Control: 1.13 Ensure that 'Members can invite' is set to 'No'
Restrict invitations to administrators only.
Restricting invitations to administrators ensures that only authorized accounts have access to cloud resources. This helps to maintain
Need to Know permissions and prevents inadvertent access to data.
By default the setting Admins and users in the guest inviter role can invite is set to yes. This will allow you to use the inviter role to control who will be able to invite guests to the tenant.
- Log in to Azure Active Directory
- Go to
- Go to
External collaboration settings
Guest invite restrictionsto
Only users assigned to specific admin roles can invite guest users
Note: By default, Members can invite is set to
steampipe check azure_compliance.control.cis_v130_1_13
This control uses a named query:ad_manual_control