GOV-10Moderate

How to Fix: Restrict Security Group Creation

Step-by-step guide to implement restrict security group creation in your Microsoft 365 environment.

See your drift in 5 minutesAuto-remediate GOV-10 on your tenant

Free baseline scan · No credit card · 5 minute setup

15-20 minutes

Estimated Time

4

Steps

low

Severity

Recommended Secure

Baseline Level

Why This Matters

Security groups are used in access grants and policy targeting. If any user can create them, group sprawl and ungoverned access assignments follow, weakening least-privilege and complicating access reviews.

Prerequisites

  • 1Global Administrator or appropriate admin role in Microsoft Entra ID
  • 2Access to Microsoft Entra admin center (entra.microsoft.com)

Expected Configuration

  • Non-admin users cannot create security groups
  • Security group creation is restricted to administrators
  • authorizationPolicy.defaultUserRolePermissions.allowedToCreateSecurityGroups is false

Remediation Steps

1

Review Current Configuration

Assess your current configuration in Microsoft Entra admin center.

  • Navigate to the relevant section in Entra admin center
  • Document current settings
  • Compare against expected state
2

Plan Implementation

Determine the changes needed to meet the expected configuration.

  • Review expected configuration requirements
  • Identify affected users or resources
  • Plan rollout strategy
3

Implement Changes

Apply the necessary configuration changes.

  • Make required configuration updates
  • Apply to appropriate scope
  • Document changes made
4

Validate and Monitor

Verify the changes are working as expected.

  • Run TrueConfig scan to verify compliance
  • Test affected functionality
  • Set up ongoing monitoring

Related Resources

Automate Your Security Configuration

TrueConfig continuously monitors your Microsoft 365 environment and can automatically fix configuration drift. Start your free trial today.

Start Free Trial