SOLVED

Is Azure Active Directory (Azure AD) Premium still the only way to prevent group sprawl?

%3CLINGO-SUB%20id%3D%22lingo-sub-224655%22%20slang%3D%22en-US%22%3EIs%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224655%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewe%20don't%20use%20Exchange%20Online%20and%20the%20number%20of%20O365%20groups%20created%20through%20various%20O365%20applications%20are%20increasing.%20I've%20long%20been%20looking%20for%20a%20way%20to%20prevent%20group%20sprawl%20but%20the%20only%20%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2Fmanage-who-can-create-office-365-groups-4c46c8cb-17d0-44b5-9776-005fced8e618%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Edocumented%20way%3C%2FA%3E%20I%20can%20find%20requires%20an%26nbsp%3B%3CSPAN%3EAzure%20Active%20Directory%20(Azure%20AD)%20Premium%20subscription.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDoes%20anybody%20have%20any%20idea%20if%20there's%20something%20else%20that%20can%20be%20done%20to%20limit%20who%20can%20create%20O365%20groups%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks%20for%20your%20input.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-224655%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%20Groups%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-226226%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-226226%22%20slang%3D%22en-US%22%3E%3CP%3EI%20agree%20with%20everyone%20here%20that%20it's%20pretty%20'unfortunate'%20that%20Microsoft%20has%20made%20this%20decision.%20Admins%20can't%20even%20govern%20this%20100%25%20with%20managing%20licenses.%20For%20example%2C%20users%20can%20create%20an%20O365%20group%20through%20planner%20even%20without%20having%20a%20license%20assigned.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESoon%20we'll%20be%20looking%20into%20AAD%20Premium%20but%20it%20will%20be%20costly%2C%20no%20question%20so%20I%20really%20wish%20there%20was%20another%20option.%20Thanks%20for%20your%20input.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225145%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225145%22%20slang%3D%22en-US%22%3EI%20wouldn%E2%80%99t%20pretend%20this%20is%20a%20problem%20for%20me%20it%20-%20it%20isn%E2%80%99t%20-%20but%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1273%22%20target%3D%22_blank%22%3E%40Kelly%20Jones%3C%2FA%3E%20raises%20an%20important%20operational%20issue.%20There%20tends%20to%20be%20a%20marketing%20led%20assumption%20that%20customers%20will%20buy%20premium%20licensing%20across%20the%20tenant%20which%20simply%20can%E2%80%99t%20be%20true%20just%20based%20on%20the%20economics.%20With%20respect%20to%20the%20Microsoft%20participants%20in%20this%20thread%2C%20there%20needs%20to%20be%20a%20grown%20up%20discussion%20within%20Microsoft%20regarding%20AD%20functionality%20and%20features%20and%20how%20these%20match%20against%20product%20features%20within%20Office%20365.%20Handing%20off%20risk%20to%20customers%20is%20not%20acceptable.%20When%20Microsoft%20entered%20the%20%E2%80%98cloud%20first%E2%80%99%20era%20I%20truly%20believed%20that%20some%20of%20the%20on%20premises%20licensing%20nightmare%20was%20behind%20us.%20I%20might%20have%20been%20wrong...%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225133%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225133%22%20slang%3D%22en-US%22%3E%3CP%3ENot%20only%20am%20I%20concerned%20because%20properly%20governing%20groups%20is%20an%20expensive%20feature%2C%20but%20if%20I%20use%20any%20of%20these%20features%20without%20licensing%20everyone%2C%20then%20I'll%20most%20likely%20be%20breaking%20our%20license%20agreement%20almost%20immediately.%26nbsp%3B%20Why%3F%20Because%20our%20business%20users%20maintaining%20Groups%20will%20add%20people%20to%20the%20group%20without%20knowing%20the%20license%20requirements%20and%20Microsoft%20doesn't%20enforce%20it%20when%20they%20do.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20enabled%20Groups%20creation%20in%20late%20May%20and%20didn't%20announce%2C%20nor%20publicize%2C%20it%20in%20anyway%20within%20our%20company.%26nbsp%3B%20In%20June%2C%20our%20end%20users%20created%20180%20groups%2C%20and%20in%20July%20they%20created%20another%20209%20--%20all%20without%20these%20features%20enabled%20because%20only%20a%20fourth%20of%20our%20users%20have%20an%20Azure%20AD%20Premium%20license.%26nbsp%3B%20I%20imagine%20by%20the%20end%20of%20the%20year%2C%20every%20person%20in%20the%20company%20will%20be%20a%20member%20of%20at%20least%20one%20group.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELicensing%20everyone%20in%20my%20company%20for%20AD%20premium%20is%20a%20million%2B%20dollar%20decision%2C%20so%20we're%20forced%20to%20govern%20groups%20without%20Microsoft's%20help.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225096%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225096%22%20slang%3D%22en-US%22%3EIndeed.%20Microsoft%20positions%20Groups%20as%20a%20key%20%E2%80%98substrate%E2%80%99%20to%20Office%20365%20and%20then%20makes%20management%20costly%20%2F%20difficult.%20This%20feels%20like%20a%20struggle%20between%20common%20sense%20and%20monetisation%20and%20it%E2%80%99s%20clear%20which%20one%20is%20winning.%20I%E2%80%99m%20a%20huge%20advocate%20of%20Groups%20but%20this%20approach%20is%20unfair.%20The%20possibility%20of%20a%20mistake%20in%20licensing%20is%20very%20likely.%20Again%2C%20admins%20need%20to%20either%20blanket%20license%20or%20monitor%20uptake%20very%20carefully.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-225069%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-225069%22%20slang%3D%22en-US%22%3E%3CP%3EThat%20is%20%3CSPAN%3Eridiculous%20!%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20double%20checked%20the%20link%20as%20I'm%20pretty%20sure%2018%20months%20ago%20you%20never%20used%20to%20need%20AAD%20P!%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224932%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224932%22%20slang%3D%22en-US%22%3EI%20continue%20to%20find%20this%20an%20odd%20approach.%20It%20makes%20compliance%20difficult%20because%20of%20the%20many%20routes%20to%20generating%20an%20Office%20365%20Group.%20Admins%20beware%20just%20because%20there%20is%20no%20enforcement%20there%20is%20still%20a%20liability!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224808%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224808%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67%22%20target%3D%22_blank%22%3E%40Christophe%20Fiessinger%3C%2FA%3E.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20page's%20Feature's%20and%20Licensing%20section%20ends%20with%20this%20curious%20note%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CBLOCKQUOTE%3E%3CP%3E%3CSTRONG%3EIMPORTANT%3C%2FSTRONG%3E%3A%20For%20all%20the%20Groups%20features%2C%20if%20you%20have%20an%20Azure%20AD%20Premium%20subscription%2C%20users%20can%20join%20the%20group%20whether%20or%20not%20they%20have%20an%20AAD%20P1%20license%20assigned%20to%20them.%20Licensing%20isn't%20enforced.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3EPeriodically%20we%20will%20generate%20usage%20reports%20that%20tell%20you%20which%20users%20are%20missing%20a%20license%2C%20and%20need%20one%20assigned%20to%20them%20to%20be%20compliant%20with%20the%20licensing%20requirements.%20For%20example%2C%20let's%20say%20a%20user%20doesn't%20have%20a%20license%20and%20they%20are%20added%20to%20a%20group%20where%20the%20naming%20policy%20is%20enforced.%20The%20report%20will%20flag%20for%20you%20that%20they%20need%20a%20license.%3C%2FP%3E%3C%2FBLOCKQUOTE%3E%3CP%20class%3D%22%22%3EIt%20sure%20seems%20that%20Microsoft%20is%20highly%20dis-incentivizing%20organizations%20from%20managing%20their%20Groups.%20(Dynamic%20membership%3B%20Creation%20controls%3B%20Naming%20Policies%3B%20etc.%20all%20require%20a%20premium%20license)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224748%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224748%22%20slang%3D%22en-US%22%3E%3CP%3ELicensing%20requirements%20are%20documented%20here%3A%26nbsp%3B%3CFONT%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2Flearn-about-office-365-groups-b565caa1-5c40-40ef-9915-60fdb2d97fa2%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%23ID0EAACAAA%3DFeatures_%26amp%3B_Licensing%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2Flearn-about-office-365-groups-b565caa1-5c40-40ef-9915-60fdb2d97fa2%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%23ID0EAACAAA%3DFeatures_%26amp%3B_Licensing%3C%2FA%3E%3C%2FFONT%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224699%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224699%22%20slang%3D%22en-US%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67%22%20target%3D%22_blank%22%3E%40Christophe%20Fiessinger%3C%2FA%3E%20I%20don%E2%80%99t%20doubt%20Juan%E2%80%99s%20reply%20for%20a%20moment%20but%20can%20you%20double%20confirm%20this%20from%20Microsoft%20itself%3F%20This%20license%20requirement%20seems%20extraordinary.%20Is%20there%20a%20PowerShell%20command%20that%20could%20be%20scripted%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-224682%22%20slang%3D%22en-US%22%3ERe%3A%20Is%20Azure%20Active%20Directory%20(Azure%20AD)%20Premium%20still%20the%20only%20way%20to%20prevent%20group%20sprawl%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-224682%22%20slang%3D%22en-US%22%3ENo%2C%20as%20you%20well%20mention%20to%20absolutely%20prevent%20Groups%20creation%20in%20your%20tenant%2C%20you%20need%20an%20Azure%20AD%20Premium%20subscription%3C%2FLINGO-BODY%3E
Regular Contributor

Hi,

 

we don't use Exchange Online and the number of O365 groups created through various O365 applications are increasing. I've long been looking for a way to prevent group sprawl but the only documented way I can find requires an Azure Active Directory (Azure AD) Premium subscription.

 

Does anybody have any idea if there's something else that can be done to limit who can create O365 groups?

 

Thanks for your input.

10 Replies
best response confirmed by Florian Hein (Regular Contributor)
Solution
No, as you well mention to absolutely prevent Groups creation in your tenant, you need an Azure AD Premium subscription
@Christophe Fiessinger I don’t doubt Juan’s reply for a moment but can you double confirm this from Microsoft itself? This license requirement seems extraordinary. Is there a PowerShell command that could be scripted?

Thanks @Christophe Fiessinger.

 

That page's Feature's and Licensing section ends with this curious note:

 

IMPORTANT: For all the Groups features, if you have an Azure AD Premium subscription, users can join the group whether or not they have an AAD P1 license assigned to them. Licensing isn't enforced.

 

Periodically we will generate usage reports that tell you which users are missing a license, and need one assigned to them to be compliant with the licensing requirements. For example, let's say a user doesn't have a license and they are added to a group where the naming policy is enforced. The report will flag for you that they need a license.

It sure seems that Microsoft is highly dis-incentivizing organizations from managing their Groups. (Dynamic membership; Creation controls; Naming Policies; etc. all require a premium license)

I continue to find this an odd approach. It makes compliance difficult because of the many routes to generating an Office 365 Group. Admins beware just because there is no enforcement there is still a liability!

That is ridiculous !

 

I double checked the link as I'm pretty sure 18 months ago you never used to need AAD P!

 

Indeed. Microsoft positions Groups as a key ‘substrate’ to Office 365 and then makes management costly / difficult. This feels like a struggle between common sense and monetisation and it’s clear which one is winning. I’m a huge advocate of Groups but this approach is unfair. The possibility of a mistake in licensing is very likely. Again, admins need to either blanket license or monitor uptake very carefully.

Not only am I concerned because properly governing groups is an expensive feature, but if I use any of these features without licensing everyone, then I'll most likely be breaking our license agreement almost immediately.  Why? Because our business users maintaining Groups will add people to the group without knowing the license requirements and Microsoft doesn't enforce it when they do.

 

We enabled Groups creation in late May and didn't announce, nor publicize, it in anyway within our company.  In June, our end users created 180 groups, and in July they created another 209 -- all without these features enabled because only a fourth of our users have an Azure AD Premium license.  I imagine by the end of the year, every person in the company will be a member of at least one group.

 

Licensing everyone in my company for AD premium is a million+ dollar decision, so we're forced to govern groups without Microsoft's help.

I wouldn’t pretend this is a problem for me it - it isn’t - but @Deleted raises an important operational issue. There tends to be a marketing led assumption that customers will buy premium licensing across the tenant which simply can’t be true just based on the economics. With respect to the Microsoft participants in this thread, there needs to be a grown up discussion within Microsoft regarding AD functionality and features and how these match against product features within Office 365. Handing off risk to customers is not acceptable. When Microsoft entered the ‘cloud first’ era I truly believed that some of the on premises licensing nightmare was behind us. I might have been wrong...

I agree with everyone here that it's pretty 'unfortunate' that Microsoft has made this decision. Admins can't even govern this 100% with managing licenses. For example, users can create an O365 group through planner even without having a license assigned.

 

Soon we'll be looking into AAD Premium but it will be costly, no question so I really wish there was another option. Thanks for your input.