Skip to content

Invite External User

Azure

Invite External User

service: Azure - Microsoft Entra ID
tactics:
techniques:

Event

Creates a B2B invitation and can create a guest user object; the invitation API also supports resetting redemption for an existing guest. Sending an invitation, redeeming it, signing in, and receiving application/resource assignments are separate steps. Invitation success does not grant unrestricted tenant-resource access.

Security Context

Unauthorized guest onboarding can prepare persistent cloud access (contextual T1136.003). Approved partner collaboration is common. Verify the identity, sponsor, collaboration restrictions, and actual entitlements before asserting a backdoor.

Log Source

Microsoft Entra directory audit logs. The sample uses activityDisplayName: Invite external user. Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing.

Key Fields

FieldInvestigation value
targetResources, additionalDetailsInvited identity, guest object, and invitation details where recorded.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Match the invitation to a sponsor and approved collaboration purpose; verify the actor’s invitation authority.
  3. Check guest existence, redemption state, cross-tenant/external-collaboration restrictions, and Conditional Access.
  4. Correlate group, app, and role assignments with guest sign-ins. An invitation alone proves neither redemption nor resource use.

Sample Event

Synthetic scenario. The sample illustrates an invitation for an external guest. External-account control, the inviter’s administrator role, and successful redemption are not established.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-000001110011_4F7E2_61082451",
"category": "UserManagement",
"correlationId": "90000000-0000-4000-8000-000001110011",
"result": "success",
"resultReason": "",
"activityDisplayName": "Invite external user",
"activityDateTime": "2026-04-15T19:51:08.4172395Z",
"loggedByService": "Core Directory",
"operationType": "Add",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "30000000-0000-4000-8000-001010011100",
"displayName": "outside.draco_evilcorp.example#EXT#@fantasticlogs.cloud",
"type": "User",
"userPrincipalName": "outside.draco_evilcorp.example#EXT#@fantasticlogs.cloud",
"groupType": null,
"modifiedProperties": [
{
"displayName": "AccountEnabled",
"oldValue": "[]",
"newValue": "[true]"
},
{
"displayName": "DisplayName",
"oldValue": "[]",
"newValue": "[\"outside.draco\"]"
},
{
"displayName": "InvitedUserEmailAddress",
"oldValue": "[]",
"newValue": "[\"outside.draco@evilcorp.example\"]"
},
{
"displayName": "UserPrincipalName",
"oldValue": "[]",
"newValue": "[\"outside.draco_evilcorp.example#EXT#@fantasticlogs.cloud\"]"
},
{
"displayName": "UserType",
"oldValue": "[]",
"newValue": "[\"Guest\"]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"AccountEnabled, DisplayName, InvitedUserEmailAddress, UserPrincipalName, UserType\""
}
]
}
],
"additionalDetails": [
{
"key": "InvitedUserEmailAddress",
"value": "outside.draco@evilcorp.example"
},
{
"key": "User-Agent",
"value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1136.003 — Cloud Account — Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.