Difference between guest and member user types in MS Entra ID

Quattrocchi, Calogero 265 Reputation points
2023-10-16T07:48:38.21+00:00

Hi, I recently changed my account from a guest user type to a member user type in MS Entra ID due to a recommendation from MS Defender for Cloud: "Guest accounts with owner permissions on Azure resources should be removed"

User's image

However, I'm not sure what the difference is between guest and member user types, and what impact it will have on my account since I am still using the same account. Can anyone explain the difference between the two user types and what changing my user type will impact if I use the same account? Thank you.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,904 questions
0 comments No comments
{count} votes

Accepted answer
  1. Michael Smith 2,916 Reputation points Microsoft Employee
    2023-10-16T10:12:17.9133333+00:00

    Hi @Quattrocchi, Calogero

    Guest users are more restricted than members.

    Below are the comparisons between the guest and the member.

    https://zcusa.951200.xyz/en-us/azure/active-directory/external-identities/user-properties

    • External guest: Most users who are commonly considered external users or guests fall into this category. This B2B collaboration user has an account in an external Microsoft Entra organization or an external identity provider (such as a social identity), and they have guest-level permissions in the resource organization. The user object created in the resource Microsoft Entra directory has a UserType of Guest.
    • External member: This B2B collaboration user has an account in an external Microsoft Entra organization or an external identity provider (such as a social identity) and member-level access to resources in your organization. This scenario is common in organizations consisting of multiple tenants, where users are considered part of the larger organization and need member-level access to resources in the organization’s other tenants. The user object created in the resource Microsoft Entra directory has a UserType of Member.

    Diagram showing B2B collaboration users.

    https://zcusa.951200.xyz/en-us/azure/active-directory/fundamentals/users-default-permissions#compare-member-and-guest-default-permissions

    Users and contacts Enumerate the list of all users and contactsRead all public properties of users and contactsInvite guestsChange their own passwordManage their own mobile phone numberManage their own photoInvalidate their own refresh tokens Read their own propertiesRead display name, email, sign-in name, photo, user principal name, and user type properties of other users and contactsChange their own passwordSearch for another user by object ID (if allowed)Read manager and direct report information of other users Read their own propertiesChange their own passwordManage their own mobile phone number
    Groups Create security groupsCreate Microsoft 365 groupsEnumerate the list of all groupsRead all properties of groupsRead non-hidden group membershipsRead hidden Microsoft 365 group memberships for joined groupsManage properties, ownership, and membership of groups that the user ownsAdd guests to owned groupsManage dynamic membership settingsDelete owned groupsRestore owned Microsoft 365 groups Read properties of non-hidden groups, including membership and ownership (even non-joined groups)Read hidden Microsoft 365 group memberships for joined groupsSearch for groups by display name or object ID (if allowed) Read object ID for joined groupsRead membership and ownership of joined groups in some Microsoft 365 apps (if allowed)
    Applications Register (create) new applicationsEnumerate the list of all applicationsRead properties of registered and enterprise applicationsManage application properties, assignments, and credentials for owned applicationsCreate or delete application passwords for usersDelete owned applicationsRestore owned applicationsList permissions granted to applications Read properties of registered and enterprise applicationsList permissions granted to applications Read properties of registered and enterprise applicationsList permissions granted to applications
    Devices Enumerate the list of all devicesRead all properties of devicesManage all properties of owned devices No permissions No permissions
    Organization Read all company informationRead all domainsRead configuration of certificate-based authenticationRead all partner contractsRead multi-tenant organization basic details and active tenants Read company display nameRead all domainsRead configuration of certificate-based authentication Read company display nameRead all domains
    Roles and scopes Read all administrative roles and membershipsRead all properties and membership of administrative units No permissions No permissions
    Subscriptions Read all licensing subscriptionsEnable service plan memberships No permissions No permissions
    Policies Read all properties of policiesManage all properties of owned policies No permissions No permissions

    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.