Microsoft 365 guest access: how to share with outsiders without leaving data exposed
Most small businesses don’t work alone. An accountancy practice swaps files with clients every week. An engineering firm shares drawings with subcontractors. A charity works on documents with trustees and funders. A biotech on a science park sends data to a contract research lab. Almost all of it runs through SharePoint, OneDrive and Teams.
That makes Microsoft 365 guest access for small businesses one of the quietest risks in the tenant. Every invite is reasonable on the day it’s sent. Two years later, nobody can say who still has access to the old client project site, or why a contractor who finished in the spring can still open the pricing folder.
Why SMEs share so much (and why it builds up)
Small firms run on relationships. Clients want to see drafts. Suppliers need specifications. Contractors, consultants and freelancers come and go with each project. Accountants, lawyers and auditors need a folder at year end.
Each relationship needs somewhere to share files, and Microsoft 365 is already open on everyone’s laptop. So SharePoint external sharing for a small business grows one invite at a time: a guest here, a link there, a Teams channel for “just this job”.
The result is predictable. The same tenant that holds your contracts, payroll and client records also holds dozens of outside identities that your team did not create and cannot easily see. That’s not a reason to stop sharing. It’s a reason to share on purpose.
Guest vs member vs “someone’s personal OneDrive link”
Not every external share is the same thing, and the differences matter.
Entra B2B guests. When you invite someone to a site or a team, Microsoft creates a guest account in your directory. According to Microsoft’s B2B collaboration overview, the guest signs in with their own organisation’s credentials, and their account shows up with #EXT# in its user name. Your Conditional Access policies can apply to them. That is the controllable option.
Members. Your own staff. Occasionally a long-term contractor is given a full member account. That can be right, but it means joiner and leaver processes must treat them like an employee.
Specific-people links. A file or folder shared with a named external address. The recipient has to prove who they are, and with Entra B2B integration switched on, a guest account is created behind the scenes, per Microsoft’s SharePoint sharing settings guide.
Anyone links. No sign-in required. The same guide is blunt: forwarded Anyone links work for anyone, and you can’t track who has access or who opened the item. Fine for a public price list. Not fine for a client’s HR file.
Then there’s where the share starts. A file shared from someone’s OneDrive belongs to that person, not the business. Microsoft notes that OneDrive’s default site-level sharing setting is Anyone, while group-connected sites follow your Groups guest settings (site sharing defaults). When that person leaves, the project’s history goes with their account. A project or client site keeps the data with the company.
MFA, expiry and least privilege for external users
Guests should meet the same bar as staff. For guest MFA, the tool is Conditional Access: a policy scoped to guest and external users that requires MFA or a stronger authentication strength. Microsoft’s authentication strength guidance for external users walks through it and recommends starting in report-only mode. You can also decide whether to trust MFA completed in the partner’s own tenant. If you’re tidying your own sign-in methods at the same time, our note on SMS MFA retirement covers that side.
Next, expiry. SharePoint can automatically expire guest access to a site or OneDrive after a set number of days, at organisation level or per site. Three details catch people out, all from Microsoft’s page on managing guest expiration:
So SharePoint guest expiry is a useful backstop, not a clean-up tool.
For Anyone links, you can make every link expire within a maximum number of days and limit them to view-only. Shorten the limit and existing links shrink to match; lengthen it and existing links keep their current expiry.
Finally, reviews. Microsoft Entra access reviews for guests ask a group owner, or the guest themselves, to confirm that access is still needed. Denied guests can be blocked from signing in and then deleted from the tenant after 30 days. The catch is licensing: access reviews need Microsoft Entra ID P2 or Entra ID Governance. Without those, the same review can be run by hand. It just needs an owner.
Site design that contains risk
The cheapest control is structure. Give each client, project or partner its own named site or team: one client, one site. One subcontract, one team. Invite guests there and nowhere else.
That keeps the damage small if something goes wrong. A guest on “Client A – 2026 audit” sees that client’s files, not the whole intranet. Access reviews map neatly onto the group behind the site. When the work ends, you know exactly what to close.
For Teams external access, remember there are two different features. Microsoft’s Teams guidance separates external access, which lets you chat and meet with other organisations but not share files, from guest access, which adds a person to a team with a guest account. If a supplier only needs calls and chat, external access is enough. Don’t hand out a team membership for a weekly catch-up.
Sensitivity labels are an optional next step. They can mark a site as confidential and control guest sharing on it. Get the site structure right first. A label on a sprawling site is lipstick on a filing cabinet.
What to revoke when a project or contractor ends
Project end dates are rarely written into IT. Make them. When a client engagement closes or a contractor leaves:
Step six is what turns a contractor access review from archaeology into a quick check.
Evidence customers and insurers ask for on external access
Larger customers, insurers and supplier questionnaires increasingly ask how you control outsiders in your tenant. In regulated sectors such as life sciences it’s standard, and our guide to supplier questionnaires covers the wider pack. For external access specifically, useful evidence is simple:
Keep it next to your backup evidence. People tend to ask for both in the same breath.
When managed IT should own the guest-review calendar
Guest sprawl isn’t a technology failure. It’s a calendar failure. Settings drift, projects end quietly and nobody books the review.
A quarterly access review is a practical rhythm for most small businesses. Export the guest list, confirm owners, remove what’s stale, check sharing settings still match policy, and file the evidence. It takes an hour when done regularly and a week when done after an audit request.
CAMBITION is a Cambridge MSP founded in 2012, and we have assisted 250+ clients. We run this under managed IT, with cyber security and compliance facilitation alongside, so the review happens whether or not a questionnaire is due.
A short fit call is enough to look at your live guest sprawl and set up a quarterly review. Call 01223 656 156 or get in touch. We help small businesses share with clients and partners without leaving the door open.
Frequently asked questions
Does SharePoint guest expiration remove existing guests?
No. Microsoft says the policy only applies to guests given access after it is switched on, and expiring site access doesn’t change the guest account itself.
What is the difference between Teams external access and guest access?
External access lets you chat, call and meet with people in other organisations but not share files. Guest access adds them to a team with a guest account in your directory, including file access.
Can a small business force guests to use MFA in Microsoft 365?
Yes. A Conditional Access policy scoped to guest and external users can require MFA or a stronger authentication strength. You can also choose whether to trust MFA completed in the partner’s own tenant.
Do Entra access reviews need a special licence?
Yes. Microsoft lists Microsoft Entra ID P2 or Microsoft Entra ID Governance as prerequisites. Without them, run the same quarterly review manually and keep the records.
© CAMBITION I.T. Services Ltd
Head Office
Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridgeshire, CB22 7RG
VAT# 136 186 313 · Registered in the UK # 808 4429
View Privacy / Data Protection / Cookie Statement · Terms
Microsoft 365 guest access: how to share with outsiders without leaving data exposed
Most small businesses don’t work alone. An accountancy practice swaps files with clients every week. An engineering firm shares drawings with subcontractors. A charity works on documents with trustees and funders. A biotech on a science park sends data to a contract research lab. Almost all of it runs through SharePoint, OneDrive and Teams.
That makes Microsoft 365 guest access for small businesses one of the quietest risks in the tenant. Every invite is reasonable on the day it’s sent. Two years later, nobody can say who still has access to the old client project site, or why a contractor who finished in the spring can still open the pricing folder.
Why SMEs share so much (and why it builds up)
Small firms run on relationships. Clients want to see drafts. Suppliers need specifications. Contractors, consultants and freelancers come and go with each project. Accountants, lawyers and auditors need a folder at year end.
Each relationship needs somewhere to share files, and Microsoft 365 is already open on everyone’s laptop. So SharePoint external sharing for a small business grows one invite at a time: a guest here, a link there, a Teams channel for “just this job”.
The result is predictable. The same tenant that holds your contracts, payroll and client records also holds dozens of outside identities that your team did not create and cannot easily see. That’s not a reason to stop sharing. It’s a reason to share on purpose.
Guest vs member vs “someone’s personal OneDrive link”
Not every external share is the same thing, and the differences matter.
Entra B2B guests. When you invite someone to a site or a team, Microsoft creates a guest account in your directory. According to Microsoft’s B2B collaboration overview, the guest signs in with their own organisation’s credentials, and their account shows up with #EXT# in its user name. Your Conditional Access policies can apply to them. That is the controllable option.
Members. Your own staff. Occasionally a long-term contractor is given a full member account. That can be right, but it means joiner and leaver processes must treat them like an employee.
Specific-people links. A file or folder shared with a named external address. The recipient has to prove who they are, and with Entra B2B integration switched on, a guest account is created behind the scenes, per Microsoft’s SharePoint sharing settings guide.
Anyone links. No sign-in required. The same guide is blunt: forwarded Anyone links work for anyone, and you can’t track who has access or who opened the item. Fine for a public price list. Not fine for a client’s HR file.
Then there’s where the share starts. A file shared from someone’s OneDrive belongs to that person, not the business. Microsoft notes that OneDrive’s default site-level sharing setting is Anyone, while group-connected sites follow your Groups guest settings (site sharing defaults). When that person leaves, the project’s history goes with their account. A project or client site keeps the data with the company.
MFA, expiry and least privilege for external users
Guests should meet the same bar as staff. For guest MFA, the tool is Conditional Access: a policy scoped to guest and external users that requires MFA or a stronger authentication strength. Microsoft’s authentication strength guidance for external users walks through it and recommends starting in report-only mode. You can also decide whether to trust MFA completed in the partner’s own tenant. If you’re tidying your own sign-in methods at the same time, our note on SMS MFA retirement covers that side.
Next, expiry. SharePoint can automatically expire guest access to a site or OneDrive after a set number of days, at organisation level or per site. Three details catch people out, all from Microsoft’s page on managing guest expiration:
So SharePoint guest expiry is a useful backstop, not a clean-up tool.
For Anyone links, you can make every link expire within a maximum number of days and limit them to view-only. Shorten the limit and existing links shrink to match; lengthen it and existing links keep their current expiry.
Finally, reviews. Microsoft Entra access reviews for guests ask a group owner, or the guest themselves, to confirm that access is still needed. Denied guests can be blocked from signing in and then deleted from the tenant after 30 days. The catch is licensing: access reviews need Microsoft Entra ID P2 or Entra ID Governance. Without those, the same review can be run by hand. It just needs an owner.
Site design that contains risk
The cheapest control is structure. Give each client, project or partner its own named site or team: one client, one site. One subcontract, one team. Invite guests there and nowhere else.
That keeps the damage small if something goes wrong. A guest on “Client A – 2026 audit” sees that client’s files, not the whole intranet. Access reviews map neatly onto the group behind the site. When the work ends, you know exactly what to close.
For Teams external access, remember there are two different features. Microsoft’s Teams guidance separates external access, which lets you chat and meet with other organisations but not share files, from guest access, which adds a person to a team with a guest account. If a supplier only needs calls and chat, external access is enough. Don’t hand out a team membership for a weekly catch-up.
Sensitivity labels are an optional next step. They can mark a site as confidential and control guest sharing on it. Get the site structure right first. A label on a sprawling site is lipstick on a filing cabinet.
What to revoke when a project or contractor ends
Project end dates are rarely written into IT. Make them. When a client engagement closes or a contractor leaves:
Step six is what turns a contractor access review from archaeology into a quick check.
Evidence customers and insurers ask for on external access
Larger customers, insurers and supplier questionnaires increasingly ask how you control outsiders in your tenant. In regulated sectors such as life sciences it’s standard, and our guide to supplier questionnaires covers the wider pack. For external access specifically, useful evidence is simple:
Keep it next to your backup evidence. People tend to ask for both in the same breath.
When managed IT should own the guest-review calendar
Guest sprawl isn’t a technology failure. It’s a calendar failure. Settings drift, projects end quietly and nobody books the review.
A quarterly access review is a practical rhythm for most small businesses. Export the guest list, confirm owners, remove what’s stale, check sharing settings still match policy, and file the evidence. It takes an hour when done regularly and a week when done after an audit request.
CAMBITION is a Cambridge MSP founded in 2012, and we have assisted 250+ clients. We run this under managed IT, with cyber security and compliance facilitation alongside, so the review happens whether or not a questionnaire is due.
A short fit call is enough to look at your live guest sprawl and set up a quarterly review. Call 01223 656 156 or get in touch. We help small businesses share with clients and partners without leaving the door open.
Frequently asked questions
Does SharePoint guest expiration remove existing guests?
No. Microsoft says the policy only applies to guests given access after it is switched on, and expiring site access doesn’t change the guest account itself.
What is the difference between Teams external access and guest access?
External access lets you chat, call and meet with people in other organisations but not share files. Guest access adds them to a team with a guest account in your directory, including file access.
Can a small business force guests to use MFA in Microsoft 365?
Yes. A Conditional Access policy scoped to guest and external users can require MFA or a stronger authentication strength. You can also choose whether to trust MFA completed in the partner’s own tenant.
Do Entra access reviews need a special licence?
Yes. Microsoft lists Microsoft Entra ID P2 or Microsoft Entra ID Governance as prerequisites. Without them, run the same quarterly review manually and keep the records.
© CAMBITION I.T. Services Ltd
Head Office
Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridgeshire, CB22 7RG
VAT# 136 186 313 · Registered in the UK # 808 4429
View Privacy / Data Protection / Cookie Statement · Terms
Most small businesses don’t work alone. An accountancy practice swaps files with clients every week. An engineering firm shares drawings with subcontractors. A charity works on documents with trustees and funders. A biotech on a science park sends data to a contract research lab. Almost all of it runs through SharePoint, OneDrive and Teams.
That makes Microsoft 365 guest access for small businesses one of the quietest risks in the tenant. Every invite is reasonable on the day it’s sent. Two years later, nobody can say who still has access to the old client project site, or why a contractor who finished in the spring can still open the pricing folder.
Small firms run on relationships. Clients want to see drafts. Suppliers need specifications. Contractors, consultants and freelancers come and go with each project. Accountants, lawyers and auditors need a folder at year end.
Each relationship needs somewhere to share files, and Microsoft 365 is already open on everyone’s laptop. So SharePoint external sharing for a small business grows one invite at a time: a guest here, a link there, a Teams channel for “just this job”.
The result is predictable. The same tenant that holds your contracts, payroll and client records also holds dozens of outside identities that your team did not create and cannot easily see. That’s not a reason to stop sharing. It’s a reason to share on purpose.
Not every external share is the same thing, and the differences matter.
Entra B2B guests. When you invite someone to a site or a team, Microsoft creates a guest account in your directory. According to Microsoft’s B2B collaboration overview, the guest signs in with their own organisation’s credentials, and their account shows up with #EXT# in its user name. Your Conditional Access policies can apply to them. That is the controllable option.
Members. Your own staff. Occasionally a long-term contractor is given a full member account. That can be right, but it means joiner and leaver processes must treat them like an employee.
Specific-people links. A file or folder shared with a named external address. The recipient has to prove who they are, and with Entra B2B integration switched on, a guest account is created behind the scenes, per Microsoft’s SharePoint sharing settings guide.
Anyone links. No sign-in required. The same guide is blunt: forwarded Anyone links work for anyone, and you can’t track who has access or who opened the item. Fine for a public price list. Not fine for a client’s HR file.
Then there’s where the share starts. A file shared from someone’s OneDrive belongs to that person, not the business. Microsoft notes that OneDrive’s default site-level sharing setting is Anyone, while group-connected sites follow your Groups guest settings (site sharing defaults). When that person leaves, the project’s history goes with their account. A project or client site keeps the data with the company.
Guests should meet the same bar as staff. For guest MFA, the tool is Conditional Access: a policy scoped to guest and external users that requires MFA or a stronger authentication strength. Microsoft’s authentication strength guidance for external users walks through it and recommends starting in report-only mode. You can also decide whether to trust MFA completed in the partner’s own tenant. If you’re tidying your own sign-in methods at the same time, our note on SMS MFA retirement covers that side.
Next, expiry. SharePoint can automatically expire guest access to a site or OneDrive after a set number of days, at organisation level or per site. Three details catch people out, all from Microsoft’s page on managing guest expiration:
So SharePoint guest expiry is a useful backstop, not a clean-up tool.
For Anyone links, you can make every link expire within a maximum number of days and limit them to view-only. Shorten the limit and existing links shrink to match; lengthen it and existing links keep their current expiry.
Finally, reviews. Microsoft Entra access reviews for guests ask a group owner, or the guest themselves, to confirm that access is still needed. Denied guests can be blocked from signing in and then deleted from the tenant after 30 days. The catch is licensing: access reviews need Microsoft Entra ID P2 or Entra ID Governance. Without those, the same review can be run by hand. It just needs an owner.
The cheapest control is structure. Give each client, project or partner its own named site or team: one client, one site. One subcontract, one team. Invite guests there and nowhere else.
That keeps the damage small if something goes wrong. A guest on “Client A – 2026 audit” sees that client’s files, not the whole intranet. Access reviews map neatly onto the group behind the site. When the work ends, you know exactly what to close.
For Teams external access, remember there are two different features. Microsoft’s Teams guidance separates external access, which lets you chat and meet with other organisations but not share files, from guest access, which adds a person to a team with a guest account. If a supplier only needs calls and chat, external access is enough. Don’t hand out a team membership for a weekly catch-up.
Sensitivity labels are an optional next step. They can mark a site as confidential and control guest sharing on it. Get the site structure right first. A label on a sprawling site is lipstick on a filing cabinet.
Project end dates are rarely written into IT. Make them. When a client engagement closes or a contractor leaves:
Step six is what turns a contractor access review from archaeology into a quick check.
Larger customers, insurers and supplier questionnaires increasingly ask how you control outsiders in your tenant. In regulated sectors such as life sciences it’s standard, and our guide to supplier questionnaires covers the wider pack. For external access specifically, useful evidence is simple:
Keep it next to your backup evidence. People tend to ask for both in the same breath.
Guest sprawl isn’t a technology failure. It’s a calendar failure. Settings drift, projects end quietly and nobody books the review.
A quarterly access review is a practical rhythm for most small businesses. Export the guest list, confirm owners, remove what’s stale, check sharing settings still match policy, and file the evidence. It takes an hour when done regularly and a week when done after an audit request.
CAMBITION is a Cambridge MSP founded in 2012, and we have assisted 250+ clients. We run this under managed IT, with cyber security and compliance facilitation alongside, so the review happens whether or not a questionnaire is due.
A short fit call is enough to look at your live guest sprawl and set up a quarterly review. Call 01223 656 156 or get in touch. We help small businesses share with clients and partners without leaving the door open.
No. Microsoft says the policy only applies to guests given access after it is switched on, and expiring site access doesn’t change the guest account itself.
External access lets you chat, call and meet with people in other organisations but not share files. Guest access adds them to a team with a guest account in your directory, including file access.
Yes. A Conditional Access policy scoped to guest and external users can require MFA or a stronger authentication strength. You can also choose whether to trust MFA completed in the partner’s own tenant.
Yes. Microsoft lists Microsoft Entra ID P2 or Microsoft Entra ID Governance as prerequisites. Without them, run the same quarterly review manually and keep the records.
© CAMBITION I.T. Services Ltd
Head Office
Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridgeshire, CB22 7RG
VAT# 136 186 313 · Registered in the UK # 808 4429
View Privacy / Data Protection / Cookie Statement · Terms