Forum Discussion

Maxwell Shifman's avatar
Maxwell Shifman
Copper Contributor
Feb 13, 2019

SharePoint Guests vs Azure AD Guests

I'm trying to understand the use of SharePoint Online Guests and the integration with Azure AD.

 

We use External Sharing via SharePoint/OneDrive for Business extensively, with the default being to Specific People with email address enforcement. At the moment, I can keep track of all Accounts that have ever been shared to at https://tenant.sharepoint.com/_layouts/15/people.aspx?MembershipGroupId=0.

 

We do not require manually adding Guest users to our Azure AD, and it is not our practice. Yet, when I go to Azure AD management (https://portal.azure.com/#blade/Microsoft_AAD_IAM/UsersManagementMenuBlade/AllUsers), a subset (maybe 50%) of the external users that have been shared to via SharePoint are also shown as Guests in our Azure AD.

 

What I want to know is:

  1. What is the trigger for an external user to be added automatically as a Guest to our Azure AD?
  2. Do I need to keep users in our Azure AD as Guests if we are only sharing links via SharePoint?
  3. Is there any additional benefit in ensuring external users are added as Guests in Azure AD?
    • jcgonzalezmartin's avatar
      jcgonzalezmartin
      MVP
      When you share a SPO Site with an external user he should be added also as external user in your Azure AD. Basically Azure AD is the hub that centrally manages how users (external and no external) can access to Office 365 services. Behind the scenes SPO and EXO have their own AD implementation that is bidirectionally synchronized with Azure AD so if an account is added to Azure AD, is going to be propaggated to SPO and the other way around
      • StephenRice's avatar
        StephenRice
        Icon for Microsoft rankMicrosoft

        Hi Maxwell Shifman ,

         

        Hopefully I can shed some light here :) 

         

        At the moment, when you share to an entirely new person (i.e. never been shared to before) from ODB and share via the "specific people" option, one of two things can happen. If the recipient is an O365 user, when they redeem the link, they will be added to your directory as a full guest user (note that there are some cases where this may not occur). If they are not an O365 user, they are only instantiated on that site collection (or OneDrive).

         

        This will all change in a few months when we fully migrate over to Azure B2B as the backing guest account service for ODB/SPO (as announced/demo'd at Ignite). Once done, all new shares will result in guest accounts being created.

         

        The biggest difference between guest account created/not created is how you apply management & policy to those users.

         

        Hope that helps!


        Stephen Rice

        OneDrive Program Manager II

Share

Resources