Control: Azure > CIS v2.0 > 01 - Identity and Access Management > 1.21 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No'
Configures auditing against a CIS Benchmark item.
Level: 2
Restrict Microsoft 365 group creation to administrators only.
Restricting Microsoft 365 group creation to administrators only ensures that creation of Microsoft 365 groups is controlled by the administrator. Appropriate groups should be created and managed by the administrator and group creation rights should not be delegated to any other user.
Resource Types
This control targets the following resource types:
Primary Policies
The following policies can be used to configure this control:
- 1.21 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No'
- 1.21 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No' > Attestation
Category
In Your Workspace
Developers
- tmod:@turbot/azure-cisv2-0#/control/types/r0121
- tmod:@turbot/cis#/control/categories/v071406
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/azure-cisv2-0#/control/types/r0121"
Get Controls
Control Type URI
Category URI
GraphQL
CLI