Low

Public Microsoft 365 groups

Detects M365 groups with public visibility

Category
Guest Users
Default severity
Low
Rule key
CHECK_PUBLIC_M365_GROUPS
Last updated

How to fix it

Change public groups to private unless open access is intentional.

Required Microsoft Graph permissions

EntraAnalyzer needs the following read-only Graph permissions to evaluate this rule:

  • Directory.Read.All

Further reading

Search Microsoft Learn for related guidance →

Run this check on your tenant

EntraAnalyzer evaluates this rule automatically on every scan and emails you the results.

Get started — free first scan →