Remediation
From Azure Portal
- In the Azure portal, open the portal menu.
- Select
Microsoft Entra ID. - Under
Manage, selectUsers. - Under
Manage, selectUser settings. - Set
Restrict non-admin users from creating tenantstoYes. - Click
Save.
From PowerShell
Import-Module Microsoft.Graph.Identity.SignIns
Connect-MgGraph -Scopes 'Policy.ReadWrite.Authorization'
Select-MgProfile -Name beta
$params = @{ DefaultUserRolePermissions = @{ AllowedToCreateTenants = $false } }
Update-MgPolicyAuthorizationPolicy -AuthorizationPolicyId -BodyParameter $params