How to Restrict Microsoft Teams and Microsoft 365 Groups Creation Tenant-wide

Published On: November 20, 2025
fixr.cloud

⏲ Reading Time: 3 min

The best method to restrict Microsoft Teams and Microsoft 365 Group creation tenant-wide is:

✔️ Create a Security Group
✔️ Allow ONLY that group to create M365 Groups
✔️ Apply restriction using Graph PowerShell

Below is the full step-by-step guide, updated for 2025, using Microsoft Graph PowerShell (modern and recommended).



Goal

Restrict ALL users from creating:

  • Microsoft 365 Groups
  • Microsoft Teams (because Teams requires an M365 group)

Only members of a specific Security Group will have permission.


🔧 STEP 1 — Create a Security Group

(You can also use an existing one)

Portal

  1. Go to Azure Portal → Microsoft Entra ID (Aka Azure Active Directory)
  2. Groups > New Group
  3. Group type: Security
  4. Name: “Allowed M365 Group Creators” (recommended)
  5. Membership type: Assigned
  6. Add the users/admins who should be able to create Teams/M365 Groups.

IMPORTANT:
If you use dynamic or Microsoft 365 type groups, it will NOT work. Must be Security Group → Assigned.


🔧 STEP 2 — Install & Connect to Microsoft Graph

Open PowerShell 7.x and run:

-- Install required modules --

#Install the Microsoft Graph cmdlets.
Install-Module Microsoft.Graph -Scope AllUsers

#Install the Microsoft Graph beta cmdlets.
Install-Module Microsoft.Graph.Beta -Scope AllUsers

# Connect with required scopes
Connect-MgGraph -Scopes "Directory.ReadWrite.All", "Group.ReadWrite.All"

Sign in using a Global Admin or Privileged Role Admin.



🔧 STEP 3 — Get the Security Group Object ID

Replace the group name with the one you created:

$group = Get-MgGroup -Filter "DisplayName eq 'Allowed M365 Group Creators'"
$group.Id

Copy the Object ID output.



🔧 STEP 4 — Create the Directory Setting Template

M365 uses a hidden “Group.Unified” setting.
We need to create a tenant setting using that template.

Run:

#Get the directory settings template
$template = Get-MgBetaDirectorySetting | where-object {$_.displayname -eq 'Group.unified'}
$template.Values


#Creating a new directory setting object 
$SettingTemplate = Get-MgBetaDirectorySettingTemplate | where {$_.DisplayName -eq 'Group.Unified'}

New-MgBetaDirectorySetting -TemplateId $SettingTemplate.Id


🔧 STEP 5 — Configure Group Creation Restriction

We will set:

  • EnableGroupCreation = false
  • GroupCreationAllowedGroupId = <your security group id>

Replace <your_group_id> with the ID from Step 3.

$group = Get-MgGroup -Filter "DisplayName eq 'Allowed M365 Group Creators'"

$params = @{
	Values = @(
		@{
			Name = "EnableGroupCreation"
			Value = "false"
		}
		@{
			Name = "GroupCreationAllowedGroupId"
			Value = "<your_group_id>"
		}
		)
}





$Setting = Get-MgBetaDirectorySetting | where-object {$_.displayname -eq 'Group.unified'}
Update-MgBetaDirectorySetting -DirectorySettingId $Setting.id -BodyParameter $params



🔄 STEP 6 — To Re-Enable Group/Teams Creation Later

You can delete the setting:

Get-MgBetaDirectorySetting | Where-Object {$_.DisplayName -eq "Group.Unified"} | `
    Remove-MgBetaDirectorySetting

Or set EnableGroupCreation = true.




🚨 Important Notes

✔️ Teams creation is now restricted

Teams creation fails for users NOT in the security group.

✔️ Outlook, Planner, Viva Engage group creation is restricted too

Those apps cannot create groups anymore.

✔️ Existing groups continue working

Only new creation is blocked.

Kiran Maji

Hey, I’m Kiran Maji — a Microsoft Certified IT Professional with over 8 years of experience, including 6 years of hands-on work with Microsoft 365, cloud infrastructure, and system administration.I’m passionate about technology, troubleshooting, and simplifying complex IT concepts through real-world examples. Beyond work, I love blogging, content creation, and exploring trading and automation — all things that keep me curious and creative.This blog is my space to share what I learn, document practical fixes, and help others grow in their IT journey.

Leave a Comment