Description:
Guest user access permissions in Entra ID manage what external users can access within your organization's resources. This feature helps control the level of access granted to guests, ensuring that they have the necessary permissions without compromising security.
How it works:
How to be compliant
Under *Guest user access*, select either:
Guests can see membership of all non-hidden groups
Guests can't see membership of any groups
Under *Guest user invite settings*, select either:
Prevent everyone, including admins, from inviting external users
Allow members of Global Administrators, User Administrators, and Guest Inviter roles to invite external users
Why:
Azure Active Directory (Azure AD), part of Microsoft Entra, allows you to restrict what external guest users can see in their organization in Azure AD. Guest users are set to a limited permission level by default in Azure AD, while the default for member users is the full set of user permissions. When guest access is restricted, guests can view only their own user profile. Permission to view other users isn't allowed even if the guest is searching by User Principal Name or objectId. Restricted access also restricts guest users from seeing the membership of groups they're in. Restricting guest user access permissions is part of a least privileged access approach to security.
Configured: This setting is in place.
Not Configured: This setting is not in place.
Scoring: Contributes up to 2 points to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Works with Basic licensing
Remediation in Augmentt: Configure directly in Augmentt (Configure tab)
Compliance Frameworks:
CISA SCuBA — MS.AAD.8.1, MS.AAD.8.2
NIST CSF 2.0 — PR.AA-05
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.1.6.2
CIS Microsoft 365 Benchmark v7 (Level 1) — 5.1.6.2
HIPAA Security Rule — 164.308(a)(4)(ii)(B)
CMMC Level 1 — AC.L1-b.1.iii
CMMC Level 2 — AC.L2-3.1.5
Microsoft documentation:
