Oct 04 2023 12:15 AM
We have previously allowed external users to be invited as guests to teams but have found that once the user is a guest in our office365 tenant internal users can invite them to whatever they want, other teams, sharepoint files/folders etc. Due to this when we reviewed guest access we found many inappropriate guest shares (especially to entire sharepoint folders) because internal users have not considered the implication when sharing externally. So we now have a tenant that does not allow any external guest access.
Id love your help to understand if the following requirements are possible in some way:
At the moment we are considering a separate tenant to achieve this external collaboration but even this has issues if we want to use it to collaborate with more than one external organisation if users can accidently share one companies data with another.
Oct 04 2023 01:19 AM
Hi @briannorman,
The simplest solution to isolate guest users to a single team and stop users sharing other resources with them is to:
Once you have done this, guest users will only be able to access the "Guest Users" team and the resources within that team. Other users in your organization will not be able to share other resources with guest users.
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
(LinkedIn)
Oct 04 2023 02:33 AM
@LeonPavesic thanks for the quick response, this is kind of what we were doing before but it had the following challenges:
Are there things we can do to solve the above?
Oct 04 2023 04:19 AM
SolutionHi @briannorman,
to address the challenges you mentioned, you can do the following:
Allowing owners to invite internal users to the guest team
To allow owners to invite internal users to the guest team, you can add the "Add members" permission to the Owner role for the guest team. You can do this by going to the Teams admin center, clicking Teams, and then clicking the name of the guest team. Under Permissions, click Manage roles. Select the Owner role and then click Edit. Under Permissions, select the Add members checkbox and then click Save.
Ensuring that guest users only have access to files in the team they were added to
To ensure that guest users only have access to files in the team they were added to, you can disable guest sharing for SharePoint and OneDrive. You can also use SharePoint security groups to control access to SharePoint files and folders. For example, you can create a security group for guest users and then grant that group access to the files and folders in the guest team.
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
(LinkedIn)