Introducing guest access for Office 365 Groups!

Former Employee

Today, we announced the new guest access feature for Office 365 Groups, the group membership service that provides a single identity for teams in Office 365. The new guest access feature gives you the ability to include people outside of your company in an Office 365 group.

 

  • Get the details in this blog post
  • Learn more about collaborating outside the firewall with Office 365 Groups at this session at Ignite
  • Check out the whole lineup of sessions on Office 365 Groups at Ignite here!

@Christophe Fiessinger @Shashi Singaravel

65 Replies

So I shall chalk my frustrating experience with Photos to the list of other issues with this new network.... Tant pis.

How about when it screws up profile circles so they create a beautiful oval frame of your ear Tony?
How about when it screws up profile circles so they create a beautiful oval frame of your ear Tony?

Guess access became available over the weekend, after I'd struggled through the PowerShell steps - needed to install different versions of Azure AD moduleto get the commandlets so it would work - and it looks like it will be an answer to several collaboration issues.

 

But Groups bring new issues. I know, from following the threads on Groups that these issue will be resolving themselves over time, but here's what I'm seeing:

 

Navigation is clumsy. It seems that there's no direct way to get to the Group Team Site. One has to go to the group in OWA or OneDrive, That link brings you to either the mailbox or the documents library for the group. From the OneDrive/Library path one can then click Home and get to the Team Site. From OWA/Mailbox one has to click Files to get to the library and then Home to the Team Site. 

 

Too many clicks!

 

It seems the Group Team Sites are otherwise hidden. There's no place to go from O365 SharePoint Online to see which sites exist. 

 

I know that my users won't want to be bothered with all these steps and most of them won't (or can't without handholding) create bookmarks/favorites for navigation. 

 

So, for me, navigation will be a critical aspect.

Thanks for your feedback.

You can now set the tenant level guest settings through Office 365 portal as well. 

Barry thanks for the feedback, we are making a number of improvements around navigation and reducing the clicks, I'll be demoing a few at Ignite in two weeks (yes the recorded session will be made publically available shortly after)

These direct links work for my group members - of course you don't have an invite so they won't work for you :) so you need https://TENANTNAME.sharepoint.com/sites/GROUPNAME

 

Sharepoint team site for the group is:   https://davidslight.sharepoint.com/sites/CAF/SitePages/Home.aspx

Document library for the group is:        https://davidslight.sharepoint.com/sites/CAF

 

Discover and a directory of sites also works in Outlook client quite nicely try Browse Groups. 

Would be nice if the Group Description field also was part of the Group listing ...

Thanks for the replies. Especially the assuarance that navigation is being looked at as an important update.

 

David, thanks for reminding me of the path statement. I may be able to get my users to understand. The users in question are salespersons for whom curiosity about and actually investing energy in using the software tools we have made available to them is severely limited.

 

For the sales people, if these links, such as https://TENANTNAME.sharepoint.com/sites/GROUPNAME, don't appear magically on the devices, they don't want to bother and will continue to use other, non-collaborative means. 

 

OTOH, if I can get them to use Groups in Outlook, we might get somewhere :)

 

 

The stupid avatar makes my ear look pretty though...

This is VERY helpful - thanks @Darrell Webster. I was getting a little tired of downloading every pic...  Smiley Happy

 

And while I'm here, back onto the thread topic - we've hit the ground running and have set up private Outlook Groups with external members for about four projects just today. Conversations are flowing, files are being saved into the group folder and plans are being made in Planner. Loving. It. 

 

And how about when you click and nothing happens so you click again and then you get a duplicate post !! ;)

@Christophe Fiessinger @Tony Redmond

 

Does Guest Access respect the tenant-level Allowlist (whitelist)?

 

We are seeing evidence that it does not, which our security team will not love at all. :(

Those whitelists (defined in the Sharing section of the SharePoint Online Admin Center) control invitations for individual SharePoint items and not the addition of guest members to Office 365 Groups. However, it's easy to scan the membership of groups to find guests from forbidden domains and remove them. I have the PowerShell code to do that and will talk about it at Ignite (but you can figure it out yourself)!

Thanks David for the feedback! Currently we don't honour Sharepoint Allow-List, that list for external sharing of SharePoint items not linked with Guests in groups, but as @Tony Redmond has mentioned you should be able to remove the guests with black-listed domains with the Powershell script.

Thanks @Tony Redmond and @Sahil Arora !

 

While having the PowerShell is nice, there is still some exposure there if a user shares something externally to a domain we do not allow. During that time period between the share occurring and some sort of automated job or utility running to scan all guest users to identify their domains and remove the ones we don't want, whatever was shared is exposed to the outside world. This will scare many IT departments into turning guest access off completely, or at best putting data sensitivity restrictions on what a Group is allowed to be used for. I'm assuming either of those scenarios is not the ultimate goal of Groups.

 

It would be much simpler, more effective, and less risky to simply query the tenant level whitelist or blacklist when the guest access sharing action occurs to see if the domain is allowed or not. If allowed, proceed as normal. If not allowed, throw the same error message that SharePoint does now when you attempt to share to a domain that is not allowed. I'm obviously not familiar with the exact inner workings of everything on your side of the fence, but this seems like a fairly simple and straighforward requirement that functionality already exists for - the connection is just not being made right now.

 

I personally love Groups, and I clearly see the vision of where it is headed and how it will make things better across the board in Office 365. Not having this sort of integration from the start makes this almost a non-starter to large enterprises that have a risk averse security department, which is becoming almost the norm these days. Even if added later, then it becomes a Change issue since I'll then have a huge battle to relocate teams who started using other solutions since Groups was not ready yet to fit their needs.

Thanks @David Rosenthal for the feedback! We take this feedback and include this datapoint in our planning.

If I add guest outside of organization which just uses gmail, its not working because he cant login using his gmail acocunt obivously. I do not understand this well probably. I can see that gmail user added as guest to my office 365 group recieving welcome email, and is part of Conversations, but as guest I cant use Planner, File, shared calendar and Onedrive for sharing files... 

 

Do I need to add those guest access also in admin center somewhere or what?? 

1. As a guest member, when you click Read group files link in your welcome email, you will be redirected to access the group files in SharePoint Online, in which you will have full control to view and edit group files, and also share group files to existing group members/guest members. But you will neither be able to add new guest user nor share groups files to new group members/guest members.

 

2. Guest access is not yet supported for Planner. Its coming soon. 

 

3. Shared Calendar - When users in the group share a calender event, guest user can able to participate in. But cannot able to view full calendar events in the group.

 

You can refer this Getting Started blog which will help you on this. 

http://www.jijitechnologies.com/blogs/new-guest-access-feature-for-office365-groups

Many thanks for prompt response. Second point is most important for me. I want to use it for task management with a person outside of organization. Any idea when the guess access for Planner will be available?? So that I can plan around it...