Securing Azure — Users Can Invite Guest Users to the Tenant

Joe Helle
Jun 26, 2023

Issue

Unprivileged users in Azure AD are permitted to invite guest users to the tenant.

Recommended Remediation

The following outlines the recommended steps that the systems and network administrators should take in order to secure the environment.

  • After logging into the Azure tenant as a privileged user (i.e., Global Administrator), access the Azure Active Directory option.
Azure Active Directory option
  • Select the User Settings blade under Manage.
User settings option
  • Click Manage external collaboration settings under External users.
Manage external collaboration settings
  • Under Guest invite settings, select “Only users assigned to specific admin roles can invite guest users.” Click save.
Saving guest user settings change

--

--

Joe Helle

Father | Husband | Army Veteran | Former Mayor | Chief Operating Officer | Red Team Lead | CISM | PNPT | OSCP | Retired Moonshiner | Twitter @joehelle