M365SPO-004: Site creation restrictions
- Platform
- Entra ID / M365
- Category
- SharePoint & OneDrive Security
- Severity
- Medium
- Zero Trust pillar
- Data (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Unrestricted site creation in SharePoint Online allows any user to create new sites, teams, and associated resources without governance oversight. Uncontrolled site proliferation leads to inconsistent security settings, ungoverned data repositories, and difficulty enforcing classification and retention policies. Restricting site creation to authorized personnel or requiring an approval workflow ensures proper governance from the point of creation.
Recommended value
Site creation restricted to authorized administrators or governed through an approval process; Microsoft 365 group creation restricted
Remediation
Restrict self-service site creation in the SharePoint admin center by disabling the ability for users to create new sites directly. Implement a site provisioning request process that routes creation requests through an approval workflow ensuring appropriate classification, sharing settings, and ownership are established. If self-service creation must be allowed, configure default sensitivity labels and sharing policies that are automatically applied to newly created sites.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | WARN |
| no-data | Not Assessed |
Framework mappings
- NIST SP 800-53
- CM-6
- CIS M365 Benchmark
- 7.2.4