Microsoft 365

Teams external access vs guest access: settings, risks and a sane default

Understand what Teams external access and guest access each allow, where the settings live in Teams, Entra ID and SharePoint, and a defensible baseline.

12 min read
On this page

Teams external access lets your users chat, call and meet with people in other organizations who keep their own identity, while guest access brings an outsider into your directory as an Entra ID B2B guest so they can join teams, channels and files. A sensible default for most organizations is to keep external access on but block known-bad domains, unmanaged-account inbound contact and trial-only tenants, and to keep guest access on with invitations limited to members, restricted guest directory visibility and recurring access reviews.

Who this is for and what you will have at the end

This guide is for Microsoft 365 and Teams administrators who need to decide how people outside the organization can reach their users, and who want the setting locations for both features in one place. At the end you will have:

  • A clear picture of what each feature allows, and where shared channels fit.
  • External access configured at the organization level, with optional per-user policies.
  • Guest access configured across Entra ID, Microsoft 365 Groups, Teams and SharePoint.
  • A verification routine and fixes for the most common "they can't reach us" tickets.

External access, guest access and shared channels compared

Microsoft 365 gives you three Teams-level ways to work with outsiders. External access and guest access are covered in depth here; shared channels use Entra B2B direct connect and are worth knowing about because they often replace guests for partner organizations.

CapabilityExternal accessGuest accessShared channels (B2B direct connect)
Identity usedTheir own home accountA guest account in your directoryTheir own home account
Account created in your Entra IDNoYesNo
1:1 and group chatYesYesChannel conversations
Calls and meetingsYesYes-
Access to your teams and filesNoYesOnly the shared channel
Find people by searchOnly by email or SIP addressNo-
Needs switching organizations in TeamsNoYesNo
Works with consumer accountsUnmanaged Teams accountsYes, any business or consumer emailNo, Entra ID organizations only
Extra admin setupTeams admin centerEntra ID, Microsoft 365 Groups, Teams, SharePointEntra cross-tenant access settings in both tenants

A dash means Microsoft's comparison doesn't cover that row for shared channels. Some practical consequences from the comparison: with external access your users can't share files and can't see the external person's out-of-office message; guests can. People outside the organization reached through external access can't use Meet now and can't see the phone numbers of dial-in participants by default. Several chat features (editing and deleting sent messages, Giphy, stickers, screen sharing in chat) are supported for external access only in 1:1 chats between Teams-only users in two different organizations.

Skype consumer interoperability with Teams ended on May 5, 2025, and the associated policies, including the AllowPublicUsers parameter, are deprecated. External access now covers other Microsoft 365 organizations and unmanaged Teams accounts.

Risks to weigh

Open federation. The default, Allow all external domains, means anyone in any Microsoft 365 tenant that also allows federation can find your users by email address and start a chat. That is convenient for sales and support, but those messages arrive in Teams rather than passing through your email filtering, so they are a possible phishing channel.

Unmanaged Teams accounts. People using Teams with a personal Microsoft account can, by default, discover and start conversations with your users. Anyone can create one with a personal Microsoft account.

Trial-only tenants. Tenants that have only trial subscriptions and no purchased licences are easy to create and hard to attribute. Microsoft blocks them by default through ExternalAccessWithTrialTenants; confirm nobody has changed it.

Guest sprawl. Every guest is a directory object with access to whatever teams and sites it was added to. Leaving a team doesn't remove the guest account; an admin has to delete it. Without reviews, guests accumulate long after projects end.

File exposure. Guests reach SharePoint content through the team. If SharePoint organization-level sharing is set to Anyone, users can also send unauthenticated links, which is a separate risk from guest access itself.

A sane default

This baseline suits most commercial tenants. Tighten it for regulated environments.

AreaRecommended setting
Teams external organizationsAllow all, with a maintained block list; or allow only named partner domains in regulated tenants
Unmanaged Teams accountsAllow your users to start chats if needed; turn off inbound contact from unmanaged accounts
Trial-only tenantsBlocked (the default)
Block specific usersTurn on when you need to stop a named external sender
Teams guest accessOn
Entra guest invite settingsMember users and users assigned to specific admin roles can invite, or admins plus the Guest Inviter role only
Entra guest user accessGuest users have limited access to properties and memberships of directory objects (the default), or the most restrictive option
SharePoint external sharingNew and existing guests, unless you need Anyone links
LifecycleRecurring Entra access reviews for guests; sensitivity labels to block guests on confidential teams

Guests are B2B users in your directory, so your Conditional Access and MFA policies can target them the same way they target staff. People reached through external access sign in with their home organization's identity and have no account in your directory. The zero trust remote access architecture covers how those controls fit into a wider design.

Prerequisites

  • Access to the Teams admin center, the Microsoft Entra admin center and the SharePoint admin center.
  • For Entra external collaboration settings, a role that can update them, such as External Identity Provider Administrator (Global Administrator also works but should be reserved for emergencies).
  • The MicrosoftTeams PowerShell module, version 6.4.0 or later if you want to manage trial-tenant settings from PowerShell.

Configure external access

Organization settings

  1. In the Teams admin center, go to Users > External access.
  2. Next to Teams and Skype for Business users in external organizations, choose one of: allow all external domains, Allow only specific external domains, Block only specific external domains, or block all external domains.
  3. If you choose an allow or block list, add domains with Add external domains or Block external domains, then select Done.
  4. Turn People in my organization can communicate with unmanaged Teams accounts on or off. If it's on, decide whether to select External users with Teams accounts not managed by an organization can contact users in my organization. With that checkbox cleared, unmanaged users can't find your users by email address, and your users must start every conversation.
  5. Optionally turn on Block specific users from communicating with people in my organization, then add up to 200 individual addresses with Block a user.
  6. Select Save.

Blocking a domain doesn't block its subdomains unless you also set BlockAllSubdomains. People from blocked domains can still join meetings anonymously if anonymous join is allowed, so review meeting settings at the same time.

The same settings are available in PowerShell:

Connect-MicrosoftTeams
 
# Review current tenant federation settings
Get-CsTenantFederationConfiguration
 
# Add a domain to the block list, then block subdomains of every blocked domain
$x = New-CsEdgeDomainPattern -Domain 'fabrikam.com'
Set-CsTenantFederationConfiguration -BlockedDomains @{Add=$x}
Set-CsTenantFederationConfiguration -BlockAllSubdomains $true
 
# Let users start chats with unmanaged Teams accounts, but block inbound contact
Set-CsTenantFederationConfiguration -AllowTeamsConsumer $true -AllowTeamsConsumerInbound $false
 
# Keep trial-only tenants blocked
Set-CsTenantFederationConfiguration -ExternalAccessWithTrialTenants 'Blocked'

To switch to an allow list instead, replace the allowed domains with a list object. The AllowedDomains and BlockedDomains parameters each support up to 4,000 domains.

$allowed = New-Object Collections.Generic.List[String]
$allowed.Add('contoso.com')
$allowed.Add('fabrikam.com')
Set-CsTenantFederationConfiguration -AllowedDomainsAsAList $allowed

AllowFederatedUsers is the master switch. If it's $false, nobody can federate regardless of domain lists or policies.

User policies

Both the organization setting and the user's external access policy must allow a feature before that user can use it. To limit federation to specific people, turn the control off in the Global (org-wide default) policy and assign a custom policy to the users who need it:

Set-CsExternalAccessPolicy -EnableFederationAccess $false
New-CsExternalAccessPolicy -Identity PartnerFacing -EnableFederationAccess $true
New-CsBatchPolicyAssignmentOperation -PolicyType ExternalAccessPolicy -PolicyName 'PartnerFacing' -Identity @('megan@contoso.com', 'alex@contoso.com')

Custom policies can also carry their own domain lists through -CommunicationWithExternalOrgs with AllowSpecificExternalDomains or BlockSpecificExternalDomains, limited to 100 domains per list. The org-wide default policy always uses the organization settings.

Configure guest access

Guest access depends on four layers. The most restrictive one wins, so check all four.

1. Microsoft Entra external collaboration settings

In the Microsoft Entra admin center, go to Entra ID > External Identities > External collaboration settings.

  • Under Guest user access, keep Guest users have limited access to properties and memberships of directory objects (the default) or choose Guest user access is restricted to properties and memberships of their own directory objects if guests from different companies shouldn't see each other.
  • Under Guest invite settings, the default lets everyone, including guests, invite guests. Choose Member users and users assigned to specific admin roles can invite guest users including guests with member permissions, or Only users assigned to specific admin roles can invite guest users and give named people the Guest Inviter role.
  • Under Collaboration restrictions, allow or deny invitations to specific domains.

For partner tenants that use Entra ID, also review cross-tenant access settings for inbound and outbound B2B collaboration. If you are consolidating tenants rather than collaborating, the Microsoft 365 tenant-to-tenant migration architecture is the better pattern.

2. Microsoft 365 Groups

In the Microsoft 365 admin center, go to Settings > Org settings > Microsoft 365 Groups and make sure both Let group owners add people outside your organization to Microsoft 365 Groups as guests and Let guest group members access group content are checked. Teams membership is built on these groups.

3. Teams

  1. In the Teams admin center, go to Users > Guest access.
  2. Set Guest access to On.
  3. Under Calling, Meeting and Messaging, decide what guests can do, for example Make private calls, Video conferencing, Screen sharing, Meet now in channels, Edit sent messages, Delete sent messages and Chat.
  4. Select Save.

The equivalent tenant switch in PowerShell is Set-CsTeamsClientConfiguration -Identity Global -AllowGuestUser $true. Allow up to 24 hours for the setting to take effect. Turning guest access off later removes guests' access to their teams without removing them from the teams.

4. SharePoint

In the SharePoint admin center, go to Policies > Sharing and set external sharing to New and existing guests (or Anyone if you accept unauthenticated links). Site-level settings can't be more permissive than this. For a sensitive team, set the team site to a stricter level under Sites > Active sites > the site > Settings > More sharing settings, or use a sensitivity label that blocks guests.

Verification

  1. From a test account in a partner tenant, search for one of your users by email and send a chat. Then repeat from a blocked domain and confirm it fails.
  2. From a personal Microsoft account in Teams, try to start a chat with your user. With inbound contact turned off, the search should not find them.
  3. Invite a test guest to a pilot team. Confirm the invitation arrives, the guest can redeem it, and after switching organizations in Teams they see the team. Check that the guest appears with the (Guest) label.
  4. In Entra ID, check the audit log for the Added member to group activity that Teams records when a guest is added.
  5. Run Get-CsTenantFederationConfiguration and Get-CsExternalAccessPolicy and keep the output with your change record.

Troubleshooting

External chat doesn't work in one direction. Federation must be allowed on both sides. The other organization has to trust your domain and enable external access for its users; otherwise its users can't chat with yours and join your meetings as anonymous participants. Microsoft provides a diagnostic in the Microsoft 365 admin center that checks a user's SIP address against a federated tenant's domain.

A user can chat externally but a colleague can't. Check the external access policy assigned to each user. A custom policy can override the organization's domain lists.

Domain allowed, but still blocked. Confirm AllowFederatedUsers is $true. When it's $false, domain lists and policies are ignored.

Guest can't be added or never gets access. Work through the four layers above: Entra invite settings and collaboration restrictions, Microsoft 365 Groups guest settings, Teams guest access, and SharePoint sharing. Remember the up to 12-hour delay after adding a guest. Microsoft 365 admin center also has a guest access diagnostic.

Guests from a partner using a work account can't be invited by alias. Invite guests with work or school accounts by their user principal name; other address formats aren't supported.

Messages from a trial tenant disappeared. With ExternalAccessWithTrialTenants set to Blocked, users from trial-only tenants are removed from existing chats. Add specific trusted trial domains with AllowedTrialTenantDomains if needed.

Checklist

  • Decided which partner scenarios use external access, guests or shared channels.
  • External access domain policy set (block list or allow list) and subdomain blocking reviewed.
  • Inbound contact from unmanaged Teams accounts turned off unless required.
  • Trial-only tenants still blocked.
  • Entra guest invite settings limited, guest directory access restricted, domain restrictions reviewed.
  • Microsoft 365 Groups, Teams and SharePoint guest settings aligned.
  • Conditional Access applied to guests.
  • Recurring access reviews scheduled for guests; sensitivity labels applied to confidential teams.

References

Questions people ask

What is the difference between external access and guest access in Teams?

External access (federation) lets your users find, chat, call and meet with people in other Microsoft 365 organizations and with unmanaged Teams accounts, using their own identities and without access to your teams or files. Guest access adds a person to your directory as a Microsoft Entra B2B collaboration guest, so they can be a member of a team and work in its channels and files.

Is external access in Teams on by default?

Yes. By default, Teams allows external access with all external domains, and the org-wide setting and user policies for external access are turned on. Communication with tenants that hold only trial licences is blocked by default.

Do guests in Teams need a Microsoft 365 licence?

No extra Microsoft 365 licence is needed for guests. Guest access works with Microsoft 365 Business Standard, Enterprise and Education subscriptions, and the Microsoft Entra External ID billing model applies to guests.

Why can a guest not see a team right after being added?

After a guest is added to a team, it can take up to 12 hours for them to have access, and after turning guest access on in Teams the setting can take up to 24 hours to become active. The guest also has to accept the invitation and switch to your organization in Teams.

Microsoft TeamsTeams admin centerEntra ID B2BGuest accessSharePoint Online
  1. SharePoint Online external sharing settings at tenant and site level

    Configure SharePoint and OneDrive guest sharing end to end: Entra B2B invite settings, tenant and site sharing levels, domain limits, Anyone link expiry and guest access expiration.

    Microsoft 36513 min read
  2. Microsoft 365 suites with and without Teams: licensing options explained

    How Microsoft 365 and Office 365 suites with and without Teams work after the November 2025 reversal and July 2026 prices, when to add Teams Enterprise, and how to check who is licensed for Teams.

    Microsoft 36510 min read
  3. Replacing SharePoint alerts with Rules and Power Automate after retirement

    SharePoint alerts no longer work. Map each alert type to a SharePoint rule or a Power Automate flow, including digests, changes by others and single-item notifications.

    Microsoft 36513 min read