Ensure that "Members can invite" policy is set to "No" within your Microsoft Entra ID user settings so that non-administrator members cannot invite guest users to collaborate on resources secured by your Microsoft Entra ID, such as SharePoint sites or certain Azure cloud resources.
This rule resolution is part of the Conformity Security & Compliance tool for Azure.
Restricting the ability to send invitations to Microsoft Entra ID administrators only prevents inadvertent access to your Microsoft Entra ID data and ensures that only authorized accounts have access to your Azure cloud resources.
Audit
To determine if non-admin members can invite guests for collaboration, perform the following actions:
Note: Querying "Members can invite" Microsoft Entra ID setting configuration using Microsoft Graph API or Azure CLI is not currently supported.Remediation / Resolution
To make sure that only Microsoft Entra ID members with administrator roles can invite guest users to your directory by setting "Members can invite" option to "No", perform the following actions:
Note: Configuring Microsoft Entra ID external collaboration settings to restrict invitations to Microsoft Entra ID administrators only using Microsoft Graph API or Azure CLI is not currently supported.References
- Azure Official Documentation
- Microsoft Entra built-in roles
- Configure external collaboration settings
- CIS Microsoft Azure Foundations