logo
search
Security Policy Errors

How to Check and Restrict Who Can Create Microsoft 365 Groups

Emma BrownEmma Brown Oct 8, 2026 868 views

Question details

The user needs to restrict the ability of regular users to create new Microsoft 365 Groups and wants to verify these configuration changes securely.

How to Check and Restrict Who Can Create Microsoft 365 Groups in Entra ID
Product
Microsoft 365 / Microsoft Entra ID
Device & OS
not provided
Scenario
Managing enterprise security policies to prevent unauthorized or uncontrolled Microsoft 365 group creation across the organization.
Observed behavior
By default, regular users can create groups. The goal is to disable this in Entra ID and confirm the setting returns as false via Microsoft Graph Explorer.
Before you start

Ensure you are logged in with Global Administrator or Privileged Role Administrator credentials in Microsoft 365 to modify Entra ID group policies and execute Microsoft Graph queries.

Solution 1Recommended

Disable Group Creation in Entra ID and Verify via Graph Explorer

Use the Microsoft 365 admin center to restrict group creation permissions, then query the Microsoft Graph API to confirm the policy is active.

Restricting Microsoft 365 group creation helps prevent directory sprawl and ensures that only authorized administrators or designated users can create unified groups. Verification through Microsoft Graph ensures the policy has propagated correctly at the API level.

1
Access Microsoft Entra ID

Open the Microsoft 365 admin center, expand the left navigation menu, and select 'Microsoft Entra ID' to open the centralized identity management portal.

2
Navigate to Group Settings

In the Entra ID dashboard, click on 'Groups' from the side menu, then select 'General' to view tenant-wide group configurations.

3
Restrict Group Creation

Locate the 'Microsoft 365 Groups' section and toggle the setting for 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' to 'No'. Click 'Save' to apply the restriction.

4
Query Microsoft Graph Explorer

Navigate to the Microsoft Graph Explorer website. Sign in with your admin account and consent to the required permissions (e.g., Directory.Read.All).

5
Verify the Policy Status

Run a GET query to 'https://graph.microsoft.com/v1.0/groupSettings'. Inspect the JSON response; if the relevant group creation setting returns a 'false' value, the restriction has been successfully applied to regular users.

Disable Group Creation in Entra ID and Verify via Graph Explorer
Propagation Time: Directory setting changes in Microsoft Entra ID can sometimes take up to an hour to fully propagate across all Microsoft 365 services and reflect accurately in Microsoft Graph.
Free Microsoft Office alternative

Manage Your Documents Locally with WPS Office

While enforcing security policies in Microsoft 365 requires complex Entra ID management, handling daily document tasks shouldn't be complicated. Equip your team with WPS Office, a fast, lightweight, and highly compatible alternative that reduces cloud dependency and administrative overhead.

  1. 1. Download the Installer: Visit the official WPS website and download the free, lightweight installation package for your operating system.
  2. 2. Install WPS Office: Run the installer file and follow the quick on-screen instructions to set up the software in minutes.
  3. 3. Open Office Files Instantly: Launch WPS Office and directly open your existing Word, Excel, or PowerPoint files without worrying about complex cloud permissions.
Simplifies enterprise software rollout without the need for complex cloud policies or Entra ID group management.Seamless compatibility with Microsoft Office formats (.docx, .xlsx, .pptx) for uninterrupted team workflows.Lightweight installation that runs flawlessly on older enterprise hardware and modern devices alike.Familiar tabbed interface that requires zero retraining for users migrating from Microsoft Office.
microsoft office alternative - wps office

Frequently Asked Questions

Why should I restrict users from creating Microsoft 365 Groups?

Restricting group creation helps prevent 'group sprawl,' a common issue where users create redundant or abandoned groups. This limits clutter in your Global Address List, minimizes security risks, and reduces the administrative burden of auditing unused SharePoint sites and Teams.

Can I allow a specific set of users to create groups while blocking others?

Yes. You can create a dedicated security group in Microsoft Entra ID, add your authorized users to it, and then configure the directory settings via PowerShell to allow only members of that specific security group to create Microsoft 365 Groups.

What permissions are required to check groupSettings in Microsoft Graph?

To successfully query the 'groupSettings' endpoint in Microsoft Graph Explorer, your administrator account must be granted the 'Directory.Read.All' or 'Directory.ReadWrite.All' delegated permissions.