5.3.2 Ensure 'Access reviews' for Guest Users are configured

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Access reviews enable administrators to establish an efficient automated process for reviewing group memberships, access to enterprise applications, and role assignments. These reviews can be scheduled to recur regularly, with flexible options for delegating the task of reviewing membership to different members of the organization.

Ensure Access reviews for Guest Users are configured to be performed no less frequently than monthly.

Rationale:

Access to groups and applications for guests can change over time. If a guest user's access to a particular folder goes unnoticed, they may unintentionally gain access to sensitive data if a member adds new files or data to the folder or application. Access reviews can help reduce the risks associated with outdated assignments by requiring a member of the organization to conduct the reviews. Furthermore, these reviews can enable a fail-closed mechanism to remove access to the subject if the reviewer does not respond to the review.

Impact:

Access reviews that are ignored may cause guest users to lose access to resources temporarily.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Create an access review for Guest Users:

Navigate to Microsoft Entra admin center https://entra.microsoft.com/

Click to expand Identity Governance and select Access reviews

Click New access review.

Select what to review choose Teams + Groups.

Review Scope set to All Microsoft 365 groups with guest users, do not exclude groups.

Scope set to Guest users only then click Next: Reviews.

Select reviewers an appropriate user that is NOT the guest user themselves.

Duration (in days) at most 3.

Review recurrence is Monthly or more frequent.

End is set to Never, then click Next: Settings.

Check Auto apply results to resource.

Set If reviewers don't respond to Remove access.

Check the following: Justification required, E-mail notifications, Reminders.

Click Next: Review + Create and finally click Create.

Default Value:

By default access reviews are not configured.

See Also

https://workbench.cisecurity.org/benchmarks/12934