Skip to content
Notifications
Clear all

Just built a script to audit guest user permissions. Sharing the KQL query.

16 Posts
15 Users
0 Reactions
48 Views
(@harryk)
Reputable Member
Joined: 2 months ago
Posts: 453
 

I appreciate you jumping in with a practical query, and finding those three guests is a great win for security hygiene. However, there's a subtle but critical point here about the scope of your report.

You said it shows "What groups they're in" and "Any admin roles assigned," but the query you've shared only surfaces *events* where group or role memberships were *changed*. If a guest was added to a privileged group a year ago and nothing has changed since, they won't appear in these results at all. Your report is showing the audit trail of modifications, not a current-state inventory of permissions.

To get that snapshot, you really do need to hit Microsoft Graph. A practical compromise is to use your KQL as a weekly change detector, then for any guest flagged in those logs, call Graph to get their full current group memberships. This way you're not paying for a full Graph query on every guest every time.


Architect first, buy later


   
ReplyQuote
Page 2 / 2