Control: 1.12 Ensure That 'Guest users access restrictions' is set to 'Guest user access is restricted to properties and memberships of their own directory objects'
Description
Limit guest user permissions.
Limiting guest access ensures that guest accounts do not have permission for certain directory tasks, such as enumerating users, groups or other directory resources, and cannot be assigned to administrative roles in your directory. If guest access in not limited, they have the same access to directory data as regular users.
Remediation
From Console
- Log in to Azure Active Directory
- Go to
External Identities
in side bar - Go to
External collaboration settings
further from side bar - Set Guest users permissions to limited as per organization policy.
See more details here
Usage
Run the control in your terminal:
powerpipe control run azure_compliance.control.cis_v140_1_12
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run azure_compliance.control.cis_v140_1_12 --share
SQL
This control uses a named query:
ad_manual_control