to post in the Microsoft Graph community on the Microsoft Q&A platform to get assistance from specialized engineers.
Can I automate Exchange PowerShell commands using Python?
Yes. You can use Python's 'subprocess' module to execute a local PowerShell instance. This allows your Python application to run Exchange Online cmdlets silently and manage mail-enabled security groups as part of an automated workflow.




