M365PP-001: Environment creation restrictions
- Platform
- Entra ID / M365
- Category
- Power Platform Security
- Severity
- High
- Zero Trust pillar
- Applications & Workloads (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
By default, all users in a Microsoft 365 tenant can create new Power Platform environments, which spin up associated Dataverse databases and can host Power Apps and Power Automate flows with access to organizational data. Unrestricted environment creation leads to shadow IT sprawl where ungoverned applications are built with data connections that bypass IT security controls. Restricting environment creation to administrators ensures proper governance and prevents uncontrolled data exposure.
Recommended value
Environment creation restricted to Global Admins and Power Platform Admins only; all production environments managed through a formal provisioning process
Remediation
Navigate to the Power Platform admin center and restrict environment creation to only Global Administrators and Power Platform Administrators by configuring the tenant-level setting. Implement a formal request and provisioning process for new environments that includes security review, data classification, and DLP policy assignment before environment creation. Audit existing environments to identify and decommission any ungoverned environments that were created before restrictions were put in place.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.POWERPLATFORM.1.1v1, MS.POWERPLATFORM.1.2v1
- NIST SP 800-53
- CM-7
- CIS M365 Benchmark
- 9.1