Home

Disabling users from creating teams

Kaushal Mehta (LYNC)
Microsoft

Disabling users from creating teams

Group policies have moved to MS Graph / AAD and AAD is the authoritative of group settings including group creation enforcement. Get-OwaMailboxPolicy is coming from exchange which are moving towards AAD policies.

Please set up the policies in AAD and decide to disable team creation and enable only for users in a specific security group.

 

The commands can be found here - https://msdn.microsoft.com/en-us/library/azure/mt733084(v=azure.98).aspx

 

Below is a sample script.

 

PS D:\scripts\powershell\Ops> $template = Get-MsolAllSettingTemplate | where-object {$_.displayname -eq "Group.Unified"}

PS D:\scripts\powershell\Ops> $setting = $template.CreateSettingsObject()
PS D:\scripts\powershell\Ops> $value = $Setting.GetSettingsValue()
PS D:\scripts\powershell\Ops> $value

TemplateId DisplayName Values
---------- ----------- ------
{AllowGuestsToBeGroupOwner, AllowGue...


PS D:\scripts\powershell\Ops> $value.Values

Name Value
---- -----
AllowGuestsToBeGroupOwner False
AllowGuestsToAccessGroups True
GuestUsageGuidelinesUrl
GroupCreationAllowedGroupId
AllowToAddGuests True
UsageGuidelinesUrl
ClassificationList
EnableGroupCreation True


PS D:\scripts\powershell\Ops> $template

ObjectId DisplayName Description Values
-------- ----------- ----------- ------
62375ab9-6b52-47ed-826b-58... Group.Unified ... {AllowGuestsToBeGroupOwner...


PS D:\scripts\powershell\Ops> $setting["EnableGroupCreation"] = "false"
PS D:\scripts\powershell\Ops> New-MsolSettings -SettingsObject $setting

ObjectId DisplayName TemplateId Values
-------- ----------- ---------- ------
b0a2c922-b094-4e22-ac9e-97... 62375ab9-6b52-47ed-826b-58... {AllowGuestsToBeGroupOwner...


PS D:\scripts\powershell\Ops> $value = $Setting.GetSettingsValue()
PS D:\scripts\powershell\Ops> $value.Values

Name Value
---- -----
AllowGuestsToBeGroupOwner False
AllowGuestsToAccessGroups True
GuestUsageGuidelinesUrl
GroupCreationAllowedGroupId
AllowToAddGuests True
UsageGuidelinesUrl
ClassificationList
EnableGroupCreation False


PS D:\scripts\powershell\Ops>

1 Reply

Re: Disabling users from creating teams

Hi Guys,

 

So when you've disabled the ability for users to create O365 groups and therefore Teams, the user tries to click "Add Team" and anyone not in the 'Group creation allowed group' get a message saying the IT department have disabled the ability, etc..

 

That works well, however when I add a user to an O365 group where a private team already exists the user doesn't see that team appear in Teams.

Is there a powershell command I can run centrally to make the team show in Teams automatically when a user is put into an exsiting team? Otherwise it looks like users need to be able to create groups just to add an existing group.

I suppose I'm thinking/hoping something along the lines of automapping with Exchange mailboxes - when you have permissions over the mailbox with the -automapping flag it appears in Outlook.

 

The reason we've disabled the ability for users to create groups is because they can only create groups using the default domain. We've got multiple domains in our tenancy so users creating them in the default domain is a real pain.

 

Any help would be greatly appreciated.

 

Matt

Related Conversations
Teams crashes on check for updates
Jonathon Halford  in  Microsoft Teams  on
36 Replies
How to change logo on the associated SP site?
Jakob Rohde  in  Microsoft Teams  on
12 Replies
How to connect a "Team" to a "Group"
Mike Dumka  in  Microsoft Teams  on
45 Replies
Adding external users to teams
Sean Whyment  in  Microsoft Teams  on
308 Replies
No Team Channel Notifications
Jake Baldwin  in  Microsoft Teams  on
66 Replies