CTD-000103

Microsoft Entra tenant where regular users can create Microsoft 365 groups

Low
Entra ID
Collection
v15

Signature Identity

CTD-000103
Threat ID
15
Version
IOE
Indicator Type

Threat Description

Microsoft 365 groups are used to manage access to resources and services in Azure. If a regular user can create groups in the tenant, a threat actor might create a group and use that group to get access to other user accounts. Microsoft 365 groups creation should be restricted to Microsoft Entra administrators only.

MITRE ATT&CK: Attack Tactics

Collection

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To prevent users from creating security groups: 

  1. Open Microsoft Entra admin center.
  2. In the navigation panel, select Groups.
  3. In the Settings section, select General.
  4. Under Microsoft 365 Groups, change Users can create Microsoft 365 groups setting to No
  5. Click Save button.

Frequently Asked Questions

What does Microsoft Entra tenant where regular users can create Microsoft 365 groups mean?

In a Microsoft Entra tenant, non-administrative users have the ability to create and manage Microsoft 365 groups without needing administrative permissions. This setting allows regular users to create groups, which can be used to grant access to resources and services.

This issue is rated low severity because an attacker would need additional steps or context to exploit the ability for non-administrative users to create groups. The risk is present but indirect, which places this issue in the lower end of the severity scale.

An attacker might use the ability to create a group to gain access to other user accounts through group membership enumeration. This could allow the attacker to collect sensitive information or even take control of resources within the tenant.

Cayosoft Guardian monitors the settings and permissions in the Entra ID platform to identify when non-administrative users have the ability to create groups. When this is found, Guardian alerts administrators to provide visibility into potential security risks.

Cayosoft Guardian assists response by helping administrators review and limit the ability for non-administrative users to create and manage groups, reducing the potential for attackers to exploit this setting.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Tenant-wide
Attack Tactics
Collection
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical