Skip to main content

Default Authorization Settings - Sign-up for email based subscription

Indicates whether users can sign up for email based subscriptions.

NameallowedToSignUpEmailBasedSubscriptions
ControlDefault Authorization Settings
DescriptionManages authorization settings in Azure AD
SeverityMedium

How to fix

Details of configuration item

Recommendation
Configurationpolicies/authorizationPolicy
SettingallowedToSignUpEmailBasedSubscriptions
Recommended Value'false'
Default Valuetrue
Graph API DocsauthorizationPolicy resource type - Microsoft Graph v1.0 - Microsoft Learn
Graph ExplorerOpen in Graph Explorer

MITRE ATT&CK

TacticTechniqueMitigation
TA0001 - Initial Access - Initial Access