Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes.
Why This Matters
Restricting guest invites to only approved external domains prevents unauthorized external access to your Azure AD tenant. Without this control, any user in your organization could invite guests from any domain, increasing the risk of data exposure, phishing attacks, and compliance violations. IT administrators should prioritize this check to enforce a least-privilege model for external collaboration and maintain security boundaries.
What Aether365 Checks
Aether365 verifies that your Azure AD tenant is configured to allow guest invitations only from a managed list of approved external domains. This check appears in the Aether365 dashboard under the entra-id section and flags any deviations from your authorized domain policy.