M365TEAMS-002: Guest access settings

Platform
Entra ID / M365
Category
Microsoft Teams Security
Severity
High
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Guest access in Microsoft Teams allows external users to be added to teams and channels, granting them access to conversations, files, and shared resources. Overly permissive guest settings can allow external users to create channels, modify team settings, or access sensitive content that should be restricted to internal users. Guest capabilities must be configured to provide the minimum necessary access for external collaboration.

Recommended value

Guest access enabled with restricted capabilities; guests cannot create or update channels, participate in private chats, or share files without approval

Remediation

Review the Teams guest access settings and restrict guest capabilities to prevent guests from creating or deleting channels, adding or removing apps, and sharing screen in meetings. Disable guest access entirely if external collaboration is not required, or configure it with the most restrictive settings that still support business needs. Implement Azure AD access reviews for Teams guest accounts to regularly validate that guest access is still appropriate.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365TEAMS-002
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
AC-14
CIS M365 Benchmark
8.1.2