5.1.3.2 Ensure that 'Restrict user ability to access groups features in My Groups' is set to 'Yes'

Information

This setting restricts standard users from accessing the My Groups web interface in the My Account portal ( https://myaccount.microsoft.com/groups ). When set to Yes, this web interface access is removed for standard users.

The recommended state is Yes.

By default, any authenticated user can access the My Groups portal and enumerate group memberships, SharePoint site URLs, group email addresses, Teams URLs, and Yammer URLs across the tenant. This information enables reconnaissance, where a user could identify high-value or privileged groups, map resource URLs, and use that data to plan further attacks or lateral movement. Restricting the web interface limits passive enumeration by users who do not require group browsing as part of their duties, reducing the available attack surface without impacting core productivity.

Note: This setting applies only to the My Groups web interface. API-based enumeration remains possible for users with appropriate permissions or tooling, and this control should not be treated as a complete enumeration defense.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

- Navigate to Microsoft Entra admin center https://entra.microsoft.com/.
- Expand Entra ID > Groups and select General.
- Under Self Service Group Management, set Restrict user ability to access groups features in My Groups. Group and User Admin will have read-only access when the value of this setting is 'Yes' to Yes.
- Click Save.

Impact:

Setting this to Yes creates administrative overhead for users who need to look up group memberships and must now request that information from an administrator.

See Also

https://workbench.cisecurity.org/benchmarks/24620

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-6, 800-53|AC-6(1), 800-53|AC-6(7), 800-53|AU-9(4), CSCv7|14.6

Plugin: microsoft_azure

Control ID: f28b4caf80f453771f61d195440f91beed4d69c07f0734ededadb4260ad900ac