Skip to main content

Default Authorization Settings - Guest invite restrictions

Manages controls who can invite guests to your directory to collaborate on resources secured by your Azure AD, such as SharePoint sites or Azure resources.

NameallowInvitesFrom
ControlDefault Authorization Settings
DescriptionManages authorization settings in Azure AD
SeverityMedium

How to fix

Details of configuration item

RecommendationCISA SCuBA 2.18: Only users with the Guest Inviter role SHOULD be able to invite guest users
Configurationpolicies/authorizationPolicy
SettingallowInvitesFrom
Recommended Value'adminsAndGuestInviters','none'
Default Valueeveryone
Graph API DocsauthorizationPolicy resource type - Microsoft Graph v1.0 - Microsoft Learn
Graph ExplorerOpen in Graph Explorer

MITRE ATT&CK

TacticTechniqueMitigation
TA0003 - Persistence - Persistence