fbpx

Unprivileged Users Can Invite Guest Users

TCM-KB-CLD-003
Last Updated: 6/26/2023

Microsoft Azure

Microsoft Azure is a comprehensive collection of cloud computing services offered by Microsoft. These services allow businesses and individuals to build, deploy, and manage applications and services through Microsoft-managed data centers.

Active Directory

Active Directory is a directory service developed by Microsoft for Windows domain networks, and it provides centralized management and authentication services for the network.

Contributor

Joe Helle

Joe Helle

Chief Hacking Officer

This Knowledge Base Article was submitted by: Joe Helle.

Recent Blogs

Issue

Unprivileged users in Azure AD are permitted to invite guest users to the tenant.

 

Recommended Remediation

The following outlines the recommended steps that the systems and network administrators should take in order to secure the environment.

  • After logging into the Azure tenant as a privileged user (i.e., Global Administrator), access the Azure Active Directory option.

Microsoft Azure Active Directory

  • Select the User Settings blade under Manage.

Azure User Settings

  • Click Manage external collaboration settings under External users

Manage External Collaboration Settings

  • Under Guest invite settings, select “Only users assigned to specific admin roles can invite guest users.” Click save.

Azure AD Invite Guests Exploit

example title page of a pentesting report at TCM Security

See What We Can Do For You

Download a sample penetration test report to see the results we can deliver for your organization.

See How We Can Secure Your Assets

Let’s talk about how TCM Security can solve your cybersecurity needs. Give us a call, send us an e-mail, or fill out the contact form below to get started.

 

tel: (877) 771-8911 | email: [email protected]