EIDTNT-005: External Collaboration Settings
- Platform
- Entra ID / M365
- Category
- Entra ID Tenant Configuration
- Severity
- High
- Zero Trust pillar
- Governance (weight 2)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
External collaboration settings define the scope of domains from which guest users can be invited and which external organizations can collaborate with the tenant. Without domain restrictions, guests can be invited from any external organization, including competitors, sanctioned entities, or attacker-controlled tenants. Domain allowlists or blocklists should be configured to limit collaboration to approved partner organizations and prevent unauthorized external access.
Recommended value
External collaboration restricted to specific allowed domains with a deny list for known high-risk domains
Remediation
Navigate to Entra ID > External Identities > External collaboration settings and configure collaboration restrictions. Implement either an allowlist of approved partner domains or a blocklist of known high-risk and competitor domains based on your organization's collaboration model. Review and update the domain list quarterly to reflect changes in partner relationships and ensure that collaboration restrictions align with data classification and information sharing policies.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.AAD.8.3v1
- NIST SP 800-53
- AC-20
- CIS M365 Benchmark
- 1.3.1