Information
Access reviews enable administrators to establish an efficient automated process for reviewing group memberships, access to enterprise applications, and role assignments. These reviews can be scheduled to recur regularly, with flexible options for delegating the task of reviewing membership to different members of the organization.
Ensure Access reviews for Guest Users are configured to be performed no less frequently than monthly
Access to groups and applications for guests can change over time. If a guest user's access to a particular folder goes unnoticed, they may unintentionally gain access to sensitive data if a member adds new files or data to the folder or application. Access reviews can help reduce the risks associated with outdated assignments by requiring a member of the organization to conduct the reviews. Furthermore, these reviews can enable a fail-closed mechanism to remove access to the subject if the reviewer does not respond to the review.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To remediate using the UI:
- Navigate to Microsoft Entra admin center
https://entra.microsoft.com/
- Click to expand Identity Governance and select Access reviews
- Click New access review
- Select what to review choose Teams + Groups
- Review Scope set to All Microsoft 365 groups with guest users do not exclude groups.
- Scope set to Guest users only then click Next: Reviews
- Select reviewers an appropriate user that is NOT the guest user themselves.
- Duration (in days) at most 3
- Review recurrence is Monthly or more frequent.
- End is set to Never then click Next: Settings
- Check Auto apply results to resource
- Set If reviewers don't respond to Remove access
- Check the following: Justification required E-mail notifications Reminders
- Click Next: Review + Create and finally click Create
Impact:
Access reviews that are ignored may cause guest users to lose access to resources temporarily.