Home

Conversation data storage as a guest user

%3CLINGO-SUB%20id%3D%22lingo-sub-812866%22%20slang%3D%22en-US%22%3EConversation%20data%20storage%20as%20a%20guest%20user%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-812866%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20looking%20to%20confirm%20that%20this%20is%20correct...%20when%20a%20guest%20is%20provisioned%20in%20Microsoft%20Teams%2C%20there%20is%20some%20kind%20of%20user%20stub%20created%20(that%20the%20underlying%20consumer%20user%20doesn't%20know%20what%20this%20account%20is)%20and%20then%20behind%20the%20scenes%20the%20conversations%2Fchat%20are%20stored%20in%20containers%20associated%20with%20the%20Group%20or%20Chat%20user%20in%20the%20host%20tenant%3F%20Then%20it's%20basically%20subject%20to%20that%20tenant's%20policies%20regarding%20retention%20policies%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESecondary%20question%2C%20when%20you%20switch%20between%20different%20tenants%20in%20the%20teams%20client%20-%20does%20anything%20get%20logged%20in%20your%20home%20tenant%20regarding%20the%20swap%20over%20in%20the%20user's%20home%20tenant%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-812866%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EGuest%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EGuest%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-813009%22%20slang%3D%22en-US%22%3ERe%3A%20Conversation%20data%20storage%20as%20a%20guest%20user%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-813009%22%20slang%3D%22en-US%22%3EYou%20are%20correct%20for%20the%20first%20question%20and%20in%20regards%20of%20the%20second%20one%2C%20unfortunately%20no%20information%20related%20to%20swap%20events%20is%20logged%20by%20Teams%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-813272%22%20slang%3D%22en-US%22%3ERe%3A%20Conversation%20data%20storage%20as%20a%20guest%20user%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-813272%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F228093%22%20target%3D%22_blank%22%3E%40Timothy%20Balk%3C%2FA%3E%26nbsp%3BI%20think%20you%20might%20mean%20the%20way%20that%20Office%20365%20captures%20compliance%20records%20for%20hybrid%20and%20guest%20users%20in%20%22phantom%22%20mailboxes.%20See%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.petri.com%2Fteams-compliance-records-hybrid-exchange%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petri.com%2Fteams-compliance-records-hybrid-exchange%3C%2FA%3E%26nbsp%3Bfor%20details.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-814157%22%20slang%3D%22en-US%22%3ERe%3A%20Conversation%20data%20storage%20as%20a%20guest%20user%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-814157%22%20slang%3D%22en-US%22%3ETeams%20won't%20say%20anything%2C%20but%20their%20should%20be%20an%20AAD%20Audit%20log%20of%20the%20guest%20account%20access.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-815078%22%20slang%3D%22en-US%22%3ERe%3A%20Conversation%20data%20storage%20as%20a%20guest%20user%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-815078%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F869%22%20target%3D%22_blank%22%3E%40Chris%20Webb%3C%2FA%3E%26nbsp%3BMaking%20sure%20I%20understand...%20Both%20companies%20have%20separate%20tenants%20that%20aren't%20federated.%20AdventureWorks%20invites%20a%20user%20in%20Contoso%20to%20their%20team%20via%20the%20guest%20access.%20There%20would%20be%20a%20entry%20logged%20in%20Contoso's%20Azure%20saying%20they%20had%20a%20user%20that%20swapped%20into%20AdventureWorks%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-815141%22%20slang%3D%22en-US%22%3ERe%3A%20Conversation%20data%20storage%20as%20a%20guest%20user%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-815141%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F228093%22%20target%3D%22_blank%22%3E%40Timothy%20Balk%3C%2FA%3E%26nbsp%3BYes%2C%20B2B%2C%20so%20it%20has%20an%20account%20in%20your%20AD%2C%20it%20still%20passes%20the%20login%20through%20your%20tenant%20for%20that%20access.%20See%20screenshot%2C%20this%20is%20on%20my%20Home%20tenant.%20Turismon%20is%20my%20test%20tenant%20account%20that%20is%20a%20guest%2C%20I%20switched%20over%20and%20you%20can%20see%20it%20in%20the%20login%20logs.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F127812iCC8C619280303C7E%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22guest.jpg%22%20title%3D%22guest.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-815199%22%20slang%3D%22en-US%22%3ERe%3A%20Conversation%20data%20storage%20as%20a%20guest%20user%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-815199%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F869%22%20target%3D%22_blank%22%3E%40Chris%20Webb%3C%2FA%3E%26nbsp%3BJust%20to%20fill%20out%20the%20rest%20of%20the%20scenario...%20does%20anything%20get%20logged%20in%20the%20Contoso%20tenant%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Just looking to confirm that this is correct... when a guest is provisioned in Microsoft Teams, there is some kind of user stub created (that the underlying consumer user doesn't know what this account is) and then behind the scenes the conversations/chat are stored in containers associated with the Group or Chat user in the host tenant? Then it's basically subject to that tenant's policies regarding retention policies?

 

Secondary question, when you switch between different tenants in the teams client - does anything get logged in your home tenant regarding the swap over in the user's home tenant?

 

Thanks!

6 Replies
Highlighted
You are correct for the first question and in regards of the second one, unfortunately no information related to swap events is logged by Teams
Highlighted

@Timothy Balk I think you might mean the way that Office 365 captures compliance records for hybrid and guest users in "phantom" mailboxes. See https://www.petri.com/teams-compliance-records-hybrid-exchange for details.

Highlighted
Teams won't say anything, but their should be an AAD Audit log of the guest account access.
Highlighted

@Chris Webb Making sure I understand... Both companies have separate tenants that aren't federated. AdventureWorks invites a user in Contoso to their team via the guest access. There would be a entry logged in Contoso's Azure saying they had a user that swapped into AdventureWorks?

 

 

Highlighted

@Timothy Balk Yes, B2B, so it has an account in your AD, it still passes the login through your tenant for that access. See screenshot, this is on my Home tenant. Turismon is my test tenant account that is a guest, I switched over and you can see it in the login logs. 

guest.jpg

Highlighted

@Chris Webb Just to fill out the rest of the scenario... does anything get logged in the Contoso tenant?