How to Check and Restrict Who Can Create Microsoft 365 Groups
Question details
The user needs to restrict the ability of regular users to create new Microsoft 365 Groups and wants to verify these configuration changes securely.

- Product
- Microsoft 365 / Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Managing enterprise security policies to prevent unauthorized or uncontrolled Microsoft 365 group creation across the organization.
- Observed behavior
- By default, regular users can create groups. The goal is to disable this in Entra ID and confirm the setting returns as false via Microsoft Graph Explorer.
Ensure you are logged in with Global Administrator or Privileged Role Administrator credentials in Microsoft 365 to modify Entra ID group policies and execute Microsoft Graph queries.
Disable Group Creation in Entra ID and Verify via Graph Explorer
Use the Microsoft 365 admin center to restrict group creation permissions, then query the Microsoft Graph API to confirm the policy is active.
Restricting Microsoft 365 group creation helps prevent directory sprawl and ensures that only authorized administrators or designated users can create unified groups. Verification through Microsoft Graph ensures the policy has propagated correctly at the API level.
Open the Microsoft 365 admin center, expand the left navigation menu, and select 'Microsoft Entra ID' to open the centralized identity management portal.
In the Entra ID dashboard, click on 'Groups' from the side menu, then select 'General' to view tenant-wide group configurations.
Locate the 'Microsoft 365 Groups' section and toggle the setting for 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' to 'No'. Click 'Save' to apply the restriction.
Navigate to the Microsoft Graph Explorer website. Sign in with your admin account and consent to the required permissions (e.g., Directory.Read.All).
Run a GET query to 'https://graph.microsoft.com/v1.0/groupSettings'. Inspect the JSON response; if the relevant group creation setting returns a 'false' value, the restriction has been successfully applied to regular users.

Manage Your Documents Locally with WPS Office
While enforcing security policies in Microsoft 365 requires complex Entra ID management, handling daily document tasks shouldn't be complicated. Equip your team with WPS Office, a fast, lightweight, and highly compatible alternative that reduces cloud dependency and administrative overhead.
- 1. Download the Installer: Visit the official WPS website and download the free, lightweight installation package for your operating system.
- 2. Install WPS Office: Run the installer file and follow the quick on-screen instructions to set up the software in minutes.
- 3. Open Office Files Instantly: Launch WPS Office and directly open your existing Word, Excel, or PowerPoint files without worrying about complex cloud permissions.

Frequently Asked Questions
Why should I restrict users from creating Microsoft 365 Groups?
Restricting group creation helps prevent 'group sprawl,' a common issue where users create redundant or abandoned groups. This limits clutter in your Global Address List, minimizes security risks, and reduces the administrative burden of auditing unused SharePoint sites and Teams.
Can I allow a specific set of users to create groups while blocking others?
Yes. You can create a dedicated security group in Microsoft Entra ID, add your authorized users to it, and then configure the directory settings via PowerShell to allow only members of that specific security group to create Microsoft 365 Groups.
What permissions are required to check groupSettings in Microsoft Graph?
To successfully query the 'groupSettings' endpoint in Microsoft Graph Explorer, your administrator account must be granted the 'Directory.Read.All' or 'Directory.ReadWrite.All' delegated permissions.




