EXT-04: Configure Guest Access Expiration
Frequently asked questions about implementing and managing the EXT-04 security control in Microsoft 365 and Entra ID.
QWhat is EXT-04 (Configure Guest Access Expiration)?▼
EXT-04 is a security control that guest accounts created for temporary projects often outlive their intended use. without expiration, ex-partners and former vendors retain access indefinitely. automatic expiration ensures guest access is time-bound. It requires that guest accounts have expiration dates configured and guest access expires after 90 days unless renewed, access reviews are configured for guest users.
QWhy is Configure Guest Access Expiration important for Microsoft 365 security?▼
Guest accounts created for temporary projects often outlive their intended use. Without expiration, ex-partners and former vendors retain access indefinitely. Automatic expiration ensures guest access is time-bound.
QHow do I implement EXT-04 in my tenant?▼
EXT-04 requires manual implementation. Requires Entra ID Governance access reviews configuration
QWhat license do I need for EXT-04?▼
This control requires Azure AD Premium P2 (included in Microsoft 365 E5) or standalone P2.
QWhich security baseline includes EXT-04?▼
EXT-04 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.
5
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial