Default Entra self-service settings can lead to directory sprawl, shadow IT, and easy post-compromise persistence.
Preface
Self-service options reduce admin overhead but often grant non-admins excessive privileges by default.
Problem
Compromised standard users can register malicious apps, create groups that weaken Conditional Access, or enumerate the directory through the admin portal. Self-service group creation also enables unmonitored guest sharing.
Solution
Align with CIS Microsoft 365 Foundations Benchmark Section 1:
- Restrict Entra portal access for non-admins.
- Disable user app registrations.
- Disable self-service group creation and move group management to an approval workflow.
PowerShell: Harden Directory Access Defaults
Connect-MgGraph -Scopes "Directory.ReadWrite.All"
$params = @{
RestrictNonAdminsAndAdminsFromReadAccessToOtherUsers = $true
}
Update-MgDirectoryOnPremisesDirectorySynchronization -OnPremisesDirectorySynchronizationId "default" -BodyParameter $params