fbpx

Unprivileged Users Can Create M365 and Security User Groups

TCM-KB-CLD-002
Last Updated: 6/26/2023

Microsoft 365

Microsoft 365 is a subscription-based service offered by Microsoft that includes a suite of productivity tools and cloud services. It provides access to applications like Word, Excel, PowerPoint, Outlook, and OneNote, along with services such as OneDrive for cloud storage. Depending on the plan, it also offers advanced security features, device management tools, and regular software updates. 

Active Directory

Active Directory is a directory service developed by Microsoft for Windows domain networks, and it provides centralized management and authentication services for the network.

Contributor

Joe Helle

Joe Helle

Chief Hacking Officer

This Knowledge Base Article was submitted by: Joe Helle.

Recent Blogs

Issue

Unprivileged users are not restricted from creating M365 and Security Groups in Azure Active Directory.

 

Recommended Remediation

The following outlines the recommended steps that the systems and network administrators should take in order to secure the environment.

  • After logging into the Azure tenant as a privileged user (i.e., Global Administrator), access the Azure Active Directory option.

Microsoft Azure Services

  • Select the Groups blade under Manage.

Microsoft Azure Groups

  • Select General under Settings.

Azure General Settings Window

  • In the General menu, set Self Service Group Management options to No. Set Security Groups and Microsoft 365 Groups to No. Click Save.

Self Service Group Management O365

 

example title page of a pentesting report at TCM Security

See What We Can Do For You

Download a sample penetration test report to see the results we can deliver for your organization.

See How We Can Secure Your Assets

Let’s talk about how TCM Security can solve your cybersecurity needs. Give us a call, send us an e-mail, or fill out the contact form below to get started.

 

tel: (877) 771-8911 | email: [email protected]