# Ensure that 'Users can create Azure AD Tenants' is set to 'No'

- Source: https://support.icompaas.com/support/solutions/articles/62000229787-ensure-that-users-can-create-azure-ad-tenants-is-set-to-no-
- Section: [Solutions](https://support.icompaas.com/support/solutions) › [General](https://support.icompaas.com/support/solutions/62000037933) › [Azure Compliance / Control / Check](https://support.icompaas.com/support/solutions/folders/62000168797)
- Last updated: 2026-05-29
- Publisher: iCompaas, Inc. (https://www.icompaas.com)

Description:

Microsoft Entra ID (formerly Azure Active Directory) allows users with specific permissions to create new tenants within the Azure ecosystem. When non-admin users are permitted to create tenants, it introduces the risk of unmonitored, unmanaged, and unauthorized tenant creation, resulting in security gaps, shadow IT, and governance challenges.

  

Rationale:

Restricting this capability ensures that only privileged administrators—such as Global Administrators or role-assigned personnel—can create new tenants. This control helps maintain a secure, centralized identity infrastructure and prevents the creation of external tenants that may fall outside security, compliance, and operational oversight.

  

Impact:

Enabling the restriction (setting Users can create Azure AD tenants = No) means:

-   Strengthens security by ensuring tenant creation is performed only by verified administrators.
    
-   Eliminates the risk of unmanaged or accidental tenant creation by regular users.
    
-   Helps maintain strict oversight of identity environments and cross-tenant access.
    

  

Default Value:

Default: Yes, Non-admin users are allowed to create Azure AD tenants

  

Pre-requisites:

1.  Sign in using an account with Global Administrator or Privileged Role Administrator permissions.
    

  

Test Plan:

1.  Sign in to the Azure Portal at [https://portal.azure.com](https://portal.azure.com/).
    
2.  Search for Microsoft Entra ID in the search bar.
    
3.  In the left-hand menu under the Manage section, select User settings.
    
4.  Check whether 'Restrict non-admin users from creating tenants' is set to Yes or No. If this is set to NO, follow the Remediation steps to fix it.
    

![](https://support.icompaas.com/assets/kb/61cf8d04413b142f.png)

  

Implementation Steps:

1.  Sign in to the Azure Portal at [https://portal.azure.com](https://portal.azure.com/).
    
2.  Search for Microsoft Entra ID in the search bar.
    
3.  In the left-hand menu under the Manage section, select User settings.
    
4.  Change the setting from No to Yes to Restrict non-admin users from creating tenants.
    

![](https://support.icompaas.com/assets/kb/58b754987c033077.png)

5.  Click Save to apply the new configuration.
    

  

Backout Plan:

1.  Sign in to the Azure Portal at [https://portal.azure.com](https://portal.azure.com/).
    
2.  Open Microsoft Entra ID.
    
3.  In the left-hand menu under the Manage section, select User settings.
    
4.  Change the setting from yes to no. Restrict non-admin users from creating tenants.
    

![](https://support.icompaas.com/assets/kb/4f592b280c7e16b6.png)

  

Reference:

-   [https://learn.microsoft.com/en-us/azure/active-directory-b2c/tenant-management-check-tenant-creation-permission](https://learn.microsoft.com/en-us/azure/active-directory-b2c/tenant-management-check-tenant-creation-permission)

## Related compliance guidance

- [SOC 2 compliance: a practical implementation guide for cloud-native SaaS teams](https://support.icompaas.com/compliance/soc-2-trust-services-criteria): Configuration checks like this one are the technical half of a SOC 2 / ISO 27001 programme — the guide shows where they fit, what else an auditor expects, and how to evidence them.
- [ISO/IEC 27001:2022 compliance: a practical implementation guide](https://support.icompaas.com/compliance/iso-27001-2022): ISO 27001 Annex A.8 (technological controls) is where cloud hardening evidence lands; the guide shows how to run the ISMS around it.
