An external guest identity is controlled
The attacker gains control of a guest account — through a compromised partner or reused credentials — that was invited for collaboration but retains broad default directory visibility.
Operate as a legitimate external collaborator invited into the tenant.
- Restrict guest permissions to the most limited directory role
- Conditional Access and MFA applied to guest identities
- Regular review and expiry of external guest access
- Guest sign-ins from new locations or devices
- Guest accounts accessing resources beyond their invited scope
- Dormant guest accounts becoming active
- Review default guest permissions and what they can enumerate
- Test Conditional Access coverage for external identities
- Audit stale and over-scoped guest accounts
An external identity is now operating inside the tenant with more visibility than intended.