The settingWhat we hold this to
CreativeTechs minimum
guestUserRoleId = 2af84b1e-32c8-42b7-82bc-daa82404023b (most restrictive). Restrict access to Entra admin portal = Yes. Non-admins cannot create security groups or M365 groups unless the client's workflow requires it and an exception is recorded.
Benchmark position
EIDSCA.AP07 — recommended value '2af84b1e-32c8-42b7-82bc-daa82404023b'. CISA SCuBA 2.18 — guests SHOULD have limited access to directory objects. Our minimum matches.
Where we differ, and why
Live finding: the CreativeTechs tenant is currently 10dae51f-b6af-4016-8d66-8c2a99b929b3, the more permissive role.
Where the switch is
Entra admin centre → Identity → External Identities → External collaboration settings → Guest user access. Portal restriction: Identity → Users → User settings.
How to verify
Graph: /policies/authorizationPolicy → guestUserRoleId eq '2af84b1e-32c8-42b7-82bc-daa82404023b'
- Why it matters
- By default a member can enumerate the full directory. After one account falls, that's the reconnaissance step handed over for free.
- How we check
- Maester EIDSCA.AP07, MT.1069, MT.1055.
- Fix — M365
- Entra → User settings → restrict access to the admin portal; External collaboration → guest access most restrictive. Restrict non-admin group and Teams creation where it doesn't fight the client's workflow.
- Fix — Google
- Admin → Directory settings → limit contact sharing scope.
- User notices
- Users can no longer browse the full org list from the portal. Address-book lookup in mail still works.
- Expected pushback
- Low. Group-creation restriction is the part that can annoy — decide per client.
