Description:
This setting controls who can invite guest users. When set to “Only users assigned to specific admin roles can invite guest users,” only approved administrators can send guest invitations. This prevents regular users from inviting external people without permission.
Rationale:
Limiting guest invitations to specific admin roles prevents unauthorized or accidental guest access. It ensures that only trusted administrators can add external users, which helps protect the organization from security risks.
Impact:
This setting increases security by stopping regular users from inviting guests. Only approved administrators can add external users, which reduces the risk of unwanted or unsafe guest accounts.
Default Value:
By default, Microsoft Entra ID allows all users to invite guest users unless this setting is changed. The restrictive option is not enabled automatically and must be set by an administrator.
Pre-requisites:
You must sign in with a Global Administrator or Privileged Role Administrator account.
Guest user accounts should be correctly set up in the directory.
Test Plan:
Sign in to the Azure portal at https://portal.azure.com
In the portal, search for Microsoft Entra ID.
Select External Identities under Manage.
Click External collaboration settings.
Find the Guest invite restrictions section.
Verify that the selected option is ‘Only users assigned to specific admin roles can invite guest users’.
If not, follow the implementation Plan.
Implementation Steps:
Sign in to the Azure portal at https://portal.azure.com.
In the portal, search for Microsoft Entra ID.
Select External Identities under Manage.
Click External collaboration settings.
Find the Guest invite restrictions setting.
Change the option to Only users assigned to specific admin roles can invite guest users.
Click Save to apply the change.
Backout Plan:
Go to the Azure portal login page: https://portal.azure.com
Navigate to Microsoft Entra ID.
Select External Identities under Manage.
Click External collaboration settings.
Find the Guest invite restrictions setting.
Change it back to a less restrictive option, such as allowing all users to invite guest users.
Click Save to apply the change.
Reference:


