Group sprawl has a supply side: who is allowed to create groups in the first place. Entra ID's defaults are permissive, particularly for Microsoft 365 groups, and every downstream cleanup program is partly paying for a creation policy nobody chose deliberately.

What the settings control#

Creation policy is set per group type:

  • Microsoft 365 groups: broadly user-creatable by default, through Teams, Outlook, and other workloads; restrictable to a designated creator group.
  • Security groups: creation is an administrative action by default, but automation, sync, and delegated tooling widen the real set of creators.
  • Either way, the effective policy is what the settings plus the automations actually allow, which few tenants have ever enumerated.

Choosing a deliberate policy#

Free creation optimizes collaboration and guarantees sprawl; locked-down creation optimizes governance and generates shadow workarounds. The sustainable middle is deliberate: a defined creator population, expiration for the collaboration layer, and structural review for whatever gets created.

VisualizerEngine

How VisualizerEngine helps

Whatever the policy allows, the structure it produces is visible: creation patterns show up in the change history, sprawl shows up in orphan and overlap detection, and the policy engine scores the structural rules that creation settings alone cannot enforce.