Guest identities often bypass the lifecycle controls applied to employees, making them a preferred path for external attack propagation.
Preface
Entra B2B collaboration lets partners access shared Teams, SharePoint, and other resources. Without governance, guest accounts become long-lived, under-audited entry points.
Problem
Compromised partner tenants can abuse authenticated guest access to host directories and channels. In unhardened tenants, guests may invite more guests or browse directory objects, enabling enumeration and spear-phishing.
Solution
Align with NIST SP 800-162 and CIS Microsoft 365 Foundations Benchmark:
- Restrict guest permissions: Block directory browse and group enumeration.
- Enforce Access Reviews: Quarterly re-attestation with automatic disablement on failure.
- Block self-service guest invitations: Limit invites to delegated admin roles.
PowerShell: Audit Guest Users
Connect-MgGraph -Scopes "User.Read.All"
Get-MgUser -Filter "userType eq 'Guest'" -All |
Select-Object DisplayName, UserPrincipalName, Id | Format-Table