Ensure that the "Restrict user ability to access groups features in the Access Panel" setting is set to "Yes" within your Microsoft Entra ID configuration in order to make sure that non-privileged users are not able to create and manage security groups using the Azure Access Panel.
This rule resolution is part of the Conformity Security & Compliance tool for Azure.
Security groups are used to manage member and machine access to Microsoft Azure cloud resources for a group of users. When the "Restrict user ability to access groups features in the Access Panel" setting is not enabled, all the users within your Microsoft Entra ID account are allowed to create new security groups and add members to those groups. Because security groups can grant access to sensitive and private data or critical configuration information, security group creation and management should be restricted to Microsoft Entra ID administrators only (unless your business requires permission delegation).
Audit
To determine if non-privileged users have the ability to access group features within Azure Access Panel, perform the following operations:
Note: Getting "Restrict user ability to access groups features in the Access Panel" configuration status using Microsoft Graph API or Azure CLI is not currently supported.Remediation / Resolution
By setting "Restrict user ability to access groups features in the Access Panel" to "Yes", only Global Administrators can access Microsoft Entra group features in the Access Panel, enhancing the access security to your Microsoft Entra ID resources. To disable the setting, perform the following actions:
Note: Restricting user access to Microsoft Entra group features in the Access Panel using Microsoft Graph API or Azure CLI is not currently supported.References
- Azure Official Documentation
- Set up self-service group management in Microsoft Entra ID
- PA-1: Protect and limit highly privileged users
- PA-5: Automate entitlement management
- PA-2: Restrict administrative access to business-critical systems
- GS-2: Define enterprise segmentation strategy
- GS-6: Define identity and privileged access strategy