1.13 Ensure that 'Members can invite' is set to 'No'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Restrict invitations to administrators only.

Rationale:

Restricting invitations to administrators ensures that only authorized accounts have access to cloud resources. This helps to maintain 'Need to Know' permissions and prevents inadvertent access to data.

By default the setting Admins and users in the guest inviter role can invite is set to yes. This will allow you to use the inviter role to control who will be able to invite guests to the tenant.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

From Azure Console

Go to Azure Active Directory

Go to External Identities

Go to External collaboration settings

Set Members can invite to No

Default Value:

By default, Members can invite is set to Yes.

See Also

https://workbench.cisecurity.org/files/3459