External users
32 TopicsSensitivity Labels: Labeling Documents in OneDrive severly restricts sharing with external users
Hi everyone, i am currently implementing sensitivity labels for our org and this one thing is really holding me back. Previously, it was possible do create a word-document (or any file) in OneDrive, share it to an external gmail (or any other) address and let them access it after using an email OTP. Nice! I have just recently created a set labels and assigned them to me in Purview. Most labels, including the one that is assigned to docs by default, do not apply any encryption. A label existing on a document still seems to make sharing way harder/impossible in certain scenarios: Created a fresh gmail-address-->created a fresh word document with a default label (public, no sharing restrictions, no encryption)--> Shared said document to said gmail-address via Link --> opened link in private browser tab --> OTP-Verification happens --> Document opens up in browser, then IMMEDIATELY forwards me to our tenants login-page. There, the gmail address user obviously cant log in since he is not a guest and does not have an account. The fun part: You can (sometimes) use the browser "back" button to return to the document to read and edit. This... can't be intended, right? Research suggests to me that word for the web attempts to resolve the label, for which it has to access our tenant. It then fails since no tenant user is logged in and prompts me to do so. When i use a gmail address, create a personal MS account, invite this account into my tenant as a guest, accept the request and share to that user, the user can work with the doc just fine after completing his steps. But this is way to much work for IMO. Has anyone seen this issue? Did i misconfigure something? Has anyone found a solution or a reasonable workaround or are people just living with this loss of functionality? Do you think its just a bug and i should report it?Solved53Views0likes2CommentsMicrosoft 365 Windows 11 external user or guest user sign in
Consider the following situation: CompanyA has a Microsoft 365 tenant with licensed users. CompanyA has a business relationship with CompanyB which also has a Microsoft 365 tenant. All of CompanyB's Windows 11 Pro computers are Entra ID joined and Intune enrolled. All of CompanyB's users have Microsoft 365 Business Premium licenses. An employee of CompanyA is stationed at CompanyB's office and needs to use one of CompanyB's computers as his primary computer. How would a technician have to configure things so that CompanyA user can sign into CompanyB's Windows 11 Pro computer and work like normal? I've done some reading online but most of the articles focus on access to cloud resources, whether that be Microsoft Teams or Entra Enterprise Apps or similar resources. I haven't found an article touching on Windows 11 sign in. Matthew555Views0likes2CommentsIssues with Sensitivity Labels and "Specific email addresses or domains" - Not working
Hello! We have enabled Sensitivity Labels in our tenant. The access control settings for the label states that a specific domain gets the permission "Co-Author". When we enable the Sensitivity label on a document and sent it towards the approved domain, it results in an error message when authenticating to open the document: "Selected user account does not exist in tenant 'Veni AS' and cannot access the application in that tenant. The account needs to be added as an external user in the tenant first. Please use a different account." After doing some research I did some changes to the external domain within the Cross-tenant settings. The external domain now has the following settings: Inbound access: Allow access on external users and groups, within B2B Collaboration Allow access on external users and groups, within B2B direct connect Trust multifactor authentication from Microsoft Entra tenants, within Trust settings. Outbound access: Allow access on users and groups, within B2B Collaboration Allow access on users and groups, within B2B direct connect External Identities: Block access for external users and groups. (Inherited from default) After doing this change, I no longer get the same error message as above when authenticating to open the labeled document. Now I get the following error message: "You are not signed in to office with an account that has permission to open this document. You may sign in a new account into Office that has permission or request permission from the content owner" I have this working from another tenant to the same external domain and I have cross-checked the settings. Any idea on how to proceed, or if it is any obvious change I need to make in order to get this to work? All feedback appreciated! :-)150Views1like1Comment"File Upload" Option not available for external users.
"File upload" option is only available when set Microsoft Forms “Only people in my organization can respond” or “Specific people in my organization can respond” is the selected setting. When we set, "Anyone can Respond" the option "Upload File" greyed out3.1KViews0likes2CommentsPowerpoint in Mac is missing some fonts
Hello Techies, I recently came across an issue that could be a small issue according to you, but I feel these are very crucial for some users. I am going to be frequently using PowerPoint, where I use a particular font, 'Abadi.' I would appreciate it if someone could help me with a fix regarding this.67Views0likes1CommentMicrosoft forms and external upload files possible?
Good afternoon, We as a company want to create forms that our customers can fill in with the data we need. Like plans and technical drawings. I hoped that it would be possible to create these forms, but when i try to add the upload file question I need to change the settings to only internal. Is there no possibility to create forms that have the request of uploading files from external parties we send the link to? Kind regards, Carina44KViews0likes5CommentsEdit Existing Group Me Polls without Losing Responses
Description: Currently, once a poll is created in GroupMe, it cannot be edited. This can be problematic if the poll creator makes a mistake, such as a typo, missing option, or unclear wording. Additionally, there may be instances where the creator wants to adjust the poll to guide responses in a certain direction without resetting the vote count. Proposed Solution: Enable poll creators to make minor edits to existing polls while preserving responses. This could include: • Editing the poll question • Adding or modifying response options • Adjusting the poll duration To maintain fairness, GroupMe could notify participants when changes are made and provide an option to re-cast votes if necessary. Benefits: • Fixing Mistakes: If the creator accidentally includes a typo or omits an important option, they can correct it without restarting the poll. • Clarifying Questions: A vague or misleading poll question can be refined to ensure participants fully understand it. • Guiding Responses: In some cases, the creator may want to subtly steer the poll in a particular direction without losing previous engagement. This feature would improve usability and flexibility while keeping GroupMe polls engaging and relevant.188Views1like0CommentsAdd EXTERNAL Teams account details to a contact in the GAL
We collaborate a lot with another company who have their own tenant. When we want to message an “external” user in Teams we have not messaged before, we must first search and type in the full email address, then select "(External)" to message them. We also have these same users as contacts in our GAL for email. The problem we have is that when you start searching for the user, the GAL contact comes up first, and users think that this is the correct Teams user account so they select this instead of typing further to bring up the real external account. If they do make it as far as to type out the full email address, then two users show up, one from the GAL and one with "(external)" in it. This is not a great user experience. We'd like to know if there is a way in which we can import the external user to our GAL, or if we can populate the GAL contact with the Teams attributes of the external user. The end goal is to have a GAL contact which the user can click to message in Teams. Has anyone come across this before and has a solution?152Views1like2CommentsRestrict access to a Form to include external users in our tenant?
Hello, I'm setting up an automation where a Form response triggers a Power Automate Flow that updates a non-critical value in Business Central records. It works well except that I want the form to be non-public but to still be usable for people that are from different tenants but added as guests or members in our Entra. I haven't found what kind of setup and changes I need to make for this to be possible, I feel like it's either people within my domain or public, nothing in between. Is there really no way to restrict access to exclude public and anonymous users but include users from externa tenants and invited in my domain ? This is the current Entra setup for the kind of user I want to be able to access the form, I have tried with both user type Guest and Member but no change. Thank you424Views0likes1CommentEntra invitation manager for guests
A while ago there was a change that the SharePoint invitation manager has been converted to the Entra invitation manager. This is a good thing because every guest can use the OTP for logging in. Only I see this behaviour: When a guest has been added to a group or a team. The guest can sign in with OTP to the team. Also there is a guest account created. When I share a folder or a document the guest can sign in with the OTP to the folder or document. But there is no guest account in M365 for this user. So you don't have an overview of the guest accounts in your tennant where a document has been shared with. With Powershell you can edit the entra invitation manager a bit: Set-SPOTenant -EnableAzureADB2BIntegration $true After completing this command also the users when you share something will be addeAuthenticationd as a guest. Is it default that guests are not vissible when you share a folder or document with them? Is this the right approuch to get a view of those accounts? Maurits Knoppert268Views0likes1Comment