Skip to main content
Version: 2.0.1 (preview)

Default Authorization Settings - Sign-up for email based subscription

Indicates whether users can sign up for email based subscriptions.

NameallowedToSignUpEmailBasedSubscriptions
ControlDefault Authorization Settings
DescriptionManages authorization settings in Entra ID (Azure AD)
SeverityMedium

How to fixโ€‹

Microsoft Graph PowerShell: Update-MgPolicyAuthorizationPolicy -AllowedToSignupEmailBasedSubscriptions $false

Details of configuration itemโ€‹

Recommendation
Configurationpolicies/authorizationPolicy
SettingallowedToSignUpEmailBasedSubscriptions
Recommended Value'false'
Default Valuetrue
Graph API DocsauthorizationPolicy resource type - Microsoft Graph v1.0 - Microsoft Learn
Graph ExplorerOpen in Graph Explorer

MITRE ATT&CKโ€‹

TacticTechniqueMitigation
TA0001 - Initial Access - Initial Access