Question

Difficulty: MediumSelf-Service Password Reset and External Identities

You are configuring external collaboration settings in a Microsoft Entra ID tenant to control guest user permissions and invitation capabilities. Match each Microsoft Entra ID external collaboration setting to its corresponding behavior.

  • Guest user access is restricted to properties and memberships of their own directory objectsPrevents guest users from viewing any other user profiles or group memberships, limiting them to only their own profile details.
  • Guest users have limited access to properties and memberships of directory objectsAllows guest users to see listings of other users and groups but prevents them from viewing membership of groups they are not part of.
  • Only users assigned to specific admin roles can invite guest usersRestricts B2B guest invitations to administrators and users assigned the Guest Inviter role, blocking standard member users.
  • Anyone in the organization can invite guest users including guests and non-adminsPermits existing external guest users in the tenant to invite new external guest users without administrative intervention.

Answer

The setting restricting guest access to their own objects prevents guest users from viewing any other profiles. The limited access setting allows guests to see other users and groups but not group memberships they are not part of. Restricting invites to specific admin roles blocks standard members and limits invitations to administrators and Guest Inviters. The most inclusive setting allows guests to invite other guests.
The correct matches align each external collaboration setting with its documented functionality in Microsoft Entra ID. Restricting guest access to their own directory objects limits visibility to only their profile. Limited access (the default) allows basic search capability but blocks viewing memberships of non-joined groups. Limiting invitations to specific admin roles restricts B2B invites to admin roles and the Guest Inviter role, while the most permissive invitation setting allows guests themselves to invite others.

Step-by-Step Solution

1
Analyze guest user access restriction settings.
Identify that the setting restricting access to 'their own directory objects' isolates guest users completely, preventing them from viewing any other user profiles or group memberships.
This is the most restrictive option for guest permissions in Microsoft Entra ID.
2
Analyze default guest access settings.
Identify that 'limited access to properties and memberships' allows guest users to see basic properties of other users and groups but prevents viewing group memberships of groups they are not members of.
This represents the default tenant configuration for external collaboration.
3
Analyze guest invite permissions.
Determine that setting invitations to 'specific admin roles' prevents standard members and other guests from inviting B2B users, limiting this capability to administrators and the Guest Inviter role.
This enforces least privilege by disabling invitation rights for non-administrative members.
4
Evaluate tenant-wide collaboration settings.
Determine that enabling invitations for 'anyone in the organization including guests' allows existing B2B guests to invite new external users.
This is the most permissive setting for B2B collaboration.

Key Concept

Microsoft Entra ID External Collaboration Settings
Estimated Time:1m 30s
Rate this question