GUEST USER ACCESS

Brass Contributor

Hello Experts,

We are in the process of developing policies for the Microsoft Team and Stuck in GUEST USER ACCESS.

As per company requirement, we want to enable "GUEST ACCESS" for Meetings, Chats and comfortable with allowing GUEST on these however our management is not comfortable to enable GUEST ACCESS for TEAM and following Channels as the risk is that if a Power user invites any guest in a Team and Channel then he can access files and chat history if the channel is confidential and we want to restrict this action but as per my learning if we enabled "GUEST ACCESS" which is applied on Meetings, Chats and Team/Channel then it will apply on all.

GUEST ACCESS is a single control for meetings, Chat and Channels too and access of Channel is not acceptable for us.

I Searched on the Internet and found that we can allow GUEST Access on some team as per the below link

https://tomtalks.blog/2020/04/controlling-microsoft-teams-guest-access-on-a-per-team-basis/

 

Question :

Is there any option so our Power user of Team/Channel does not have the power of inviting External GUEST User on his/her Team and Channel?

Is this link related to the above query (https://docs.microsoft.com/en-us/azure/active-directory/external-identities/delegate-invitations) I don't think its for AZUE when we want to connect two different Organization?

Any Other Suggestions to control this GUEST USER ACCESS for Team/Channel?

 

 

2 Replies

@osamamansoor/ maybe if you only consider for meetings please plan meetings with guest without selecting a channel / MS Team.  If you want this then there are some options: limit who are owner of a team , only owners of a team can add users.  Another way to limit the creation of teams and limit this one , you can enable and disable guest per team so get an provision tool and make this one work , you can use flow for this but it will get complex. consider that you have to disable creating groups which will give you another limitation .   

Thanks for your feedback

We have already taken access to creating a new team / Group only for admin which means that our power user can add/delete/invite a guest and not have the power of creating a group