Skip to main content
Version: 2.0.1 (preview)

Default Authorization Settings - User can join the tenant by email validation

Controls whether users can join the tenant by email validation. To join, the user must have an email address in a domain which matches one of the verified domains in the tenant.

NameallowEmailVerifiedUsersToJoinOrganization
ControlDefault Authorization Settings
DescriptionManages authorization settings in Entra ID (Azure AD)
SeverityMedium

How to fixโ€‹

Details of configuration itemโ€‹

RecommendationSelf-service sign up for email-verified users - Microsoft Entra ID - Microsoft Learn
Configurationpolicies/authorizationPolicy
SettingallowEmailVerifiedUsersToJoinOrganization
Recommended Value'false'
Default Valuetrue
Graph API DocsauthorizationPolicy resource type - Microsoft Graph v1.0 - Microsoft Learn
Graph ExplorerOpen in Graph Explorer

MITRE ATT&CKโ€‹

TacticTechniqueMitigation
TA0001 - Initial Access - Initial Access