diff --git a/en/azure/activedirectory/ensure-no-guest-user.md b/en/azure/activedirectory/ensure-no-guest-user.md index c50dd4189..f478bf04c 100644 --- a/en/azure/activedirectory/ensure-no-guest-user.md +++ b/en/azure/activedirectory/ensure-no-guest-user.md @@ -15,8 +15,10 @@ | **Recommended Action** | Remove all guest users unless they are required to be members of the Active Directory account. | ## Detailed Remediation Steps - - - - - +1. Log in to the Microsoft Azure Management Console. +2. Find the search bar at the top and search for Azure Active Directory.
+3. Select the "Azure Active Directory" and on the left navigation panel, select the "Users" under "Manage".
+4. In the users list, look for users with "User type" as "Guest". If there are "Guest" type users then those users are not part of the onboarding/offboarding process and are considered a security vulnerability. Such accounts must be deleted.
+5. Select all Users with "User type" as "Guest" and click "Delete User" on the top right.
+6. Click OK in the confirmation popup.
+7. Repeat step number 3 to 6 for all other directories. diff --git a/resources/azure/activedirectory/ensure-no-guest-user/.DS_Store b/resources/azure/activedirectory/ensure-no-guest-user/.DS_Store new file mode 100644 index 000000000..cc72c4456 Binary files /dev/null and b/resources/azure/activedirectory/ensure-no-guest-user/.DS_Store differ diff --git a/resources/azure/activedirectory/ensure-no-guest-user/step2.png b/resources/azure/activedirectory/ensure-no-guest-user/step2.png new file mode 100644 index 000000000..b4c2cc23a Binary files /dev/null and b/resources/azure/activedirectory/ensure-no-guest-user/step2.png differ diff --git a/resources/azure/activedirectory/ensure-no-guest-user/step3.png b/resources/azure/activedirectory/ensure-no-guest-user/step3.png new file mode 100644 index 000000000..573dff4c7 Binary files /dev/null and b/resources/azure/activedirectory/ensure-no-guest-user/step3.png differ diff --git a/resources/azure/activedirectory/ensure-no-guest-user/step4.png b/resources/azure/activedirectory/ensure-no-guest-user/step4.png new file mode 100644 index 000000000..fa31e1ae6 Binary files /dev/null and b/resources/azure/activedirectory/ensure-no-guest-user/step4.png differ diff --git a/resources/azure/activedirectory/ensure-no-guest-user/step5.png b/resources/azure/activedirectory/ensure-no-guest-user/step5.png new file mode 100644 index 000000000..9f95a6bcb Binary files /dev/null and b/resources/azure/activedirectory/ensure-no-guest-user/step5.png differ diff --git a/resources/azure/activedirectory/ensure-no-guest-user/step6.png b/resources/azure/activedirectory/ensure-no-guest-user/step6.png new file mode 100644 index 000000000..ca0718a17 Binary files /dev/null and b/resources/azure/activedirectory/ensure-no-guest-user/step6.png differ