Almost certainly, every guest anyone has ever invited into your tenant is still sitting in it.
A typical tenant holds years of accumulated guests. Suppliers you stopped using. Partners from projects that closed. Personal Gmail addresses belonging to people who left their own employer long ago. Every one of them can still open whatever was shared with them. We inventory that backlog, remove what should never have outlived its purpose, and leave a governance model behind so the pile never rebuilds itself: controlled invitations, an allowed domain list, expiry dates, a named sponsor for each guest and reviews that recur.

- Inventory firstEvery guest, mapped to what they reach
- Expiry by defaultAccess ends unless someone renews it
- Named sponsorsEvery guest has an internal owner
- Recurring reviewsRecertification, not a one-off purge
What a guest access audit typically finds.
This debt accumulates identically in nearly every tenant, for three reasons. Sharing is effortless. Removal belongs to nobody. And nothing expires on its own. By the time somebody finally looks, the guest list reads as a complete history of every collaboration the business has ever entered into, and most of it is still live.
- Guest accounts that have never once signed in, or last did so several years ago, still holding membership of Teams and SharePoint sites carrying current business content today.
- Personal addresses on Gmail, Hotmail and the rest, invited because it was faster than asking the partner for a proper work address. A number belong to people who have since left that partner company. Their mailbox went with them. Your access stayed exactly where it was.
- Guests belonging to suppliers you no longer work with, to bid teams that lost the bid, to auditors whose engagement closed two years ago, and to a recruitment agency somebody used exactly once.
- Nobody able to explain why a particular guest was invited at all, because whoever sent the invitation has since left and no sponsor was ever recorded against it.
- Anyone links across SharePoint and OneDrive that work with no account whatsoever, forwarded well beyond whoever they were created for, with no record anywhere of who currently holds one.
- None of these is unusual in the slightest. Each is simply what happens when Microsoft 365 runs on its default external sharing settings for a few years.
Eight controls that turn guest access from something that happens to you into something you decided.
Who may invite, decided and enforced
Out of the box, very nearly anybody can pull an external identity into the tenant, which is exactly why nobody can account for the guest list afterwards. We narrow invitation rights to defined roles, or route requests through a controlled process, so each new guest arrives with a deliberate origin, a recorded inviter and a stated reason. None of that slows collaboration down. It simply leaves a trail behind it.
Allowed and blocked domains
The external collaboration settings in Entra allow you to restrict invitations to a list of approved partner domains, or alternatively to block particular domains such as the personal email providers. We build that list from your real partner register, so an invitation to a company you genuinely work with goes through without friction while an invite to some random Gmail address is stopped before the account is ever created.
Guest lifecycle with expiry
Structurally, the fix for guest debt is that access ends unless somebody keeps it alive. Guests arriving through access packages carry an assignment expiry. Guests already inside Teams and groups sit under recurring access reviews with a defined outcome when nobody responds. Either route produces the same shift: continued access becomes something a person periodically re-approves, rather than something that persists purely because nobody did anything.
Sponsor accountability
Each guest is given a named internal sponsor, ordinarily whoever owns the Team or the engagement that needed them in the first place. That sponsor receives the review question, confirms or releases the access, and appears by name on the exceptions register. Should the sponsor leave the business, reassigning their guests forms part of the leaver process, which is what stops those guests sliding back into being a problem belonging to nobody at all.
Terms of use acceptance
Terms of use in Entra can require an external party to accept your conditions before they get access at all, with that acceptance recorded against them. What you end up holding is an auditable acknowledgment of confidentiality and acceptable use from every single guest. In a dispute, or in front of an auditor, that is a materially stronger position than access somebody simply handed over one afternoon.
Teams and SharePoint sharing settings that match policy
Sharing levels at tenant and site level, whether Anyone links exist at all and how quickly they expire, the default link type, and guest permissions inside each Team are all set to the tightest value that still supports how your people genuinely work. Sensitive sites end up configured more tightly than working sites. All of it gets documented, so that the administrator who comes after you inherits a policy rather than an archaeology project.
Entitlement management for structured vendor onboarding
Wherever the pattern repeats, a supplier joining a project, an outsourced function starting, an audit engagement beginning, we build an access package. A single request grants the whole defined set of Teams, sites and applications, a named approver makes the decision, and the assignment expires on a schedule. The supplier is productive from their first morning and their access dissolves the moment the engagement ends, with nobody having to remember to remove anything.
Recurring reviews and monitoring
Access reviews aimed specifically at guests recur on a fixed cadence, with the sponsors doing the reviewing and a deliberate outcome defined for anyone who fails to respond. Between those cycles, periodic sweeps pick up stale accounts, guests who have never signed in, and new sharing links appearing on sensitive content. A single cleanup is a project. These recurring pieces are what turn it into a control an auditor will actually accept.
Four things that keep guest governance alive rather than letting it lapse.
We never bulk-delete on day one
The order is inventory, sponsor confirmation, disable, soak, then delete. Staging it that way costs a few extra weeks and prevents the one incident that turns an entire business against the governance program, which is a live partner locked out halfway through a deliverable. Disabling an account is reversible inside a few minutes. Deleting one is a support ticket and a measurable loss of goodwill.
The decision sits with the business rather than with IT
Nobody in IT can possibly know whether the consultant invited two years ago is still needed. The Team owner knows. Sponsor confirmation, and recurring reviews carried out by those sponsors, place every keep or remove decision with the person genuinely holding the context. That is also precisely what makes the resulting evidence credible when an auditor reads it.
A better front door for collaboration opens before any side door closes
Tighten the sharing settings without giving people a working route to onboard a supplier and all you have taught them is to email files around instead, which is strictly worse than what you had. So the access package route and the invitation process go in first, get proven against a real engagement, and only then do the uncontrolled paths get restricted.
We design for the tenant three years from now
Success is not measured by how many guests came off the list this quarter. It is measured by the guest count and the staleness profile three years from now. Expiry applied by default, recurring reviews carrying a deliberate outcome for non-response, and periodic sweeps are what hold that line long after the project team has moved on to something else.
Clearing the existing guest debt without interrupting work that is still live.
- 01Stage 1
Inventory: every guest, mapped to what they can reach
Every guest account in the tenant gets enumerated along with its invitation date, whoever sent that invitation where the record survives, the last sign-in, and each Team, Microsoft 365 Group, SharePoint site and application it can currently reach. Sharing links come too, Anyone links included, across your sensitive libraries. What comes out the other side is a register somebody in the business can actually read: this named person, at this company, can open these specific things, and last did so on this date.
- A complete guest register carrying last sign-in and a map of what each can reach
- A shortlist of stale guests, meaning no sign-in past whatever threshold you agree
- Personal-domain shortlist, Gmail, Hotmail and similar
- Sharing-link exposure summary for sensitive sites
- 02Stage 2
Sponsor confirmation: the business decides, not IT
Any guest showing recent activity, or holding membership of a Team that is still active, gets assigned to the most plausible internal sponsor, which is usually the Team owner. That person confirms whether the business need still exists. Nobody in IT guesses on their behalf. Guests that nobody claims by the end of a defined confirmation window join the removal list. Guests that somebody does claim get a named sponsor recorded against them and an expiry date attached.
- Sponsor assignment for every active guest
- Confirmation responses tracked to a deadline
- Unclaimed guests promoted to the removal list
- Sponsor and expiry recorded for every guest that stays
- 03Stage 3
Staged removal: disable first, delete later
Removal happens in waves, and every wave disables sign-in before anything gets deleted. A disabled guest who turns out to be halfway through a live project is re-enabled within minutes and nothing is lost. A deleted one is a support call followed by an apology. Once a soak period passes with no valid objection raised, the disabled accounts are deleted, their group memberships cleaned up, and any orphaned sharing links revoked.
- Wave plan starting with never-signed-in accounts
- Disable-then-delete with a defined soak period
- Objection route published to the business before wave one
- Sharing links revoked alongside account removal
- 04Stage 4
Exceptions register: the guests that stay, on the record
A number of guests legitimately stay for years. A joint venture partner. An outsourced function that has run for a decade. A key contact at your largest client. Those go onto an exceptions register carrying the sponsor, the justification and a review date, so that the next audit reads a documented decision instead of finding an anomaly nobody can account for. That register is reviewed on exactly the same recurring cadence as everything else.
- Exceptions register with sponsor and justification per entry
- Review date on every exception, none open ended
- Register owner named, usually within IT governance
- Handover into the recurring review cycle
Four US situations where guest debt grows fastest.
Project-heavy businesses
Consultancies, engineering firms and contractors create a Team for each project, invite the client and the subcontractors into it, deliver the work and move on. Nothing dissolves those memberships when the project closes, so the guest list gradually becomes a permanent roster of every counterparty the firm has ever had. An access package per project, with expiry tied to the project end date, fixes that at the source rather than downstream.
Joint ventures and construction consortiums
A joint venture or a consortium involves deep, sustained sharing with partner organizations across years, covering drawings, schedules and commercial documents. Guests like those legitimately stay, which is precisely why they belong on the exceptions register with named sponsors and recurring recertification instead of an ordinary expiry date. When the venture eventually closes out, that register becomes the checklist for unwinding every piece of access completely.
Agencies running client teams
Marketing, PR and creative agencies host their clients as guests inside shared Teams, often several clients simultaneously, with staff turning over on both sides constantly. The scenario nobody wants is one client catching a glimpse of work belonging to another. Separate sites per client with deliberate sharing settings, guests scoped strictly to their own Team, and reviews tracking leavers on both the agency and the client side are what keep those walls standing.
Regulated and compliance-driven firms
Healthcare providers under HIPAA, financial firms under GLBA and the FTC Safeguards Rule, defense contractors working toward CMMC, and anybody facing SOC 2 or enterprise due diligence all arrive at the same question eventually. Which external parties can reach your data, and how do you know that? A governed tenant answers with a register, a list of sponsors and review evidence. An ungoverned one turns a routine questionnaire into a remediation project with a deadline attached.
Ungoverned guests are a data protection problem, not only a tidiness problem.
HIPAA, state privacy laws like CCPA/CPRA, SOC 2 examinations, FTC Safeguards obligations, and cyber insurance questionnaires all ask versions of the same question: who outside your organization can access the data you hold, and how do you know? An external party with standing access to your SharePoint and Teams content is exactly the exposure those frameworks probe.
- HR folders, customer lists, resumes, contracts, health information and financial records all routinely sit inside the same SharePoint sites and Teams that guests were added to years earlier for completely unrelated reasons.
- When a guest account belongs to somebody who has left the partner company, data in your care becomes reachable from a mailbox you hold no relationship with whatsoever. For an organization covered by HIPAA, that is precisely the sort of finding a security risk analysis exists to surface before an incident surfaces it for you.
- The moment a SOC 2 auditor, a security questionnaire from an enterprise customer, or a rights request under CCPA or CPRA asks which external parties can reach personal information, an ungoverned tenant simply cannot answer. A governed one hands over the guest register, the list of sponsors and the review evidence.
- The governance model produces the paperwork as a byproduct. Your inventory, your exceptions register and your recurring review records are exactly the artifacts any privacy and security program needs covering external access. We build the controls and generate the evidence. Interpreting it against your obligations belongs to your compliance advisors.
The same tenant, with and without guest governance.
| Feature | Governed tenant | Default-settings tenant |
|---|---|---|
Who can see the full guest list and what each guest reaches | Anyone who asks, from the register | Nobody, without a scripted investigation |
Why each guest exists | Recorded sponsor and reason | The memory of whoever invited them |
Personal email domains as guests | Blocked or exception-listed | Routine |
Guest access after a project ends | Expires or is removed at review | Persists indefinitely |
Guest belonging to someone who left the partner firm | Caught at the next review cycle | Undetected |
Anyone links on sensitive content | Disabled or expiring, audited | Unknown and unbounded |
Terms of use acknowledgment from external parties | Recorded before first access | None |
Vendor onboarding to a new project | One access package request, approved and time-limited | A flurry of individual invites and shares |
Answer to a HIPAA, SOC 2, or client due-diligence question on external access | The register and review evidence | An honest shrug |
Guest debt in three years | Held near zero by expiry and reviews | Rebuilt to the current level or worse |
Teams and SharePoint external sharing, configured on purpose.
Control surface
Who can invite guests
- The common default state
- Invitation rights held broadly, so any employee can pull an external identity into the directory
- What a governed tenant looks like
- Invitations limited to defined roles or routed through a controlled process, so each guest has a traceable origin
Control surface
Domain allow and block lists
- The common default state
- No restrictions at all on collaboration, meaning any external domain can be invited, personal mailboxes included
- What a governed tenant looks like
- Either an allow list naming approved partner domains or a block list covering personal email providers, held in step with your partner register
Control surface
SharePoint and OneDrive sharing level
- The common default state
- Sharing left permissive across the whole organization, frequently including links usable with no sign-in at all
- What a governed tenant looks like
- The tightest setting the business can genuinely work with, applied per site wherever sensitivity varies, and Anyone links either disabled outright or given an expiry where they are used
Control surface
Teams guest access
- The common default state
- Guest access enabled tenant-wide with default guest permissions
- What a governed tenant looks like
- Guest access becomes a decision: switched on where collaboration genuinely needs it, guest permissions inside each Team reviewed properly, and the sensitive Teams closed to guests altogether
Control surface
Guest expiry
- The common default state
- Nothing expires. Somebody invited in 2019 remains a guest this morning
- What a governed tenant looks like
- Access becomes time-bound through access reviews and access packages, so it lapses unless a sponsor actively renews it
Control surface
Terms of use
- The common default state
- Guests get to your shared content without ever having seen your acceptable use or confidentiality terms
- What a governed tenant looks like
- Acceptance of your terms of use is recorded before first access, leaving an auditable acknowledgment from every external party
Control surface
Sponsor accountability
- The common default state
- The sole record of why any guest exists is whatever the person who invited them happens to recall
- What a governed tenant looks like
- Each guest carries a named internal sponsor, and that person answers the question at every recurring review
Five steps from unknown guest list to standing control.
- 1
Assess and inventory
We enumerate every guest along with their last sign-in and the full reach of what they can open, capture how external collaboration, Teams and SharePoint sharing are currently configured, and identify Anyone link exposure across your sensitive sites. What comes out is the guest register itself plus a findings summary your leadership team can get through in a single sitting.
- 2
Agree the policy
Six decisions get made here. Who is permitted to invite. Which domains are allowed and which blocked. What expiry and review cadence applies to which population of guests. Which sites carry sharing settings tighter than the tenant default. And what the exceptions register demands before an entry goes on it. This is a short workshop rather than a document-writing project, but the business has to make these calls rather than letting IT default them.
- 3
Clean up the backlog
This is the staged cleanup described earlier. Sponsor confirmation carrying a deadline. Disable then delete, in waves, beginning with the accounts that have never signed in at all. Sharing links revoked alongside the accounts. And the guests who legitimately stay for years documented on the exceptions register with a review date against each.
- 4
Configure the controls
Invitation restrictions go in, along with the domain lists, terms of use, sharing levels at tenant and site level, Teams guest settings, access packages covering the vendor patterns that recur, and recurring access reviews aimed at guests with sponsors reviewing and a deliberate outcome defined for non-response. Every setting is documented against the specific line of policy it implements.
- 5
Hand over the cadence
Three things get a named owner and a schedule: the recurring reviews, the periodic sweeps for stale guests and new sharing links, and the exceptions register. We can run that cadence for you as part of a managed service or hand it across to your team with runbooks written. Either route produces the same property, which is that the control outlives everybody involved in setting it up.
What organizations ask about guest and external access governance.
What stays running after the project ends.
Continuous, no human attention
- Invitation control enforced by configurationNot by asking people nicely.
- Domain allow or block list evaluated on every invitePersonal domains stopped at the door.
- Terms of use gate on first guest accessAcceptance recorded automatically.
- Access package expiry for structured vendor accessAssignments end on their own.
Recurring, sponsor attention
- Guest access reviews per Team or groupThe sponsor confirms or the access goes.
- Non-response handling decided in advanceSilence must not mean approval.
- Exceptions register reviewLong-lived guests reconfirmed, not forgotten.
Periodic, IT governance attention
- Stale and never-signed-in guest sweepCatches what the reviews scope missed.
- Sharing link and Anyone link audit on sensitive sitesLinks are access too.
- New Teams and sites checked against sharing policyDefaults drift back if unwatched.
- Partner domain list reconciled with the partner registerEx-vendors leave the allow list.
The pages around this one.
Microsoft 365 Tenant Management
The wider tenant hygiene this belongs to, covering settings, baselines and day to day administration.
Cross-Tenant Sync & Collaboration
For sister companies: the governed alternative to hosting each other's staff as permanent guests.
Microsoft Entra
The identity platform behind the controls: Conditional Access, B2B collaboration, and identity governance.
Begin with the inventory. It takes very little time, and it puts an end to the guessing.
A single register listing every guest, everything each one can reach, and the date they last signed in. The total surprises most businesses and the staleness surprises almost all of them. After that, every decision that follows is simply the business confirming something it already knew.
Related Services
Explore more solutions that work great with this service
Microsoft Entra
Identity and access management solutions
Learn moreM365 Tenant Management
Your tenant run properly, end to end
Learn moreCross-Tenant Sync
Multi-tenant orgs collaborating safely
Learn moreTenant Security Baseline
Documented controls mapped to CIS
Learn moreMicrosoft Defender
Advanced endpoint and email threat protection
Learn more