Guest Access in Entra ID, The Invisible Security Risk in Most M365 Tenants
By Jamie Hamilton · Published · Updated
When Microsoft introduced B2B collaboration in Azure Active Directory, now Entra ID, it solved a real problem. You could invite an external contractor into Teams or a SharePoint site without creating a full user account for them. It works well. The difficulty is what happens over the following two years, when nobody thinks about that account again.
What is a guest account?
A guest account is an external Identity invited into your Microsoft 365 environment with some level of access. It sits in your directory alongside your own staff, usually identifiable by the #EXT# marker in the username.
They get created in more ways than most people expect: somebody accepts a Teams invitation, a site owner shares a document with an external address, a project manager adds a collaborator to a channel, or an IT vendor asks for access to fix something.
Why they accumulate unnoticed
- •Creating one takes almost no effort, and in a default tenant every user can invite an external, not just administrators.
- •Nothing marks the end of an engagement. The project finishes, the invoice is paid, and the account stays.
- •The guest usually does not know they still have access, so they will not tell you.
- •None of it is visible from the places people actually look. A guest does not appear in your licence count and does not show up in the active users list you check for staff.
A tenant three years old with no guest governance will typically have dozens, and the owner is usually surprised by the list.
What can a guest actually see?
More than most people assume, because the defaults are built for collaboration rather than containment.
A guest can see the Teams and SharePoint sites they were added to, which is the intended part. Depending on your external collaboration settings they may also be able to see other members of the groups they belong to, and in a permissive configuration read parts of your directory: who works there, what the addresses look like, and which groups exist. That is exactly the reconnaissance somebody wants before writing a convincing invoice email.
The realistic worst case is not dramatic. It is a contractor whose engagement finished eighteen months ago still holding access to a SharePoint site with pricing, contracts or client records in it, and nobody in the business aware that the account exists.
Guests are not the only external access, and the other kind is bigger
This is the part that gets missed, because it does not appear in the guest list at all.
When an IT provider manages your tenant, they usually do it through a delegated administration relationship rather than a guest account. That relationship gives their staff administrative access to your tenant from their own tenant, and it is granted once and then forgotten. Changing providers does not revoke it. I have reviewed tenants where two or three previous providers still had a live path to Global Administrator years after the relationship ended, and none of them appeared anywhere in the user list the owner had been checking.
You will find these under partner relationships in the Microsoft 365 admin centre rather than in Entra ID. It is a different screen, and if you have changed IT providers at any point it is the more important of the two to look at.
The related habit worth breaking is granting a vendor Global Administrator because it is quicker than working out what they actually need. It is quicker. It is also permanent unless somebody removes it, and the person who would remember to remove it is usually the one who left.
How to audit what you have
Three passes, and none of them takes long.
- •In Entra ID, open users and filter on user type equals guest. Add the columns for creation date and last sign-in, then sort by last sign-in. Anything that has never signed in, or has not signed in for a year, is a candidate for removal.
- •In the Microsoft 365 admin centre, open partner relationships and read the list. Any provider you no longer work with should not be there.
- •In SharePoint, review external sharing links separately. A link that works for anyone who has it is not a guest account and will not appear in either list above, so it survives a guest clean-up untouched.
Remove rather than block where you can. A blocked guest is still a row in your directory that somebody will eventually re-enable to solve a problem.
Stopping it happening again
Cleaning up once and changing nothing means doing it again in eighteen months.
- •Restrict who can invite. Moving invitation rights from everybody to administrators, or to a named set of people, is a single setting and it is the highest value change on this list.
- •Set an expiry expectation for guests, and review against it. Access reviews will do this automatically on the higher Entra tiers, and a calendar reminder and a spreadsheet does the same job for a small tenant.
- •Give vendors the least role that works and a written end date, rather than Global Administrator and hope.
- •Add removing external access to whatever you already do when a project finishes, because that is the moment somebody knows the engagement ended.
The point of all of it is that guest access is created by the people doing the work, at the moment the work needs it, which is correct. It is never removed by those people, because finishing a project does not feel like a security event. Somebody has to own the other half.
Frequently asked questions
What is a guest account in Entra ID?
It is an external person invited into your Microsoft 365 environment so they can collaborate without you creating a full staff account for them. They appear in your directory next to your own users, usually with #EXT# in the username. Guests are created whenever somebody accepts a Teams invitation, a site owner shares a document externally, or a vendor is given access to help with something.
How do I see all the guest users in my tenant?
In Entra ID, open users and filter on user type equals guest. Add the creation date and last sign-in columns and sort by last sign-in. Anything that has never signed in, or has not for a year, is worth removing. Do not stop there: external sharing links in SharePoint and partner relationships with IT providers are two other kinds of outside access that will not appear in that list.
Can guest users see my whole directory?
It depends on your external collaboration settings, and the defaults are more permissive than most people expect. A guest can always see the Teams and sites they were added to. In a default configuration they may also see other members of those groups and be able to read parts of the directory, which is useful reconnaissance for anyone planning to impersonate one of your staff. Tightening guest permissions is a single setting in Entra ID.
Does our old IT provider still have access after we changed providers?
Quite possibly, and it will not show in your guest list. Providers usually work through a delegated administration relationship, which grants their staff administrative access to your tenant from theirs. Changing providers does not revoke it automatically. Check partner relationships in the Microsoft 365 admin centre, which is a different screen from the user list, and remove anybody you no longer work with.
Should I block or delete an unused guest account?
Delete it where you can. A blocked guest is still an entry in your directory, and blocked accounts get re-enabled by whoever is solving a problem at the time without anyone remembering why the block was there. If the engagement has ended, remove the account. Re-inviting somebody later takes seconds if it turns out you were wrong.
How do I stop guest accounts accumulating?
The single highest value change is restricting who can send invitations, because in a default tenant every user can invite an external. Move that to administrators or a named group. After that, give vendors the smallest role that works with a written end date rather than Global Administrator, and attach removing external access to whatever you already do when a project finishes, since that is the only moment anybody knows the engagement is over.
Related Articles
Not sure who can reach your tenant from outside your organisation?
Health Check, $599or call 0403 401 250