Managing Guests

%3CLINGO-SUB%20id%3D%22lingo-sub-1228669%22%20slang%3D%22en-US%22%3EManaging%20Guests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1228669%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20like%20to%20ask%20you%20how%20to%20manage%20guest.%20We%20would%20like%20to%20manage%20all%20guests%20and%20provide%20our%20end%20users%20only%20list%20of%20allowed%20guests%20which%20they%20can%20add%20to%20Teams.%20They%20can%20not%20add%20guests%20by%20themselves.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20the%20other%20hand%20we%20would%20like%20to%20provide%20them%20an%20option%20that%20they%20can%20share%20documents%20from%20their%20OneDrive%20as%20they%20wish%20and%20with%20who%20they%20need.%20But%2C%20if%20we%20allow%20sharing%20files%20from%20OneDrive%2C%20they%20share%20files%20with%20someone%20from%20different%20tenant%2C%20it%20automatically%20creates%20guest%20account%20in%20our%20AAD%20when%20guest%20accepts%20the%20invitation.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20you%20have%20any%20advice%20how%20to%20manage%20it%3F%20Is%20it%20possible%20to%20combine%20it%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMirek%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1228669%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EGuest%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1229366%22%20slang%3D%22en-US%22%3ERe%3A%20Managing%20Guests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1229366%22%20slang%3D%22en-US%22%3EHi%20Miroslav%2C%3CBR%20%2F%3EI%20think%20you%20can%20use%20Azure%20AD%20B2B%20collaboration%2C%20then%20allow%20them%20to%20show%20up%20on%20Teams%20from%20Org%20Wide%20Setting-%26gt%3BGuest%20Access.%20You%20can%20also%20force%20Conditional%20Access%20restriction%20for%20those%20Accounts.%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20this%20helps!%3CBR%20%2F%3EMoe%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fb2b%2Flicensing-guidance%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fb2b%2Flicensing-guidance%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fb2b%2Fwhat-is-b2b%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fb2b%2Fwhat-is-b2b%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoftteams%2Fmanage-guests%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoftteams%2Fmanage-guests%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1229377%22%20slang%3D%22en-US%22%3ERe%3A%20Managing%20Guests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1229377%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F503735%22%20target%3D%22_blank%22%3E%40Moe_Kinani%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethank%20you%20for%20the%20links.%20I%20have%20read%20all%20of%20them%20already%20but%20I%20have%20not%20found%20the%20answer%20there%20or%20I%20am%20not%20sure%20about%20it%20and%20this%20is%20the%20reason%20why%20I%20posted%20here%20the%20question.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20know%20that%20I%20can%20set%20conditional%20access%20to%20external%20people.%20My%20case%20is%20only%20about%20managing%20guests%20and%20have%20a%20control%20who%20is%20in%20my%20tenant%20as%20a%20guest%20but%20on%20the%20other%20side%20provide%20comfortable%20platform%20for%20my%20end%20users.%20I%20am%20not%20sure%20if%20these%20to%20ways%20are%20not%20against%20each%20other.%20For%20managing%20access%20guests%20is%20really%20nice%20feature%20%22Access%20packages%22.%20But%20when%20I%20allow%20end%20users%20to%20share%20content%20from%20OneDrive%20or%20SharePoint%20then%20they%20create%20guests%20in%20my%20tenant%20also%20and%20first%20way%20is%20absolutely%20pointless...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMirek%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1233382%22%20slang%3D%22en-US%22%3ERe%3A%20Managing%20Guests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1233382%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F5245%22%20target%3D%22_blank%22%3E%40Miroslav%20Nov%C3%A1k%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EManaging%20guests%20can%20be%20extremely%20tricky%20and%20it's%20well%20manageable%20in%20MS365%20at%20the%20moment.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20try%20if%20you%20disable%20adding%20guests%20through%20Teams%2C%20they%20can%20go%20around%20and%20add%20them%20through%20Sharepoint%2FOnedrive.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20want%20complete%20control%2C%20you%20need%20to%20disable%20guest%20invites%20all%20together%20and%20work%20out%20some%20kind%20of%20automated%20system.%20Here%20you%20setup%20up%20a%20request%20form%2C%20a%20business%20owner%20decides%20and%20an%20automated%20guest%20provisioning%20is%20kicked%20off.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1238926%22%20slang%3D%22en-US%22%3ERe%3A%20Managing%20Guests%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1238926%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%2C%20thank%20you%20for%20your%20comment.%20I%20was%20afraid%20of%20this%20solution%20that%20there%20does%20not%20exist%20a%20way%20how%20to%20manage%20it%20together.%20Currently%20Microsoft%20provides%20a%20solution%20how%20to%20manage%20guest%20it%20is%20called%20%22Access%20packages%22%20%3CA%20href%3D%22https%3A%2F%2Faad.portal.azure.com%2F%23blade%2FMicrosoft_AAD_ERM%2FDashboardBlade%2FelmEntitlement%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faad.portal.azure.com%2F%23blade%2FMicrosoft_AAD_ERM%2FDashboardBlade%2FelmEntitlement%3C%2FA%3E%3C%2FP%3E%3CP%3EIt%20is%20not%20so%20comfortable%20but%20it%20is%20a%20way%20how%20to%20do%20it.%20I%20wanted%20let%20people%20share%20documents%20directly%20from%20OneDrive%20and%20avoid%20going%20to%20different%20portal%2C%20add%20guest%20and%20then%20share%20files.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMirek%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Hi,

 

I would like to ask you how to manage guest. We would like to manage all guests and provide our end users only list of allowed guests which they can add to Teams. They can not add guests by themselves.

 

On the other hand we would like to provide them an option that they can share documents from their OneDrive as they wish and with who they need. But, if we allow sharing files from OneDrive, they share files with someone from different tenant, it automatically creates guest account in our AAD when guest accepts the invitation. 

 

Do you have any advice how to manage it? Is it possible to combine it?

 

Thanks,

 

Mirek

4 Replies
Highlighted
Hi Miroslav,
I think you can use Azure AD B2B collaboration, then allow them to show up on Teams from Org Wide Setting->Guest Access. You can also force Conditional Access restriction for those Accounts.

Hope this helps!
Moe

https://docs.microsoft.com/en-us/azure/active-directory/b2b/licensing-guidance

https://docs.microsoft.com/en-us/azure/active-directory/b2b/what-is-b2b

https://docs.microsoft.com/en-us/microsoftteams/manage-guests

Hi @Moe_Kinani,

 

thank you for the links. I have read all of them already but I have not found the answer there or I am not sure about it and this is the reason why I posted here the question.

 

I know that I can set conditional access to external people. My case is only about managing guests and have a control who is in my tenant as a guest but on the other side provide comfortable platform for my end users. I am not sure if these to ways are not against each other. For managing access guests is really nice feature "Access packages". But when I allow end users to share content from OneDrive or SharePoint then they create guests in my tenant also and first way is absolutely pointless...

 

Mirek

Highlighted

@Miroslav Novák 

 

Managing guests can be extremely tricky and it's well manageable in MS365 at the moment.

 

It's try if you disable adding guests through Teams, they can go around and add them through Sharepoint/Onedrive.

 

If you want complete control, you need to disable guest invites all together and work out some kind of automated system. Here you setup up a request form, a business owner decides and an automated guest provisioning is kicked off.

Highlighted

Hi @Thijs Lecomte, thank you for your comment. I was afraid of this solution that there does not exist a way how to manage it together. Currently Microsoft provides a solution how to manage guest it is called "Access packages" https://aad.portal.azure.com/#blade/Microsoft_AAD_ERM/DashboardBlade/elmEntitlement

It is not so comfortable but it is a way how to do it. I wanted let people share documents directly from OneDrive and avoid going to different portal, add guest and then share files.

 

Mirek