Choose Teams external access, guest access, or neither for each collaboration need

Teams external access supports chat, calls, meetings, and separately enabled file sharing in federated chats, while guest access creates an Entra B2B identity for team and broader resource collaboration.

Executive summary

What you need to know

Teams external access supports chat, calls, meetings, and separately enabled file sharing in federated chats, while guest access creates an Entra B2B identity for team and broader resource collaboration.

Potentially affected

Microsoft Teams organizations collaborating with vendors, customers, partners, unmanaged Teams accounts, other Microsoft 365 tenants, or guests who need access to team resources.

DSE recommendation

Classify the collaboration need, inventory current tenant controls and guests, choose the least-access model, test cross-tenant behavior, enforce sponsorship and expiry, and audit removal.

Source fact: what Microsoft documents

Microsoft Teams external access lets users find, chat with, call, and meet people who use supported Microsoft identities outside the organization. It does not make an external user a member of a team. Direct file upload in external or federated chats is off by default, but administrators can enable it through the Teams files policy. When enabled, files remain in the sender’s OneDrive and existing Microsoft 365, SharePoint/OneDrive, and Microsoft Entra policies continue to apply. When direct upload is disabled, users can still paste existing file links into the chat.

Guest access adds an external person to a team and creates or uses a Microsoft Entra B2B guest account in the tenant. A guest can collaborate in channels, meetings, applications, and files according to Teams, Microsoft 365 Groups, SharePoint, and Entra configuration. Guests sign in to the host organization and may need to switch organizations in Teams. Microsoft notes that access can take up to 12 hours after addition.

Public preview: Microsoft labels automatic permission sharing for files and Loop components uploaded to external chats as public preview. Microsoft also labels guest-initiated sharing from a guest’s home-tenant OneDrive as public preview; those files remain stored in the guest’s home organization. Neither preview capability should be assumed available or treated as generally available for every tenant.

Shared channels provide another external-collaboration model without the same guest-account experience. The right choice depends on identity, content, tenant, channel, and application requirements. Leaving a team does not delete the Entra guest object.

Licensing and applicability

Microsoft documents guest access for Microsoft 365 Business Standard, Enterprise, and Education subscriptions without an extra Microsoft 365 license for the guest. Microsoft Entra External ID billing and Microsoft 365 or Entra service limits still apply. Cross-cloud, government, sovereign, unmanaged-account, shared-channel, Conditional Access, sensitivity-label, compliance, and application behavior differ. Verify the source and target tenant combination.

DSE recommendation: production-safe operational steps

  1. Document whether the external person needs communication only, file or Loop sharing in an external chat, or persistent team, channel, application, and content access.
  2. Inventory organization-wide external-access settings, allowed and blocked domains, unmanaged-account policy, Teams files policy, preview auto-sharing policy, guest settings, existing guest objects, team ownership, shared channels, and SharePoint and OneDrive sharing.
  3. Choose external access when federated communication and, if approved, separately enabled chat file sharing are sufficient. Use guest or shared-channel collaboration only when the documented content and membership need justifies it.
  4. Require a named internal sponsor, purpose, expected end date, approved organization, and data classification before persistent collaboration.
  5. Test sign-in, tenant switching, chat, meetings, direct upload enabled and disabled, pasted links, file permissions, applications, mobile access, Conditional Access, invitation redemption, and removal with a representative external identity.
  6. Audit guest creation and team membership, review access periodically, and notify sponsors before expiry.
  7. At the end of collaboration, remove team or channel access, revoke applicable sessions and links, and remove stale Entra guest objects according to the retention process.

DSE recommends avoiding a tenant-wide relaxation to solve one partner’s access problem. Troubleshoot the relevant Teams, Entra, group, SharePoint, cross-tenant, and licensing layer. Document any exception with a sponsor and expiration instead of making it permanent.

Official references

Primary reference

Review the official source

Microsoft Learn: Use guest access and external access to collaborate with people outside your organization · Published July 1, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE