A guest account is not a limited account. It’s a door, and by default, every guest gets a copy of the key.
Here’s the dangerous assumption: you invite an external contractor into your Entra ID tenant, and you figure they’re sandboxed. Limited permissions, limited visibility, limited risk. But what most admins don’t realize is that Microsoft’s default external collaboration setting is configured to “Anyone in the organization can invite guest users including guests and non-admins.” Read that again. Guests can invite guests. You didn’t just give one contractor a badge to your building, you gave them a stack of blank badges and a stamp.
One guest invite becomes a chain
Entra ID’s default lets any guest invite another, with no domain check, until the chain reaches outside your identity provider.
© 2026 Reclaim Security · reclaim.security
Why This Persists
The setting exists because Microsoft optimized for collaboration at scale. B2B partnerships, vendor onboarding, cross-org projects, the product team wanted minimal friction. And it works. It works so well that most security teams never revisit the default, because guest invitations don’t show up on the same dashboards as role assignments or conditional access policies. It’s a control that lives in a corner of the Entra admin portal most people visit once during initial setup and never again.
Real-World Risks
Uncontrolled Tenant Sprawl
When any guest can invite any external identity, including personal @outlook.com and @gmail.com accounts, you lose control of your identity perimeter. There’s no domain restriction by default. An attacker who compromises a single guest account can invite their own personal Microsoft account, establishing a persistent foothold that bypasses your IdP entirely.
Privilege Escalation via Dynamic Groups
This is where it gets ugly. Many organizations use dynamic group membership rules based on user attributes like email domain or display name. A guest who can invite another guest can craft that invitation to match dynamic group conditions, and the new account gets auto-enrolled into groups with elevated access. Researchers have demonstrated this leading to administrative access to virtual machines and automation accounts without ever touching a privileged role assignment.
Social Engineering Amplifier
Once inside your tenant, a malicious guest can send Microsoft Teams messages that appear to come from within your organization. They can enumerate users, discover group memberships, and map out your directory, all with default guest permissions. This is exactly the playbook nation-state actors have used: compromise a small tenant, pivot into a target tenant via guest access, and launch credential theft campaigns from a position of apparent trust.
Subscription-Based Privilege Escalation
In May 2025, BeyondTrust researchers disclosed that guest users with billing roles in their home tenant can create and transfer Azure subscriptions into your tenant while retaining full Owner rights. From there, they can enumerate Global Admins, disable Azure security policies on their subscription, create persistent managed identities, and register devices that bypass conditional access. This isn’t a bug, Microsoft confirmed it’s by design.
Case Studies
Midnight Blizzard (NOBELIUM), Microsoft Teams Social Engineering Campaign (2023)
Russia’s SVR-linked threat group compromised small-business Microsoft 365 tenants and used them to create guest-like external identities that sent phishing messages via Teams to approximately 40 global organizations. The attackers exploited the trust inherent in cross-tenant collaboration to bypass MFA by convincing targets to enter authenticator codes. Targets included government agencies, NGOs, and technology companies.
Impact: credential theft, email exfiltration, and attempted device enrollment across multiple sectors.
Reference: Microsoft Security Blog, August 2023
BeyondTrust “Restless Guests” Research Disclosure (2025)
BeyondTrust researchers demonstrated that Entra ID guest accounts could exploit billing permissions to create subscriptions, enumerate privileged administrators, silence security alerts, and establish persistent backdoors via managed identities and federated credentials, all from an unprivileged guest account. Researchers confirmed this technique is being actively exploited in the wild. Microsoft acknowledged the behavior as “functioning as designed.”
Reference: BeyondTrust Blog, May 2025
Consequences
- Regulatory exposure. Uncontrolled guest access means uncontrolled data access. If a guest can enumerate your directory or reach SharePoint resources, you may be out of compliance with SOC 2, GDPR, or industry-specific frameworks before you even know there’s a problem.
- Persistent attacker footholds. A guest who invites another guest creates an identity chain that’s difficult to audit and easy to overlook. Remove one account, and the other persists, potentially with its own invited guests downstream.
- Lateral movement at scale. Dynamic group exploitation, subscription creation, and device registration all become available attack surfaces once an adversary establishes a guest presence.
- Reputational damage. When your tenant is used as a launchpad for social engineering attacks against your partners, as in the Midnight Blizzard campaign, your organization becomes the vector, not just the victim.
- IP and data exfiltration. Guests with even limited access can often reach Power Apps connections, shared SharePoint sites, and Teams channels. That “limited” access may include your most sensitive collaboration spaces.
Default vs restricted guest invites
The same tenant, configured two ways. One lets any guest bring in more guests. One does not.
Default
Restricted
© 2026 Reclaim Security · reclaim.security
Best Practices for Prevention
- Restrict guest invite permissions immediately. In Entra ID, External Identities, External collaboration settings, change “Guest invite restrictions” to “Only users assigned to specific admin roles can invite guest users.” This single change eliminates the entire self-propagating guest chain.
- Enforce domain allowlists for collaboration. Under Collaboration Restrictions, switch to “Allow invitations only to the specified domains” and maintain a curated list of approved partner domains. Block personal email providers by default.
- Audit dynamic group membership rules. Review every dynamic group for rules based on user-controllable attributes (email, display name, department). If a guest could craft an identity to match the rule, the rule is a privilege escalation vector. Use attributes that only admins can set.
- Enable subscription policies. Configure Azure subscription policies to prevent guest users from creating or transferring subscriptions into your tenant. This is not enabled by default and requires explicit action.
- Implement continuous guest lifecycle monitoring. Set up automated reviews of guest accounts, who invited them, when they last signed in, what resources they can access. Stale guest accounts are dormant attack surface. Use Entra ID access reviews or a third-party tool to enforce time-bound guest access with automatic expiration.
A guest who can invite guests isn’t a collaboration feature, it’s an unmanaged identity pipeline. Reclaim Security helps you find these open doors and close them before someone else walks through.
Chat with this article in your AI assistant
A source-grounded recap for your AI assistant. Ask how this misconfiguration applies to your stack, anchored to what this article actually says.
Works with ChatGPT, Claude, Gemini, or any LLM. It stays grounded to this article, with its sources.
© 2026 Reclaim Security · reclaim.security
You find exposures fast.Can you fix them just as fast?
Nine questions, about two minutes. You get a maturity tier, your fix-window gap, and a short plan, free and on screen. No email needed to see it.



