⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Identity & Security10 min read

Guest Access in Entra ID, The Invisible Security Risk in Most M365 Tenants

When Microsoft introduced B2B collaboration in Azure Active Directory (now called Entra ID), it solved a real problem. You could invite an external contractor or partner to collaborate in Teams or access SharePoint without giving them a full user account. The problem is what happens over the next two years when nobody thinks about those guest accounts again.

What Is a Guest Account?

A guest account in Entra ID is an external Identity that has been invited into your Microsoft 365 environment with some level of access. They appear in your directory alongside internal users, usually identifiable by the “#EXT#” notation.

Guest accounts are created when someone accepts a Teams invitation, a SharePoint site owner shares a document externally, a project manager adds an external collaborator, or an IT vendor requests tenant access.

Why Guest Accounts Accumulate Unnoticed

  • Creating a guest account requires almost no friction: in many tenants, every user can invite externals
  • Nobody thinks to clean them up when the engagement ends
  • The guest themselves may not know they still have access
  • Tenants running 3+ years can accumulate dozens of unmanaged guest accounts

What Can a Guest Account Actually Access?

The defaults in many M365 tenants are more permissive than most people realise. Guests can see group memberships, access SharePoint sites and Teams they’ve been added to, and in some configurations, enumerate your directory.

Worst case: a guest account belonging to a contractor whose engagement ended 18 months ago still has access to a SharePoint site containing sensitive business information, and nobody is aware of it.

The Vendor Access Problem

IT vendors often request broad permissions (Global Admin or Exchange Admin) because it’s easier than diagnosing exact requirements. When you change vendors, the previous vendor’s access is not automatically removed. I have reviewed tenants where two or three previous IT providers still had active access years after the relationship ended.

Governance: Preventing Accumulation

  • Access reviews: Entra ID P2 includes automatic prompts to confirm whether guest access is still required
  • Guest invitation policies: restrict who can invite guests to IT administrators or specific roles
  • Expiry policies: set default expiry periods (90 or 180 days) with renewal requirements
  • Vendor access management: document, time-limit, and review all vendor access

Not sure who has access to your tenant from outside your organisation?

or call 0403 401 250