Ensure that guest user access is restricted to properties and memberships of their own directory objects in Microsoft Entra ID in order to enhance access security and comply with organization regulations and policies.
Microsoft provides the option to limit what external guest users can access within their organization in Microsoft Entra ID. By default, guest users are assigned a restricted permission level, whereas member users enjoy full user permissions. By setting the guest user access restriction level to Guest user access is restricted to properties and memberships of their own directory objects (most restrictive), guests have no access to other users and group memberships including groups they are a member of. By limiting guest access, you should ensure that these accounts do not have permissions for specific directory tasks, such as listing users, groups, or other directory resources, and they should also be prohibited from being assigned administrative roles within your directory.
Audit
To determine whether external guest users can only access their own directory data, perform the following operations:
Remediation / Resolution
To ensure that external guest users can only access their own directory data, perform the following operations: