Description:

Guest user access permissions in Entra ID manage what external users can access within your organization's resources. This feature helps control the level of access granted to guests, ensuring that they have the necessary permissions without compromising security.

How it works:

How to be compliant

Under *Guest user access*, select either:

  • Guests can see membership of all non-hidden groups

  • Guests can't see membership of any groups

Under *Guest user invite settings*, select either:

  • Prevent everyone, including admins, from inviting external users

  • Allow members of Global Administrators, User Administrators, and Guest Inviter roles to invite external users

Why:

Azure Active Directory (Azure AD), part of Microsoft Entra, allows you to restrict what external guest users can see in their organization in Azure AD. Guest users are set to a limited permission level by default in Azure AD, while the default for member users is the full set of user permissions. When guest access is restricted, guests can view only their own user profile. Permission to view other users isn't allowed even if the guest is searching by User Principal Name or objectId. Restricted access also restricts guest users from seeing the membership of groups they're in. Restricting guest user access permissions is part of a least privileged access approach to security.

Configured: This setting is in place.

Not Configured: This setting is not in place.

Scoring: Contributes up to 2 points to the Posture Recommendations score.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • CISA SCuBA — MS.AAD.8.1, MS.AAD.8.2

  • NIST CSF 2.0 — PR.AA-05

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 5.1.6.2

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 5.1.6.2

  • HIPAA Security Rule — 164.308(a)(4)(ii)(B)

  • CMMC Level 1 — AC.L1-b.1.iii

  • CMMC Level 2 — AC.L2-3.1.5

Microsoft documentation:


_KB status: already published as "Entra ID Guest User Access Permissions" — update the existing step in place._

_Source: Augmentt native check. Check ID entraIdGuestUserAccessPermissions (module 30)._

Sourced for this page:

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Identity · M365 Basic · CIS M365 v6 L1 · CIS M365 v7 L1 · NIST CSF 2.0 · HIPAA · CISA SCuBA · CMMC Level 1 · CMMC Level 2