CTD-000015

Microsoft Entra tenant with unsecure Guest user access permissions

Medium
Entra ID
Discovery
v30

Signature Identity

CTD-000015
Threat ID
30
Version
IOE
Indicator Type

Threat Description

A Microsoft Entra ID is configured with unsecure Guest user access permissions. With the current setting value, the threat actor might enumerate groups and users using a tool such as AADInternals. The API calls to Microsoft Entra ID are not logged and therefore the actions of a threat actor can not be easily detected.

MITRE ATT&CK: Attack Tactics

Discovery

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

Modify Guest user access restrictions:

  1. Sign in to the Microsoft Entra admin center as a Global Administrator.
  2. Open External Identities > External collaboration settings.
  3. Modify the value of Guest user access restrictions in the Guest user access to a more restrictive value Guest user access is restricted to properties and memberships of their own directory objects.

Learn more about Guest user access permissions in Microsoft Entra ID.

Learn more about Microsoft 365 guest access settings.

Frequently Asked Questions

What does Microsoft Entra tenant with unsecure Guest user access permissions mean?

Microsoft Entra tenant with unsecure Guest user access permissions means that Guest users can access groups and users without restrictions, enabling unauthorized enumeration of identities.

This setting allows attackers to use tools like AADInternals to enumerate groups and users in the tenant, which can be used for reconnaissance. Although it doesn't grant direct access or elevation of privileges, it still increases the attack surface.

Attackers can use tools like AADInternals to enumerate groups and users in the tenant, which can be used for reconnaissance and planning future malicious operations. This information can also be used to target specific identities or groups.

Cayosoft Guardian continuously monitors the configuration of Guest user access restrictions in the Microsoft Entra ID tenant, flagging any settings that allow unrestricted access to groups and users.

Cayosoft Guardian alerts administrators to modify the Guest user access restrictions in the External Identities > External collaboration settings, limiting the attack surface and reducing the opportunities for unauthorized enumeration.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Guest management Infrastructure Tenant-wide
Attack Tactics
Discovery
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical