Default Authorization Settings - Guest user access
Represents role templateId for the role that should be granted to guest user.
| Name | guestUserRoleId |
| Control | Default Authorization Settings |
| Description | Manages authorization settings in Entra ID (Azure AD) |
| Severity |
How to fix
Details of configuration item
| Recommendation | CISA SCuBA 2.18: Guest users SHOULD have limited access to Entra ID (Azure AD) directory objects. |
| Configuration | policies/authorizationPolicy |
| Setting | guestUserRoleId |
| Recommended Value | '2af84b1e-32c8-42b7-82bc-daa82404023b' |
| Default Value | 10dae51f-b6af-4016-8d66-8c2a99b929b3 |
| Graph API Docs | authorizationPolicy resource type - Microsoft Graph v1.0 - Microsoft Learn |
| Graph Explorer | Open in Graph Explorer |
MITRE ATT&CK
| Tactic | Technique | Mitigation |
|---|---|---|
| TA0043 - Reconnaissance - Reconnaissance |