Why do Defender for Cloud recommendations for guest accounts with Azure permissions continue to show noncompliant?

Raja P 20 Reputation points
2026-09-09T12:17:48.7433333+00:00

Why do Defender for Cloud recommendations for guest accounts with Azure permissions continue to show noncompliant?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-09-09T12:18:05.09+00:00

    A common reason is that these recommendations were transitioned from deprecated grouped assessments to new individual assessments. If the old assessment IDs are still being checked, the recommendation can appear unchanged until the replacement recommendation is reviewed in Recommendations.

    For the guest account recommendations, the replacement assessment IDs are:

    • Guest accounts with read permissions on Azure resources should be removed
      Old: fde1c0c9-0fd2-4ecc-87b5-98956cbc1095 → New: 422107c6-5b9a-46a6-bb1d-26ef1cc52d65
    • Guest accounts with write permissions on Azure resources should be removed
      Old: 0354476c-a12a-4fcc-a79d-f0ab7ffffdbb → New: 009678ce-adce-4c94-9cc8-cfc2bd0c6a06
    • Guest accounts with owner permissions on Azure resources should be removed
      Old: 20606e75-05c4-48c0-9d97-add6daa2109a → New: f2864482-b329-4310-8c06-3cf74fe880c5

    These recommendations remain noncompliant when Defender for Cloud still detects guest accounts provisioned outside the Microsoft Entra tenant that retain read, write, or owner permissions on Azure resources. The recommendation descriptions explicitly state that such guest accounts should be removed because they are external identities and can create unmonitored access risk.

    To verify the current state:

    1. In Defender for Cloud, open Recommendations.
    2. Search for the relevant replacement assessment ID.
    3. Review the affected resources listed in the recommendation.
    4. Confirm whether the guest accounts still have Azure role assignments with read, write, or owner permissions.

    If the accounts or resources were already removed and the recommendation still shows noncompliant, a refresh delay can occur. In that case, verify the resources no longer exist in Azure Resource Graph and then either wait for the next assessment cycle or, if operationally feasible, toggle the affected Defender plan off and back on to trigger a manual assessment refresh.

    If the recommendation is not applicable for a specific case, exemptions can be used. Note that exemption rules for the replacement recommendations are available only to paid customers; non-paying customers lose exemption capability for these recommendations after the original assessments are retired.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.