1.14 Ensure that 'Guests can invite' is set to 'No'

Information

Restrict guest being able to invite other guests to collaborate with your organization.

Rationale:

Restricting invitations to administrators ensures that only authorized accounts have access to cloud resources. This helps to maintain 'Need to Know' permissions and prevents inadvertent access to data.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From Azure Console

Go to Azure Active Directory

Go to External Identities

Go to External collaboration settings

Set Guests can invite to No

Default Value:

By default, Guests can invite is set to Yes.

See Also

https://workbench.cisecurity.org/files/3459

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-1, 800-53|AC-2, 800-53|IA-4, 800-53|IA-5, CSCv7|14, CSCv7|16

Plugin: microsoft_azure

Control ID: 89dbaf40bcf62d49657f6eb05ed3c572603eb6c4b6f848256f3938beb039e778