Skip to main content
Version: 2.1.1-preview

EIDSCA.AP04 - Default Authorization Settings - Guest invite restrictions.

Overview​

Manages controls who can invite guests to your directory to collaborate on resources secured by your Entra ID (Azure AD), such as SharePoint sites or Azure resources.

CISA SCuBA 2.18: Only users with the Guest Inviter role SHOULD be able to invite guest users

Test script​

https://graph.microsoft.com/beta/policies/authorizationPolicy
.allowInvitesFrom -in @('adminsAndGuestInviters','none')

MITRE ATT&CK​

TacticTechniqueMitigation
TA0003 - Persistence - Persistence

Test Metadata​

FieldValue
Test IDEIDSCA.AP04
SeverityMedium
SuiteEntra ID SCA
CategoryGeneral
PowerShell testTest-MtEidscaAP04
TagsEIDSCA, EIDSCA.AP04

Source​

  • Pester test: tests/EIDSCA/Test-EIDSCA.Generated.Tests.ps1
  • PowerShell source: powershell/internal/eidsca/Test-MtEidscaAP04.ps1