Identifying what resources Guest Users in my tenant have been granted access to?

Iron Contributor

I have a few Guest Users defined in my M365 tenant, as well as seeing a few "#EXT# external accounts (which each appear to be directly associated with their respective Guest User account) listed in my Active Users list. How can I determine what internal resources these guest user accounts have been granted access to?

1 Reply

There's no one-stop solution for this, you'll have to enumerate each individual resource (mailbox, group, site, etc) and its permissions to determine that. Checking group membership is a good start, but it doesnt cover all. And you should also complement this with Audit log search: https://docs.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compl...