Description:
Verifies that an active dynamic Microsoft Entra security group exists whose membership rule targets guest users, so guests can be addressed consistently by Conditional Access policies, access reviews and licence assignments.
Why:
CIS M365 Foundations Benchmark v6 §5.1.3.1 (L1) requires a dynamic Microsoft Entra security group whose membership rule targets guest users. This lets Conditional Access policies, access reviews, license assignments, and other controls that reference the group apply automatically to current and future guests.
Configured: An active dynamic group for guest users exists.
Not Configured: No active dynamic group for guest users was found.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: Identity
Microsoft Licensing: Requires Premium (P1) licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab); Guided remediation steps (Instructions tab)
Compliance Frameworks:
CIS Microsoft 365 Benchmark v6 (Level 1) — 5.1.3.1
CIS Controls v8 — 3.3
Microsoft documentation:
_KB status: new — this check is not yet documented in the knowledge base._
_Source: Augmentt native check, aligned to the CIS Microsoft 365 Foundations Benchmark. Check ID AUG.CIS.M365.5.1.3.1 (module 1088)._
Sourced for this page:
Category — Microsoft service targeted by the check
Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Entra ID P1 · CIS M365 v6 L1 · CIS v8
