When you assign a Teams policy to a security group, the policy may not apply to members as expected. Users might still see the default global policy or an older assigned policy. This issue usually happens because the policy assignment order, group membership, or license state is misconfigured. This article explains the root cause and gives exact steps to verify and fix the assignment.
You will learn how to check the effective policy, correct the assignment priority, and confirm that the security group is properly synced and licensed. Follow the steps in order to avoid missing a hidden cause.
Key Takeaways: Fix Teams Policy Assignment for a Security Group
- Teams admin center > Users > Manage users > Policies: Shows the effective policy assignment that can override the security group assignment.
- Teams admin center > Teams policies > Assign policies: Lists all group assignments and their priority order, which determines which policy wins.
- Group membership sync via Microsoft Entra ID: Confirms that the security group is synced and that all members are present before policy assignment.
Why Teams Policy Assignment Does Not Apply to a Security Group
Teams policy assignment for security groups uses a priority-based system. When you assign a policy to a group, Teams applies it only if the user does not have a direct policy assignment of the same type. Direct assignment always overrides group assignment, regardless of priority.
If the user already has a direct policy assignment, the group policy will not apply. The same happens if the user is not actually a member of the security group, or if the group has not been synced to Microsoft Entra ID. Another common cause is that the group assignment is still in progress. It can take up to 24 hours for the policy to propagate to all members.
License state also matters. A user without a Teams license will not receive any policy from a group. The user must have an active Teams license and be enabled for Teams in Microsoft 365.
Policy Assignment Order and Priority
When multiple groups assign the same policy type, the assignment with the highest priority wins. Priority is set when you create the assignment. Lower numbers have higher priority. If two groups have the same priority, the assignment created later takes precedence.
Steps to Diagnose and Fix Teams Policy Assignment for a Security Group
Follow these steps in order. Each step verifies one part of the assignment chain.
- Check the effective policy for the affected user
Open the Teams admin center and go to Users > Manage users. Select the user and open the Policies tab. Look for the policy type that is not applying. The value shown here is the effective policy. If it is not the security group policy, then a direct assignment or a higher-priority group is overriding it. - Remove any direct policy assignment
If the user has a direct assignment of the same policy type, remove it. In the user’s Policies tab, click Edit for that policy type and set it to Not applied. Wait a few minutes, then recheck the effective policy. The group policy should now appear. - Verify the security group membership
Go to Microsoft Entra admin center > Groups. Find the security group and open Members. Confirm that the affected user is listed. If not, add the user and wait for the group to sync to Teams. Group membership changes can take up to 24 hours to propagate. - Check group sync status
In the same group page, review the Sync status. If the group is not synced, the policy will not apply. If you use an on-premises group, run a Microsoft Entra Connect sync or use the cloud sync agent. - Verify the user has a Teams license
Go to Microsoft 365 admin center > Users > Active users. Select the user and open Licenses and apps. Confirm that Microsoft Teams is turned on. If not, enable it and wait a few hours. - Check the priority of the group policy assignment
In the Teams admin center, go to Teams policies > Assign policies. Find the assignment for your security group. Note the Priority value. If another group with a higher priority also assigns the same policy type, that policy wins. Edit the assignment and set a lower priority number to make it take precedence. - Wait for propagation and confirm
After making changes, wait up to 24 hours. Then recheck the effective policy for the user. If the policy still does not apply, create a new assignment for the same group and policy, then delete the old one. This forces a fresh propagation.
If Teams Still Has Issues After the Main Fix
Teams Policy Assignment Shows but Users Do Not See the Change
This can happen if the user is currently signed in to Teams. The policy is applied at sign-in. Have the user sign out and sign back in. In some cases, a full restart of the Teams client is required.
Security Group Is Not Available in the Assign Policies List
The group must be a security group with mail enabled or a Microsoft 365 group. Distribution groups are not supported. Also, the group must not contain more than 50,000 members. If the group is too large, split it into smaller groups.
Policy Applies to Some Members but Not Others
Check if the missing members have a different license or a direct assignment. Also verify that they are not in another group with a higher-priority assignment.
Groups vs Direct Assignment vs Default Policy: Key Differences
| Item | Direct Assignment | Group Assignment | Global Default Policy |
|---|---|---|---|
| Priority | Always wins | Wins over default | Lowest priority |
| Management effort | Per user, high effort | Per group, low effort | Single policy for all |
| Propagation time | Immediate | Up to 24 hours | Immediate |
| Best for | Exceptions | Teams of users | Baseline settings |
Now you can diagnose why a Teams policy does not apply to a security group. Check the effective policy first, then remove direct assignments, verify group membership and licensing, and adjust the priority order. Use the Teams admin center to confirm each change after a propagation wait of up to 24 hours. For persistent issues, recreate the group assignment to force a fresh push. Remember that direct assignment always overrides group assignment, so keep direct assignments only for exceptions.