Forum Discussion
Introducing guest access for Office 365 Groups!
Thanks TOny, I have that all set - as you said they were already set. I could not find those settings in the new portal, only the old portal.
(side note - thanks for the screen shot you attached. I only noticed it when coming back to reply. They don't feature very prominently do they.... Attached images should really show a thumbnail)
I am seeing 'All/Owners/Guests' in the group I've set up, but still get a warning that only individuals from within the organisation can be added when I try to add someone external.
I realise it might be a number of days away. Is there any visual indication to know external group membership is active on your tenant, or do we just keep trying until it works?
Hi Brian Mather and TonyRedmond. Here's a tip aside of the conversation topic that will help when sharing screenshots. Add "Photos" rather than "Choose Files". Photos will appear in the the body of the post. "Choose Files" is more suited to attaching documents.
(I'm catching up with the conversation and wanted to offer this to help future conversations.)
- Sahil AroraSep 18, 2016Former Employee
Thanks David Rosenthal for the feedback! We take this feedback and include this datapoint in our planning.
- David RosenthalSep 16, 2016
Microsoft
Thanks TonyRedmond and Sahil Arora !
While having the PowerShell is nice, there is still some exposure there if a user shares something externally to a domain we do not allow. During that time period between the share occurring and some sort of automated job or utility running to scan all guest users to identify their domains and remove the ones we don't want, whatever was shared is exposed to the outside world. This will scare many IT departments into turning guest access off completely, or at best putting data sensitivity restrictions on what a Group is allowed to be used for. I'm assuming either of those scenarios is not the ultimate goal of Groups.
It would be much simpler, more effective, and less risky to simply query the tenant level whitelist or blacklist when the guest access sharing action occurs to see if the domain is allowed or not. If allowed, proceed as normal. If not allowed, throw the same error message that SharePoint does now when you attempt to share to a domain that is not allowed. I'm obviously not familiar with the exact inner workings of everything on your side of the fence, but this seems like a fairly simple and straighforward requirement that functionality already exists for - the connection is just not being made right now.
I personally love Groups, and I clearly see the vision of where it is headed and how it will make things better across the board in Office 365. Not having this sort of integration from the start makes this almost a non-starter to large enterprises that have a risk averse security department, which is becoming almost the norm these days. Even if added later, then it becomes a Change issue since I'll then have a huge battle to relocate teams who started using other solutions since Groups was not ready yet to fit their needs.
- Sahil AroraSep 14, 2016Former Employee
Thanks David for the feedback! Currently we don't honour Sharepoint Allow-List, that list for external sharing of SharePoint items not linked with Guests in groups, but as TonyRedmond has mentioned you should be able to remove the guests with black-listed domains with the Powershell script.
- TonyRedmondSep 14, 2016MVP
Those whitelists (defined in the Sharing section of the SharePoint Online Admin Center) control invitations for individual SharePoint items and not the addition of guest members to Office 365 Groups. However, it's easy to scan the membership of groups to find guests from forbidden domains and remove them. I have the PowerShell code to do that and will talk about it at Ignite (but you can figure it out yourself)!
- David RosenthalSep 14, 2016
Microsoft
Does Guest Access respect the tenant-level Allowlist (whitelist)?
We are seeing evidence that it does not, which our security team will not love at all. :(
- Brian MatherSep 13, 2016Brass ContributorAnd how about when you click and nothing happens so you click again and then you get a duplicate post !! ;)
- LizP1Sep 13, 2016Iron Contributor
This is VERY helpful - thanks darrellaas. I was getting a little tired of downloading every pic... :smileyhappy:
And while I'm here, back onto the thread topic - we've hit the ground running and have set up private Outlook Groups with external members for about four projects just today. Conversations are flowing, files are being saved into the group folder and plans are being made in Planner. Loving. It.
- TonyRedmondSep 13, 2016MVP
The stupid avatar makes my ear look pretty though...
- Sep 12, 2016LOL
- Sep 12, 2016How about when it screws up profile circles so they create a beautiful oval frame of your ear Tony?
- Sep 12, 2016How about when it screws up profile circles so they create a beautiful oval frame of your ear Tony?
- TonyRedmondSep 10, 2016MVP
So I shall chalk my frustrating experience with Photos to the list of other issues with this new network.... Tant pis.
- darrellaasSep 10, 2016MVP
I'm using Chrome too and it has happily eaten the photos I spoon-fed it. Your screenshot wasn't too big a mouthful for Chrome to swallow.
- TonyRedmondSep 10, 2016MVP
Good theory, but I tried to add the screenshot as a photo and the browser (Chrome) barfed. So I didn't.