How are guest accounts in Microsoft Entra ID managed so that external individuals can access only the required resources and only for the necessary duration? A secure model combines B2B invitation, Cross-Tenant Access Settings, Conditional Access, resource permissions, business sponsors, expiration dates, and regular access reviews. The guest object in the directory alone does not grant access to a file or application; actual access is created only through groups, app assignments, Teams, SharePoint sharing, or other resource rights.
Microsoft Entra External ID encompasses several scenarios. For collaboration with business partners in your own workforce tenant, B2B Collaboration is central. Customer identities for your own applications can, however, reside in an External Tenant/CIAM configuration. These models should not be mixed.
Separate guest identity, sign-in, and resource rights
Three levels must be considered separately:
- Identity: Guest or external user representation in the resource tenant.
- Authentication: How does the person prove their identity—own Entra tenant, Microsoft account, one-time passcode, or other supported provider?
- Authorization: Which groups, apps, sites, Teams, or files are they permitted to use?
Deleting a SharePoint sharing link does not automatically remove the guest object. Conversely, the existence of a guest object does not mean access currently exists.
B2B collaboration and B2B direct connect
For workforce tenants, classic B2B Collaboration with other Entra organizations is fundamentally the standard scenario. B2B Direct Connect is not automatically active for every collaboration and must be consciously enabled and tested organization-specifically on both sides.
B2B collaboration
The external user accesses resources in your own tenant as a guest or external identity. They typically use their existing sign-in credentials. A user object is created in the resource tenant.
B2B direct connect
B2B Direct Connect is organization-specifically controlled via Cross-Tenant Access Settings and is intended for certain direct collaboration scenarios. It is not identical to normal B2B Collaboration.
For each partner company, it should be documented which model is used and which resources it affects.
Invitation process
If the guest does not use a matching Entra or Microsoft account, the email one-time passcode is used by default in many workforce tenants, provided it has not been consciously disabled. This should be known in the support process because invitation, redemption, and MFA questions differ noticeably depending on the identity source.
A controlled process answers:
- Who is permitted to invite guests?
- Which domains are allowed or blocked?
- Who is the business sponsor?
- Which resource and role are required?
- How long does the access last?
- Which terms of use or privacy information apply?
- How is the partner's identity verified?
- When is access reviewed or revoked?
Do not confuse an invitation with sharing
An invitation can create a guest object. Resource permissions must be set separately. It is best to grant access through a clearly named group or an access package so that revocation and review remain traceable.
External collaboration settings
Tenant-wide external collaboration settings control, among other things:
- who is allowed to invite guests,
- how restricted guests are from seeing directory information,
- domain allow- and deny lists,
- self-service sign-up features, to the extent they are used.
A domain allow list does not prove that every user in the domain is trustworthy. It is only an organizational restriction of the invitation scope.
Cross-tenant access settings
Cross-tenant access settings determine incoming and outgoing access to other Microsoft Entra organizations. There are default values and organization-specific settings.
Possible aspects:
- which external users or groups are allowed,
- which internal applications they are allowed to access,
- which own users are allowed in the partner tenant,
- whether MFA claims from the home tenant are trusted,
- whether device compliance or hybrid join claims are trusted,
- whether B2B Direct Connect is allowed.
Trust in MFA and device claims
The resource organization can decide whether to accept certain claims from a partner tenant. This decision should only be made for known organizations with aligned security levels. Otherwise, the resource tenant requires its own controls.
Conditional Access for external users
For guests with email one-time passcode, Require multifactor authentication is often the more realistic grant control in practice than a more demanding authentication strength. Strength-based requirements work correctly only where the external identity can actually deliver the expected method claims.
External users can have their own Conditional Access policies. Typical controls include:
- MFA or authentication strength,
- accepted terms of use,
- access limited to specific apps,
- session controls,
- blocking unknown or unsupported scenarios.
Device requirements must be tested carefully for external users. A partner device is not automatically managed by your own Intune. Cross-Tenant Trust or alternative controls may be necessary.
Resource permissions
Microsoft 365 groups and Teams
Guests can be members of a Microsoft 365 group or a team. This creates connected access to SharePoint, conversations, and other services. Private or Shared Channels have additional membership and site relationships.
SharePoint and OneDrive
Access can be granted through site membership, groups, direct file or folder sharing, or sharing links. To fully clean up access, all paths must be considered. The technical setup for external SharePoint collaboration is covered in detail in the article External Collaboration in SharePoint.
Enterprise Applications
An app can require user or group assignment. Guest object, consent, and app assignment are separate layers.
Sponsor and owner
Every guest account requires a business sponsor. The sponsor confirms:
- identity and partner organization,
- business purpose,
- required resources,
- validity period,
- renewal or revocation.
IT operations can detect technical inactivity but may not always know if a contract or project is still ongoing. Without a sponsor, reviews become guesswork.
Lifecycle and renewal
A guest access should have an expiration or review date. Possible models include:
- Access Package with a fixed-term assignment,
- recurring Access Review,
- project-based group with a lifecycle,
- external workflow or ticket deadline,
- manual but controlled follow-up.
Extension does not happen automatically just because the guest recently logged in. Activity and business necessity are different signals.
Logging and evaluation
Microsoft Entra provides audit and sign-in logs. For B2B users, activities can occur in both the home and resource tenants.
Verifiable information:
- Invitation and redemption,
- User creation and modification,
- Group memberships,
- interactive and non-interactive sign-ins,
- Conditional Access result,
- Target application,
- Audit activities of the guest user,
- Provisioning and Access Review results.
Not every business file action appears in Entra audit. SharePoint, Purview, or application-specific logs may be additionally necessary.
Typical error patterns
Guest cannot redeem invitation
Possible causes:
- incorrect email address or other home account,
- Cross-Tenant Access blocked,
- domain restriction,
- Conditional Access,
- existing guest object with a different identity,
- one-time passcode or browser issue.
Test: Check the invitation, redemption status, home tenant/issuer, sign-in log, and Conditional Access. Do not create a second guest identity until you understand the existing assignment.
Guest can sign in but cannot see the resource
Authentication works, but authorization is missing. Check the group, team, site, file, or app assignment, as well as nested memberships.
Guest was removed from the team but still has file access
Direct SharePoint sharing or sharing links may still exist. Perform a resource review and revoke all relevant paths.
Guest account is inactive but still needed for business
Inactivity is a review signal, not automatic proof of redundancy. The sponsor and resource owner decide. Longer pauses can be normal for seasonal projects.
Former partner uses a new account
A person can hold multiple external identities. The sponsor, email address, and partner organization should be regularly reconciled. Old objects are removed after controlled transfer.
Controlled cleanup
1. Inventory access
- Groups and Teams,
- Enterprise Applications,
- Access Packages,
- SharePoint/OneDrive sharing,
- Roles and Administrative Units,
- direct resource permissions.
2. Interview the sponsor
Clarify business needs, contract status, and data handover.
3. Revoke access
First, remove resource and group rights. In case of a security incident, block sign-in and revoke sessions.
4. Monitor
Check for failed sign-ins or operational issues.
5. Delete guest object
When no resource or proof requirements remain, remove the guest object carefully. Retention of logs and domain-specific data must be handled separately.
Access Reviews and entitlement management
In guest scenarios, billing implications should be documented alongside functionality. External Identities is typically considered MAU-based for B2B collaboration; additional governance features for guests may also have their own MAU or add-on effects depending on the contract.
Access Reviews can periodically check group and app access. Entitlement Management can provide access packages with request, approval, expiration, and review. License requirements and guest billing must be verified using current Microsoft documentation.
The review process is described in detail in the article Access Reviews in Microsoft Entra ID.
Test catalog
- Invite a guest from an Entra partner tenant.
- Redeem the invitation with the correct identity.
- Gain access via a group.
- Access without assignment fails.
- Meet Conditional Access and MFA requirements.
- Check cross-tenant MFA trust.
- Sponsor receives review.
- Group permission is revoked.
- Direct file sharing is recognized separately.
- Guest object is deleted after cleanup.
- Audit and sign-in events are found.
- Exception or extension has an end date.
Operational metrics
- Guests without a sponsor,
- Guests without an expiration or review date,
- inactive guests with active resource permissions,
- guests in privileged groups,
- organization-specific cross-tenant trusts,
- pending invitations,
- rejected or unreviewed access reviews,
- guests without an active sign-in but with direct approval.
For the resource-side implementation in Microsoft 365, the article External Collaboration in SharePoint deepens the approval model. Regular confirmation of existing guest access is covered by Access Reviews in Microsoft Entra ID.
How to keep external identities time-limited and business-aligned
Secure external collaboration separates identity, authentication, and resource permissions. B2B and cross-tenant settings control access, while sponsors, groups, access packages, and reviews reflect business needs. Through expiration dates, logging, and a multi-stage cleanup, visible team memberships, app assignments, and file shares are jointly reviewed and removed.
When guest accounts and external access exist without clear owners or expiration dates
Then a governance model for invitations, cross-tenant access, resource permissions, reviews, and controlled removal helps. Check guest access