{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/microsoft-teams-external-versus-guest-access/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/",
        "slug": "microsoft-teams-external-versus-guest-access",
        "url": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/microsoft-teams-external-versus-guest-access/"
        },
        "title": "Choose Teams external access, guest access, or neither for each collaboration need",
        "summary": "Teams external access supports chat, calls, meetings, and separately enabled file sharing in federated chats, while guest access creates an Entra B2B identity for team and broader resource collaboration.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T21:28:15+00:00",
        "modified_at": "2026-07-19T21:28:15+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 3,
        "word_count": 563,
        "potentially_affected": "Microsoft Teams organizations collaborating with vendors, customers, partners, unmanaged Teams accounts, other Microsoft 365 tenants, or guests who need access to team resources.",
        "dse_recommendation": "Classify the collaboration need, inventory current tenant controls and guests, choose the least-access model, test cross-tenant behavior, enforce sponsorship and expiry, and audit removal.",
        "primary_source": {
            "name": "Microsoft Learn: Use guest access and external access to collaborate with people outside your organization",
            "url": "https://learn.microsoft.com/en-us/microsoftteams/communicate-with-users-from-other-organizations",
            "published_on": "2026-07-01",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source fact: what Microsoft documents</h2>\n<p>Microsoft Teams external access lets users find, chat with, call, and meet people who use supported Microsoft identities outside the organization. It does not make an external user a member of a team. Direct file upload in external or federated chats is off by default, but administrators can enable it through the Teams files policy. When enabled, files remain in the sender&#8217;s OneDrive and existing Microsoft 365, SharePoint/OneDrive, and Microsoft Entra policies continue to apply. When direct upload is disabled, users can still paste existing file links into the chat.</p>\n<p>Guest access adds an external person to a team and creates or uses a Microsoft Entra B2B guest account in the tenant. A guest can collaborate in channels, meetings, applications, and files according to Teams, Microsoft 365 Groups, SharePoint, and Entra configuration. Guests sign in to the host organization and may need to switch organizations in Teams. Microsoft notes that access can take up to 12 hours after addition.</p>\n<p><strong>Public preview:</strong> Microsoft labels automatic permission sharing for files and Loop components uploaded to external chats as public preview. Microsoft also labels guest-initiated sharing from a guest&#8217;s home-tenant OneDrive as public preview; those files remain stored in the guest&#8217;s home organization. Neither preview capability should be assumed available or treated as generally available for every tenant.</p>\n<p>Shared channels provide another external-collaboration model without the same guest-account experience. The right choice depends on identity, content, tenant, channel, and application requirements. Leaving a team does not delete the Entra guest object.</p>\n<h2>Licensing and applicability</h2>\n<p>Microsoft documents guest access for Microsoft 365 Business Standard, Enterprise, and Education subscriptions without an extra Microsoft 365 license for the guest. Microsoft Entra External ID billing and Microsoft 365 or Entra service limits still apply. Cross-cloud, government, sovereign, unmanaged-account, shared-channel, Conditional Access, sensitivity-label, compliance, and application behavior differ. Verify the source and target tenant combination.</p>\n<h2>DSE recommendation: production-safe operational steps</h2>\n<ol>\n<li>Document whether the external person needs communication only, file or Loop sharing in an external chat, or persistent team, channel, application, and content access.</li>\n<li>Inventory organization-wide external-access settings, allowed and blocked domains, unmanaged-account policy, Teams files policy, preview auto-sharing policy, guest settings, existing guest objects, team ownership, shared channels, and SharePoint and OneDrive sharing.</li>\n<li>Choose external access when federated communication and, if approved, separately enabled chat file sharing are sufficient. Use guest or shared-channel collaboration only when the documented content and membership need justifies it.</li>\n<li>Require a named internal sponsor, purpose, expected end date, approved organization, and data classification before persistent collaboration.</li>\n<li>Test sign-in, tenant switching, chat, meetings, direct upload enabled and disabled, pasted links, file permissions, applications, mobile access, Conditional Access, invitation redemption, and removal with a representative external identity.</li>\n<li>Audit guest creation and team membership, review access periodically, and notify sponsors before expiry.</li>\n<li>At the end of collaboration, remove team or channel access, revoke applicable sessions and links, and remove stale Entra guest objects according to the retention process.</li>\n</ol>\n<p>DSE recommends avoiding a tenant-wide relaxation to solve one partner&#8217;s access problem. Troubleshoot the relevant Teams, Entra, group, SharePoint, cross-tenant, and licensing layer. Document any exception with a sponsor and expiration instead of making it permanent.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/microsoftteams/communicate-with-users-from-other-organizations\" target=\"_blank\" rel=\"noopener noreferrer\">Use guest access and external access to collaborate with people outside your organization</a> — external and guest identity models, defaults, cross-cloud notes, and collaboration choices.</li>\n<li><a href=\"https://learn.microsoft.com/en-us/microsoftteams/share-files-loop-in-external-chats\" target=\"_blank\" rel=\"noopener noreferrer\">Share Files and Loop components in external chats</a> — file-policy controls, OneDrive storage, governing policies, and public-preview capabilities.</li>\n</ul>",
        "content_text": "Source fact: what Microsoft documents\nMicrosoft Teams external access lets users find, chat with, call, and meet people who use supported Microsoft identities outside the organization. It does not make an external user a member of a team. Direct file upload in external or federated chats is off by default, but administrators can enable it through the Teams files policy. When enabled, files remain in the sender’s OneDrive and existing Microsoft 365, SharePoint/OneDrive, and Microsoft Entra policies continue to apply. When direct upload is disabled, users can still paste existing file links into the chat.\nGuest access adds an external person to a team and creates or uses a Microsoft Entra B2B guest account in the tenant. A guest can collaborate in channels, meetings, applications, and files according to Teams, Microsoft 365 Groups, SharePoint, and Entra configuration. Guests sign in to the host organization and may need to switch organizations in Teams. Microsoft notes that access can take up to 12 hours after addition.\nPublic preview: Microsoft labels automatic permission sharing for files and Loop components uploaded to external chats as public preview. Microsoft also labels guest-initiated sharing from a guest’s home-tenant OneDrive as public preview; those files remain stored in the guest’s home organization. Neither preview capability should be assumed available or treated as generally available for every tenant.\nShared channels provide another external-collaboration model without the same guest-account experience. The right choice depends on identity, content, tenant, channel, and application requirements. Leaving a team does not delete the Entra guest object.\nLicensing and applicability\nMicrosoft documents guest access for Microsoft 365 Business Standard, Enterprise, and Education subscriptions without an extra Microsoft 365 license for the guest. Microsoft Entra External ID billing and Microsoft 365 or Entra service limits still apply. Cross-cloud, government, sovereign, unmanaged-account, shared-channel, Conditional Access, sensitivity-label, compliance, and application behavior differ. Verify the source and target tenant combination.\nDSE recommendation: production-safe operational steps\n\nDocument whether the external person needs communication only, file or Loop sharing in an external chat, or persistent team, channel, application, and content access.\nInventory organization-wide external-access settings, allowed and blocked domains, unmanaged-account policy, Teams files policy, preview auto-sharing policy, guest settings, existing guest objects, team ownership, shared channels, and SharePoint and OneDrive sharing.\nChoose external access when federated communication and, if approved, separately enabled chat file sharing are sufficient. Use guest or shared-channel collaboration only when the documented content and membership need justifies it.\nRequire a named internal sponsor, purpose, expected end date, approved organization, and data classification before persistent collaboration.\nTest sign-in, tenant switching, chat, meetings, direct upload enabled and disabled, pasted links, file permissions, applications, mobile access, Conditional Access, invitation redemption, and removal with a representative external identity.\nAudit guest creation and team membership, review access periodically, and notify sponsors before expiry.\nAt the end of collaboration, remove team or channel access, revoke applicable sessions and links, and remove stale Entra guest objects according to the retention process.\n\nDSE recommends avoiding a tenant-wide relaxation to solve one partner’s access problem. Troubleshoot the relevant Teams, Entra, group, SharePoint, cross-tenant, and licensing layer. Document any exception with a sponsor and expiration instead of making it permanent.\nOfficial references\n\nUse guest access and external access to collaborate with people outside your organization — external and guest identity models, defaults, cross-cloud notes, and collaboration choices.\nShare Files and Loop components in external chats — file-policy controls, OneDrive storage, governing policies, and public-preview capabilities.",
        "content_markdown": "## Source fact: what Microsoft documents\n\nMicrosoft Teams external access lets users find, chat with, call, and meet people who use supported Microsoft identities outside the organization. It does not make an external user a member of a team. Direct file upload in external or federated chats is off by default, but administrators can enable it through the Teams files policy. When enabled, files remain in the sender’s OneDrive and existing Microsoft 365, SharePoint/OneDrive, and Microsoft Entra policies continue to apply. When direct upload is disabled, users can still paste existing file links into the chat.\n\nGuest access adds an external person to a team and creates or uses a Microsoft Entra B2B guest account in the tenant. A guest can collaborate in channels, meetings, applications, and files according to Teams, Microsoft 365 Groups, SharePoint, and Entra configuration. Guests sign in to the host organization and may need to switch organizations in Teams. Microsoft notes that access can take up to 12 hours after addition.\n\nPublic preview: Microsoft labels automatic permission sharing for files and Loop components uploaded to external chats as public preview. Microsoft also labels guest-initiated sharing from a guest’s home-tenant OneDrive as public preview; those files remain stored in the guest’s home organization. Neither preview capability should be assumed available or treated as generally available for every tenant.\n\nShared channels provide another external-collaboration model without the same guest-account experience. The right choice depends on identity, content, tenant, channel, and application requirements. Leaving a team does not delete the Entra guest object.\n\n## Licensing and applicability\n\nMicrosoft documents guest access for Microsoft 365 Business Standard, Enterprise, and Education subscriptions without an extra Microsoft 365 license for the guest. Microsoft Entra External ID billing and Microsoft 365 or Entra service limits still apply. Cross-cloud, government, sovereign, unmanaged-account, shared-channel, Conditional Access, sensitivity-label, compliance, and application behavior differ. Verify the source and target tenant combination.\n\n## DSE recommendation: production-safe operational steps\n\n- Document whether the external person needs communication only, file or Loop sharing in an external chat, or persistent team, channel, application, and content access.\n\n- Inventory organization-wide external-access settings, allowed and blocked domains, unmanaged-account policy, Teams files policy, preview auto-sharing policy, guest settings, existing guest objects, team ownership, shared channels, and SharePoint and OneDrive sharing.\n\n- Choose external access when federated communication and, if approved, separately enabled chat file sharing are sufficient. Use guest or shared-channel collaboration only when the documented content and membership need justifies it.\n\n- Require a named internal sponsor, purpose, expected end date, approved organization, and data classification before persistent collaboration.\n\n- Test sign-in, tenant switching, chat, meetings, direct upload enabled and disabled, pasted links, file permissions, applications, mobile access, Conditional Access, invitation redemption, and removal with a representative external identity.\n\n- Audit guest creation and team membership, review access periodically, and notify sponsors before expiry.\n\n- At the end of collaboration, remove team or channel access, revoke applicable sessions and links, and remove stale Entra guest objects according to the retention process.\n\nDSE recommends avoiding a tenant-wide relaxation to solve one partner’s access problem. Troubleshoot the relevant Teams, Entra, group, SharePoint, cross-tenant, and licensing layer. Document any exception with a sponsor and expiration instead of making it permanent.\n\n## Official references\n\n- [Use guest access and external access to collaborate with people outside your organization](https://learn.microsoft.com/en-us/microsoftteams/communicate-with-users-from-other-organizations) — external and guest identity models, defaults, cross-cloud notes, and collaboration choices.\n\n- [Share Files and Loop components in external chats](https://learn.microsoft.com/en-us/microsoftteams/share-files-loop-in-external-chats) — file-policy controls, OneDrive storage, governing policies, and public-preview capabilities."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/",
                "url": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Choose Teams external access, guest access, or neither for each collaboration need",
                        "item": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/#article",
                "identifier": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/",
                "url": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/",
                "headline": "Choose Teams external access, guest access, or neither for each collaboration need",
                "description": "Teams external access supports chat, calls, meetings, and separately enabled file sharing in federated chats, while guest access creates an Entra B2B…",
                "abstract": "Teams external access supports chat, calls, meetings, and separately enabled file sharing in federated chats, while guest access creates an Entra B2B identity for team and broader resource collaboration.",
                "articleBody": "Source fact: what Microsoft documents\nMicrosoft Teams external access lets users find, chat with, call, and meet people who use supported Microsoft identities outside the organization. It does not make an external user a member of a team. Direct file upload in external or federated chats is off by default, but administrators can enable it through the Teams files policy. When enabled, files remain in the sender’s OneDrive and existing Microsoft 365, SharePoint/OneDrive, and Microsoft Entra policies continue to apply. When direct upload is disabled, users can still paste existing file links into the chat.\nGuest access adds an external person to a team and creates or uses a Microsoft Entra B2B guest account in the tenant. A guest can collaborate in channels, meetings, applications, and files according to Teams, Microsoft 365 Groups, SharePoint, and Entra configuration. Guests sign in to the host organization and may need to switch organizations in Teams. Microsoft notes that access can take up to 12 hours after addition.\nPublic preview: Microsoft labels automatic permission sharing for files and Loop components uploaded to external chats as public preview. Microsoft also labels guest-initiated sharing from a guest’s home-tenant OneDrive as public preview; those files remain stored in the guest’s home organization. Neither preview capability should be assumed available or treated as generally available for every tenant.\nShared channels provide another external-collaboration model without the same guest-account experience. The right choice depends on identity, content, tenant, channel, and application requirements. Leaving a team does not delete the Entra guest object.\nLicensing and applicability\nMicrosoft documents guest access for Microsoft 365 Business Standard, Enterprise, and Education subscriptions without an extra Microsoft 365 license for the guest. Microsoft Entra External ID billing and Microsoft 365 or Entra service limits still apply. Cross-cloud, government, sovereign, unmanaged-account, shared-channel, Conditional Access, sensitivity-label, compliance, and application behavior differ. Verify the source and target tenant combination.\nDSE recommendation: production-safe operational steps\n\nDocument whether the external person needs communication only, file or Loop sharing in an external chat, or persistent team, channel, application, and content access.\nInventory organization-wide external-access settings, allowed and blocked domains, unmanaged-account policy, Teams files policy, preview auto-sharing policy, guest settings, existing guest objects, team ownership, shared channels, and SharePoint and OneDrive sharing.\nChoose external access when federated communication and, if approved, separately enabled chat file sharing are sufficient. Use guest or shared-channel collaboration only when the documented content and membership need justifies it.\nRequire a named internal sponsor, purpose, expected end date, approved organization, and data classification before persistent collaboration.\nTest sign-in, tenant switching, chat, meetings, direct upload enabled and disabled, pasted links, file permissions, applications, mobile access, Conditional Access, invitation redemption, and removal with a representative external identity.\nAudit guest creation and team membership, review access periodically, and notify sponsors before expiry.\nAt the end of collaboration, remove team or channel access, revoke applicable sessions and links, and remove stale Entra guest objects according to the retention process.\n\nDSE recommends avoiding a tenant-wide relaxation to solve one partner’s access problem. Troubleshoot the relevant Teams, Entra, group, SharePoint, cross-tenant, and licensing layer. Document any exception with a sponsor and expiration instead of making it permanent.\nOfficial references\n\nUse guest access and external access to collaborate with people outside your organization — external and guest identity models, defaults, cross-cloud notes, and collaboration choices.\nShare Files and Loop components in external chats — file-policy controls, OneDrive storage, governing policies, and public-preview capabilities.",
                "datePublished": "2026-07-19T21:28:15+00:00",
                "dateModified": "2026-07-19T21:28:15+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/microsoft-teams-external-versus-guest-access/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 563,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Learn: Use guest access and external access to collaborate with people outside your organization",
                    "url": "https://learn.microsoft.com/en-us/microsoftteams/communicate-with-users-from-other-organizations",
                    "datePublished": "2026-07-01"
                }
            }
        ]
    }
}