Ensure that only administrators or properly delegated users (i.e., users with tenant creator roles) have the permission to create Microsoft Entra ID or Azure Active Directory B2C tenants.
By default, anyone who creates a Microsoft Entra ID tenant will become the global administrator for that tenant. By setting Restrict non-admin users from creating tenants to Yes in the Microsoft Entra ID settings, you can limit the creation of tenants to the global administrator or delegated users with tenant creator roles. Enforcing the Restrict non-admin users from creating tenants setting will ensure that only authorized identities can create new tenants.
Audit
To determine if non-admin, non-authorized users are allowed to create Microsoft Entra ID tenants, perform the following operations:
Remediation / Resolution
To ensure that non-admin, non-authorized users are not allowed to create Microsoft Entra ID tenants, perform the following operations:
References
- Azure Official Documentation
- What is Microsoft Entra ID?
- Quickstart: Create a new tenant in Microsoft Entra ID
- What are the default user permissions in Microsoft Entra ID?
- Add or update a user's profile information and settings in the Microsoft Entra admin center
- Review tenant creation permission in Azure Active Directory B2C
- Global Administrator
- Tenant Creator