CTD-000014

Microsoft Entra tenant configured to allow guests to invite other guests

Medium
Entra ID
Initial Access
v31

Signature Identity

CTD-000014
Threat ID
31
Version
IOE
Indicator Type

Threat Description

A guest invitation configuration where guest users can invite other guest users poses a threat to the tenant’s identities. Even with limited access, guest users can collect some data about the environment, for example, they can verify other user’s existence in the environment. A threat actor might use a guest account to collect information for future attacks.

MITRE ATT&CK: Attack Tactics

Initial Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

Modify Guest invite settings:

  1. Sign in to the Microsoft Entra admin center as a Global Administrator.
  2. Open External Identities > External collaboration settings.
  3. Modify the value of Guest invite restrictions in the Guest invite settings from Anyone in the organization can invite guest users including guests and non-admins to a more restrictive value.

Learn more about Microsoft 365 guest sharing settings.

Frequently Asked Questions

What does Microsoft Entra tenant configured to allow guests to invite other guests mean?

Microsoft Entra tenant configured to allow guests to invite other guests means that the tenant's guest invitation configuration allows guest users to invite other guest users, enabling them to collect data about the environment, such as verifying user existence and group membership.

This setting is rated medium severity because it allows attackers to gather information about users, groups, and the environment, which can support later attacker activity. The potential for reconnaissance and data collection poses a meaningful threat.

An attacker can sign in using a guest account and perform reconnaissance against the tenant by gathering information about users, groups, and the environment. This discovery activity may go unnoticed because guest access can appear as ordinary low-privilege traffic.

Cayosoft Guardian detects this setting by continuously monitoring the guest invitation configuration across the tenant and flagging it as a security issue when enabled.

Cayosoft Guardian helps reduce the risk by alerting administrators to modify the guest invitation settings in the Microsoft Entra admin center, limiting the ability for guest users to invite other guest users and reducing potential reconnaissance opportunities available to attackers.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID
Themes
Guest management Tenant-wide
Attack Tactics
Initial Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical