Medium

Guest users from consumer email providers

Identifies guest users invited from consumer domains (gmail, outlook.com, hotmail, yahoo, etc.).

Category
Identity
Default severity
Medium
Rule key
CHECK_GUESTS_FROM_CONSUMER_DOMAINS
Last updated

How to fix it

Prefer B2B invitations that target the partner's corporate tenant. Consumer accounts cannot be governed by the inviting tenant.

Required Microsoft Graph permissions

EntraAnalyzer needs the following read-only Graph permissions to evaluate this rule:

  • Directory.Read.All
  • User.Read.All

Further reading

Microsoft documentation →

Run this check on your tenant

EntraAnalyzer evaluates this rule automatically on every scan and emails you the results.

Get started — free first scan →