Default Entra self-service settings can lead to directory sprawl, shadow IT, and easy post-compromise persistence.

Preface

Self-service options reduce admin overhead but often grant non-admins excessive privileges by default.

Problem

Compromised standard users can register malicious apps, create groups that weaken Conditional Access, or enumerate the directory through the admin portal. Self-service group creation also enables unmonitored guest sharing.

Solution

Align with CIS Microsoft 365 Foundations Benchmark Section 1:

  1. Restrict Entra portal access for non-admins.
  2. Disable user app registrations.
  3. Disable self-service group creation and move group management to an approval workflow.

PowerShell: Harden Directory Access Defaults

Connect-MgGraph -Scopes "Directory.ReadWrite.All"
$params = @{
    RestrictNonAdminsAndAdminsFromReadAccessToOtherUsers = $true
}
Update-MgDirectoryOnPremisesDirectorySynchronization -OnPremisesDirectorySynchronizationId "default" -BodyParameter $params