Invite External User
Invite External User
Event
Creates a B2B invitation and can create a guest user object; the invitation API also supports resetting redemption for an existing guest. Sending an invitation, redeeming it, signing in, and receiving application/resource assignments are separate steps. Invitation success does not grant unrestricted tenant-resource access.
Security Context
Unauthorized guest onboarding can prepare persistent cloud access (contextual T1136.003). Approved partner collaboration is common. Verify the identity, sponsor, collaboration restrictions, and actual entitlements before asserting a backdoor.
Log Source
Microsoft Entra directory audit logs. The sample uses activityDisplayName: Invite external user. Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing.
Key Fields
| Field | Investigation value |
|---|---|
targetResources, additionalDetails | Invited identity, guest object, and invitation details where recorded. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Match the invitation to a sponsor and approved collaboration purpose; verify the actor’s invitation authority.
- Check guest existence, redemption state, cross-tenant/external-collaboration restrictions, and Conditional Access.
- Correlate group, app, and role assignments with guest sign-ins. An invitation alone proves neither redemption nor resource use.
Sample Event
Synthetic scenario. The sample illustrates an invitation for an external guest. External-account control, the inviter’s administrator role, and successful redemption are not established.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "id": "Directory_90000000-0000-4000-8000-000001110011_4F7E2_61082451", "category": "UserManagement", "correlationId": "90000000-0000-4000-8000-000001110011", "result": "success", "resultReason": "", "activityDisplayName": "Invite external user", "activityDateTime": "2026-04-15T19:51:08.4172395Z", "loggedByService": "Core Directory", "operationType": "Add", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "30000000-0000-4000-8000-001010011100", "displayName": "outside.draco_evilcorp.example#EXT#@fantasticlogs.cloud", "type": "User", "userPrincipalName": "outside.draco_evilcorp.example#EXT#@fantasticlogs.cloud", "groupType": null, "modifiedProperties": [ { "displayName": "AccountEnabled", "oldValue": "[]", "newValue": "[true]" }, { "displayName": "DisplayName", "oldValue": "[]", "newValue": "[\"outside.draco\"]" }, { "displayName": "InvitedUserEmailAddress", "oldValue": "[]", "newValue": "[\"outside.draco@evilcorp.example\"]" }, { "displayName": "UserPrincipalName", "oldValue": "[]", "newValue": "[\"outside.draco_evilcorp.example#EXT#@fantasticlogs.cloud\"]" }, { "displayName": "UserType", "oldValue": "[]", "newValue": "[\"Guest\"]" }, { "displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"AccountEnabled, DisplayName, InvitedUserEmailAddress, UserPrincipalName, UserType\"" } ] } ], "additionalDetails": [ { "key": "InvitedUserEmailAddress", "value": "outside.draco@evilcorp.example" }, { "key": "User-Agent", "value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1136.003 — Cloud Account — Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.