Control: 1.14 Ensure That 'Restrict access to Azure AD administration portal' is set to 'Yes'
Description
Restrict guest being able to invite other guests to collaborate with your organization.
Restricting invitations to administrators ensures that only authorized accounts have access to cloud resources. This helps to maintain "Need to Know" permissions and prevents inadvertent access to data.
Remediation
From Console
- Log in to Azure Active Directory
- Go to
External Identities
- Go to
External collaboration settings
- Ensure that Guests can invite is set to No
Note: By default, Guests can invite is set to Yes
.
Usage
Run the control in your terminal:
powerpipe control run azure_compliance.control.cis_v140_1_14
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run azure_compliance.control.cis_v140_1_14 --share
SQL
This control uses a named query:
ad_manual_control