Skip to main content

Default Authorization Settings - User can join the tenant by email validation

Controls whether users can join the tenant by email validation. To join, the user must have an email address in a domain which matches one of the verified domains in the tenant.

NameallowEmailVerifiedUsersToJoinOrganization
ControlDefault Authorization Settings
DescriptionManages authorization settings in Azure AD
SeverityMedium

How to fix

Details of configuration item

RecommendationSelf-service sign up for email-verified users - Microsoft Entra ID - Microsoft Learn
Configurationpolicies/authorizationPolicy
SettingallowEmailVerifiedUsersToJoinOrganization
Recommended Value'false'
Default Valuetrue
Graph API DocsauthorizationPolicy resource type - Microsoft Graph v1.0 - Microsoft Learn
Graph ExplorerOpen in Graph Explorer

MITRE ATT&CK

TacticTechniqueMitigation
TA0001 - Initial Access - Initial Access