how do i block users from creation azure security groups Just select the option "Users can create security groups in Azure portal, API or Powershell" and set it to no This will not affect M365 Groups because there is another option for it right below
Resource exemption in Microsoft Defender for Cloud In the past, the only way to remove recommendations from the Defender for Cloud dashboard and prevent them from influencing your Secure Score was to disable the whole related policy in the Microsoft Defender for Cloud Policy Initiative
User roles and permissions - Microsoft Defender for Cloud | Azure Docs Security Admin: A user in this role has the same access as the Security Reader and can also update security policies and dismiss alerts and recommendations Assign the least permissive role needed for users to complete their tasks
Review security recommendations - Microsoft Defender for Cloud Examples of low severity recommendations include the need to disable local authentication in favor of Microsoft Entra ID, health issues with your endpoint protection solution, best practices not being followed with network security groups, or misconfigured logging settings that could make it harder to detect and respond to security incidents
Ensure that Users can create security groups in Azure Portals is set . . . Restrict security group creation to administrators only When creating security groups is enabled, all users in the directory are allowed to create new security groups and add members to those groups Unless a business requires this day-to-day delegation, security group creation should be restricted to administrators only
Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud One of the main features of Microsoft Defender for Cloud is cloud security posture management (CSPM) CSPM provides detailed visibility into the security state of your assets and workloads and offers hardening guidance to help you improve your security posture
New Blog | Best Practices to Manage and Mitigate Security . . . Defender CSPM's Governance Rule allows you to categorize tasks based on their severity and potential impact on your organization's security posture Focus on high-severity findings first to mitigate the most significant threats promptly