Tenant setup 04 β User, device, and group settings
π Complete tenant-setup cookbook in one PDF This article is part of the series. Full series + screenshots in one document: download PDF . (PDF is currently in Czech.) As J. M.
This article is part of the series. Full series + screenshots in one document: download PDF. (PDF is currently in Czech.)
As J. M. Juran put it: 80% of results come from 20% of causes. We'll look at part of that 20% today. These small, simple settings will make your life easier and protect you from at least some attacks. They take 5β15 minutes to configure and are absolutely worth it.
User settings (Users β User settings):
- Users can register applications β keep off unless your users build apps in Azure.
- Restrict non-admin users from creating tenants β keep on. I've yet to find a reason to allow this.
- Users can create security groups β keep off. Security groups are an admin concern.
- Restrict access to Microsoft Entra admin center β on. Critical: keeps an attacker with a normal account out of admin portals.
- Show keep user signed in β off. The "stay signed in" cookie persists to disk; bad if the device is later compromised.
Group settings: turn off "Users can create Microsoft 365 groups" β without this users can't even create Teams. The only place teams can then be created is the Teams admin center. The expiration tab matters: set the contact email to someone permanent (yourself, ideally) so groups without an owner can still be renewed.
Device settings: leave most defaults if you'll follow this guide further. The exception is Local administrator settings β turn everything off. Admin access to PCs goes through workstation admin accounts (we'll get to LAPS later).