External users
21 TopicsSensitivity Labels: Labeling Documents in OneDrive severly restricts sharing with external users
Hi everyone, i am currently implementing sensitivity labels for our org and this one thing is really holding me back. Previously, it was possible do create a word-document (or any file) in OneDrive, share it to an external gmail (or any other) address and let them access it after using an email OTP. Nice! I have just recently created a set labels and assigned them to me in Purview. Most labels, including the one that is assigned to docs by default, do not apply any encryption. A label existing on a document still seems to make sharing way harder/impossible in certain scenarios: Created a fresh gmail-address-->created a fresh word document with a default label (public, no sharing restrictions, no encryption)--> Shared said document to said gmail-address via Link --> opened link in private browser tab --> OTP-Verification happens --> Document opens up in browser, then IMMEDIATELY forwards me to our tenants login-page. There, the gmail address user obviously cant log in since he is not a guest and does not have an account. The fun part: You can (sometimes) use the browser "back" button to return to the document to read and edit. This... can't be intended, right? Research suggests to me that word for the web attempts to resolve the label, for which it has to access our tenant. It then fails since no tenant user is logged in and prompts me to do so. When i use a gmail address, create a personal MS account, invite this account into my tenant as a guest, accept the request and share to that user, the user can work with the doc just fine after completing his steps. But this is way to much work for IMO. Has anyone seen this issue? Did i misconfigure something? Has anyone found a solution or a reasonable workaround or are people just living with this loss of functionality? Do you think its just a bug and i should report it?Solved69Views0likes2CommentsMicrosoft 365 Windows 11 external user or guest user sign in
Consider the following situation: CompanyA has a Microsoft 365 tenant with licensed users. CompanyA has a business relationship with CompanyB which also has a Microsoft 365 tenant. All of CompanyB's Windows 11 Pro computers are Entra ID joined and Intune enrolled. All of CompanyB's users have Microsoft 365 Business Premium licenses. An employee of CompanyA is stationed at CompanyB's office and needs to use one of CompanyB's computers as his primary computer. How would a technician have to configure things so that CompanyA user can sign into CompanyB's Windows 11 Pro computer and work like normal? I've done some reading online but most of the articles focus on access to cloud resources, whether that be Microsoft Teams or Entra Enterprise Apps or similar resources. I haven't found an article touching on Windows 11 sign in. Matthew571Views0likes2CommentsIssues with Sensitivity Labels and "Specific email addresses or domains" - Not working
Hello! We have enabled Sensitivity Labels in our tenant. The access control settings for the label states that a specific domain gets the permission "Co-Author". When we enable the Sensitivity label on a document and sent it towards the approved domain, it results in an error message when authenticating to open the document: "Selected user account does not exist in tenant 'Veni AS' and cannot access the application in that tenant. The account needs to be added as an external user in the tenant first. Please use a different account." After doing some research I did some changes to the external domain within the Cross-tenant settings. The external domain now has the following settings: Inbound access: Allow access on external users and groups, within B2B Collaboration Allow access on external users and groups, within B2B direct connect Trust multifactor authentication from Microsoft Entra tenants, within Trust settings. Outbound access: Allow access on users and groups, within B2B Collaboration Allow access on users and groups, within B2B direct connect External Identities: Block access for external users and groups. (Inherited from default) After doing this change, I no longer get the same error message as above when authenticating to open the labeled document. Now I get the following error message: "You are not signed in to office with an account that has permission to open this document. You may sign in a new account into Office that has permission or request permission from the content owner" I have this working from another tenant to the same external domain and I have cross-checked the settings. Any idea on how to proceed, or if it is any obvious change I need to make in order to get this to work? All feedback appreciated! :-)162Views1like1CommentPowerpoint in Mac is missing some fonts
Hello Techies, I recently came across an issue that could be a small issue according to you, but I feel these are very crucial for some users. I am going to be frequently using PowerPoint, where I use a particular font, 'Abadi.' I would appreciate it if someone could help me with a fix regarding this.76Views0likes1CommentEdit Existing Group Me Polls without Losing Responses
Description: Currently, once a poll is created in GroupMe, it cannot be edited. This can be problematic if the poll creator makes a mistake, such as a typo, missing option, or unclear wording. Additionally, there may be instances where the creator wants to adjust the poll to guide responses in a certain direction without resetting the vote count. Proposed Solution: Enable poll creators to make minor edits to existing polls while preserving responses. This could include: • Editing the poll question • Adding or modifying response options • Adjusting the poll duration To maintain fairness, GroupMe could notify participants when changes are made and provide an option to re-cast votes if necessary. Benefits: • Fixing Mistakes: If the creator accidentally includes a typo or omits an important option, they can correct it without restarting the poll. • Clarifying Questions: A vague or misleading poll question can be refined to ensure participants fully understand it. • Guiding Responses: In some cases, the creator may want to subtly steer the poll in a particular direction without losing previous engagement. This feature would improve usability and flexibility while keeping GroupMe polls engaging and relevant.196Views1like0CommentsAdd EXTERNAL Teams account details to a contact in the GAL
We collaborate a lot with another company who have their own tenant. When we want to message an “external” user in Teams we have not messaged before, we must first search and type in the full email address, then select "(External)" to message them. We also have these same users as contacts in our GAL for email. The problem we have is that when you start searching for the user, the GAL contact comes up first, and users think that this is the correct Teams user account so they select this instead of typing further to bring up the real external account. If they do make it as far as to type out the full email address, then two users show up, one from the GAL and one with "(external)" in it. This is not a great user experience. We'd like to know if there is a way in which we can import the external user to our GAL, or if we can populate the GAL contact with the Teams attributes of the external user. The end goal is to have a GAL contact which the user can click to message in Teams. Has anyone come across this before and has a solution?160Views1like2CommentsHow to add and grant access to external users for an M365 mailbox
Hello, what is the workaround to allow external users to share a mailbox? External users who are not within our domain should be able to send and receive emails using an address like (email address removed for privacy reasons). I have tried setting up both Shared and Group mailboxes, but it’s not possible to add external members, even after creating and inviting the external user in Entra and granting them access as a Guest or Member. These external users need to be able to log in to this mailbox to send and receive emails. As of now, it seems impossible to add or delegate external members. We do not require Teams or any other apps; we only need email/Outlook services. I have attempted multiple configurations, but nothing seems to work.3.6KViews0likes4CommentsSharing Excel sheet via embed into public web page without login
I am having difficulty sharing an Excel file to a public web page using the embed iFrame function. It embeds fine for me and I can view the web page, however a public user (or me using an incognito browser) is getting prompted to login to office 365. I need to display the data without login. I have Checked that sharing policies in Sharepoint admin centre are set to most permissive (both sharepoint and onedrive are set to "anyone" "Users can share files and folders using links that don't require sign-in." The Excel file is set (under manage access/share) "to anyone with link can view" What am I missing? Thanks for your help296Views0likes0CommentsRecommendation - Microsoft 365 authorisation concepts - Part 1
[New Blog Post] *PART 1!* I have put a new article online. This article is divided into two parts. In these two parts, you will learn the most important things about #AdministrativeUnits in #EntraID. What needs to be considered when creating an authorization concept. https://www.msb365.blog/?p=5495 #MVPsummit #M365 #Microsoft365 #CommunityRocks293Views0likes0Comments