Skip to main content

Default Authorization Settings - User can join the tenant by email validation

Controls whether users can join the tenant by email validation. To join, the user must have an email address in a domain which matches one of the verified domains in the tenant.

NameallowEmailVerifiedUsersToJoinOrganization
ControlDefault Authorization Settings
DescriptionManages authorization settings in Entra ID (Azure AD)
SeverityMedium

How to fix

Details of configuration item

RecommendationSelf-service sign up for email-verified users - Microsoft Entra ID - Microsoft Learn
Configurationpolicies/authorizationPolicy
SettingallowEmailVerifiedUsersToJoinOrganization
Recommended Value'false'
Default Valuetrue
Graph API DocsauthorizationPolicy resource type - Microsoft Graph v1.0 - Microsoft Learn
Graph ExplorerOpen in Graph Explorer

MITRE ATT&CK

TacticTechniqueMitigation
TA0001 - Initial Access - Initial Access