In Focus
No items found.
thinformatics
Back to the blog
Allgemein
Entra ID
Governance
Identity Governance
Microsoft 365
Microsoft Teams

Microsoft Teams – Fulfill Advanced Guest Access Requirements

There are a lot of of settings available in a Microsoft 365 Tenant which were responsible for guest access. To manage guest Access in Teams you have to adjust different settings. At least the Azure AD external Collaboration Settings, the SharePoint Sharing Policies & Settings and the Teams Guest Access...

Jakob Schaefer
Jakob Schaefer
Consultant & SME Team GRC[br]Governance, Risk & Compliance
December 4, 2020
6 Minuten
Reading time

There are a lot of of settings available in a Microsoft 365 Tenant which were responsible for guest access. To manage guest Access in Teams you have to adjust different settings. At least the Azure AD external Collaboration Settings, the SharePoint Sharing Policies & Settings and the Teams Guest Access Settings are relevant. If you’re reading this blog I’m sure you know this switches.

The next level you might be aware, are the Microsoft 365 Group settings and sensitivity labels. With the Microsoft 365 Group Settings – which you can manage via Exchange & AAD PowerShell or the Graph API – you can e.g. disable guest invitations for a single Team . With Sensitivity Labels for Groups – one of the features I’m most excited about – you can also define, among other things, that no external users can participate on a Team.

The previously named options only allow to enable / disable guest access to a single Team or for the whole Tenant. With the Azure AD external collaboration settings you have minimal options to steer which Guests are allowed by adding their domains to a whitelist.

For some customers these options doesn’t fulfill their requirements for access management in Teams. In this blog I will explain a possibility to allow only authorized users to add guests from approved domains. We will use the Azure AD Identity Governance Feature, which allows us to implement an approval for new guests. Furthermore it will allow Access Expiry and Reviews.

So, lets start to add some more granularity and controls to the Teams guest management.

Create a Connected Organization

First you navigate to the AAD Portal for Identity Governance. Here you can add the domains you plan to collaborate with. Just add the Partner here add the domains they use.

Be aware that you can not use domains here, that you have blocked via the Azure AD External Collaboration Settings.

You can add a M365 Tenant partner domain or any other „type“. The assistant will check itself if it’s an Azure AD counterpart. If the partner organization is also using an Azure AD you can use more functions in the future, but for our scenario every kind of partner domain is fine.

In the next step you can add internal and external sponsors. You can make use of them in approval scenarios later. Users to add here, are mostly partner managers or other responsible persons in your and the related partner organization. The external sponsor must have an existing guest account in you domain, so you have to invite him before.

Create a Catalog

After finishing the connected organization assistant, the next step is to add catalogs. A catalog contains the resources to which you want to grant access. In our case we will add a Team or a Group of Teams here to the catalog. We will enable the catalog for external usage. After creating the catalog we can add the resource (the Team) to the catalog.

Create an Access Package

The next step is to create an Access Package which regulates via policies which connected organizations can access the resources we’ve added to a catalog.

On the „Requests“ tab we define the connected organizations which are allowed to participate in the Team. Choose every connected organization here which should be able to participate as a guest in the Team. Furthermore you can implement an approval here. In most cases, a single sage approval where the Team owners are assigned as approvers is enough. But you can also add a second stage and e.g. involve the external Sponsor which we’ve defined in the connected organization before.

On the „Requestor information“ tab you can add questions which guests have to answer to request access. It can be used to gather further information about the requestor and his justification to participate in the Team.

The tab „Lifecycle“ defines an expiration of the Guest Access requests and allows you to define a regulatory review of guests which have access to the package resources. You can insert static reviewers like the Team owners, or allow a self review. In our case we decide to insert the Team owners. They will receive an report on a regularly base which contains the external guests who have access to the Team and recommended actions to extend or quit the guest access.

With the finalization of the access package you will receive a link which can be used to invite the guests. Pass it over to the Team owners, to enable them to invite guests from the connected organization via sharing the link.

Result

What we’ve done now is that we implemented an approval Process for Teams Guests. Only guest from connected Organizations which were authorized via policy to the access package, are able to access request. The Team Owner is able to invite Guests very simply by sending them a link. The Team owners will receive a Access Review were they can check which Guests are in the Team, if they were still active, and can initiate related actions.

Every Guest will stay in the Team for 180 days before he get’s an notification to decide if he want to participate longer or not. If the Guest decides to continue a new approval is started.

Now we just have to care about the native guest invitations in Teams. Because we want guests to be invited via the access package, we could not use the regular process any longer. Unfortunately Teams doesn’t respect the Guest Inviter Role. So every owner will be able to add guests, as long as Guest Invitations are allowed in the Tenant and Team. The trick here is to disable the Guest Invitation Feature „AllowToAddGuests“ in the underlying Office 365 Group

To get this done you have to configure the Group Settings. You might know it from defining Group Creation Limitations, AAD Naming Conventions and so on.

(If you not already have enabled the Template Based Settings you can read how to get it done in general here: Configure group settings using PowerShell – Azure AD | Microsoft Docs. )

To disable the Guest Invitation Feature per Team you can use the AAD PowerShell or use the Microsoft Graph API:

You will recognize that Team Owners are not able to add guests to the Team on the native way anymore. The possibility to add guests to the access package will continue to work.

The following GIF shows a exemplary Guest Invitation Process:

This is pretty much stuff to configure to implement the guest access management. If you decide to build an Access Package per Team and let organization A,B and C participate in the Team, it will be hard to configure this manually every time. But because all these configurations could be done via Graph API you can easily implement it in an automated Teams Deployment Process.

If you need an example how to get this done, and allow the management of the connected organizations in a self service approach, you can read my blog article Another Microsoft Teams Governance Approach – Using Azure AD Identity Governance – thinformatics blog (Yeah, you will need some time to read it, but it’s a step-by-step description to implement Identity Governance into your Teams Deployment Process).

manage-external-communications-in-teams
Manage external Communications in Teams
September 18, 2025
6 Minuten
Microsoft Teams
Security
Collaboration
Microsoft 365
ansatz-zum-behandeln-des-datenabflusses-bei-der-nutzung-von-m365-fr-sensible-accounts
Isolation von sensiblen Accounts in M365
January 9, 2025
10 Minuten
Identity
Security
Enterprise
Compliance
SSE
GSA
export-archiv-mailbox-content-using-ediscovery
Export Exchange Online Archiv Mailbox content using eDiscovery
September 6, 2024
6 Minuten
Compliance
Microsoft Purview
Export
Exchange Online
Archiving
PowerShell
cloning-entra-cloud-sync-jobs
Cloning Entra Cloud Sync Jobs
May 6, 2024
7 Minuten
Entra ID
PowerShell
Cloud Sync
Hybrid
Microsoft Graph API
entra-cloud-sync-group-provisioning-mappings
Entra Cloud Sync - Group Provisioning
February 21, 2024
6 Minuten
Entra ID
Active Directory
Hybrid
Identity
TIL
do-more-with-less-or-do-less-with-more
“Do more with less” or „Do less with more“?
January 10, 2024
8 Minuten
Allgemein
wie-wandle-ich-meine-sharepoint-liste-in-eine-mini-app
Wie wandle ich meine SharePoint-Liste in eine Mini-APP
July 31, 2023
4 Minuten
Citizen Development
Lists
SharePoint
shared-channels-in-microsoft-teams
Shared Channels in Microsoft Teams: So bringen wir unsere Unternehmensgruppe zusammen
April 24, 2023
7 Minuten
Allgemein
Microsoft 365
User Adoption
Entra ID
Security
Microsoft Teams
datengetriebenes-change-management
Datengetriebenes Change Management? Analyse von Nutzungszahlen und deren Aussagekraft bei der Erfolgsmessung der Digitalisierung und User Adoption
April 13, 2023
8 Minuten
Change Management
Messbarkeit
teams-inventory-implement-membership-requests
Teams Inventory – Implement Membership Requests
March 1, 2023
5 Minuten
Allgemein
Governance
Microsoft 365
Power Automate
Power Platform
SharePoint
Microsoft Teams
how-to-build-a-simple-teams-inventory
How to build a simple Teams Inventory
February 17, 2023
9 Minuten
Logic Apps
update-power-automate-dein-day-summary-flow
Update: Power Automate: Dein „Day Summary“-Flow
February 1, 2023
2 Minuten
Citizen Development
Power Automate
power-automate-dein-day-summary-flow
Power Automate: Dein „Day Summary“-Flow
January 4, 2023
2 Minuten
Citizen Development
Power Automate
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-v
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part V
December 27, 2022
5 Minuten
Allgemein
Exchange Online
Microsoft 365
Migrations
PowerShell
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-iv
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part IV
November 30, 2022
5 Minuten
Allgemein
Exchange Online
Microsoft 365
Migrations
PowerShell
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-iii
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part III
November 25, 2022
4 Minuten
Allgemein
Azure
Exchange Online
Microsoft 365
Migrations
PowerShell
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-ii
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part II
November 18, 2022
5 Minuten
Allgemein
Compliance
Exchange Online
Microsoft 365
Microsoft Purview
Migrations
PowerShell
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-i
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part I
November 16, 2022
5 Minuten
Allgemein
Compliance
Exchange Online
Microsoft 365
Microsoft Purview
Migrations
PowerShell
ignite-impressionen-was-ist-neu-in-microsoft-viva
Ignite Impressionen: Was ist neu in Microsoft Viva?
October 28, 2022
5 Minuten
Employee Experience
ignite-impressionen-summary-und-persoenliches-fazit
Ignite Impressionen: Summary und persönliches Fazit zur Session „Microsoft To Do is good for your mental health!“
October 28, 2022
5 Minuten
Allgemein
Microsoft 365
Planner
To Do
ignite-impressionen-microsoft-entra-workload-identities
Ignite Impressionen: Microsoft Entra Workload Identities
October 28, 2022
4 Minuten
Microsoft 365
Entra ID
Conditional Access
Identity
Identity Governance
Identity Protection
ignite-impressionen-microsoft-syntex-die-freundliche-ki-von-nebenan
Ignite Impressionen: Microsoft Syntex – die freundliche KI von nebenan
October 28, 2022
3 Minuten
Allgemein
Microsoft 365
Governance
Information Governance
Power Automate
Power Platform
SharePoint
ignite-impressionen-uebersetzung-mit-ai-builder
Ignite Impressionen: Übersetzung mit AI Builder
October 28, 2022
3 Minuten
Allgemein
Microsoft 365
Citizen Development
Power Automate
Power Platform
SharePoint
how-to-retain-exchange-online-content-an-overview-of-the-different-compliance-options-in-microsoft-365
How to retain Exchange Online content – An overview of the different compliance options in Microsoft 365
September 28, 2022
10 Minuten
Archiving
Compliance
Governance
Retention
azure-ad-guest-governance-automation
Azure AD Guest Governance Automation
August 16, 2022
6 Minuten
Governance
Log Analytics
Logic Apps
assign-teams-app-permission-policies-to-groups
Assign Teams app permission policies to Groups(-Members)
July 1, 2022
8 Minuten
Allgemein
Microsoft 365
Governance
PowerShell
Microsoft Teams
powerautomate-prozente-in-einer-html-tabelle
PowerAutomate: Prozente in einer HTML-Tabelle
May 30, 2022
2 Minuten
Citizen Development
planner-e-mail-report-mit-aufgaben-gruppiert-nach-bucket
Planner E-Mail-Report mit Aufgaben gruppiert nach Bucket
March 31, 2022
3 Minuten
Citizen Development
sharepoint-liste-als-e-mail-uebersicht-mit-personen-feldern-und-odata-meistern
SharePoint-Liste als E-Mail-Übersicht mit Personen-Feldern (und OData meistern)
March 29, 2022
2 Minuten
Citizen Development
Power Automate
use-graph-directory-schema-extensions-for-microsoft-teams-governance
Use Graph Directory Schema Extensions for Microsoft Teams Governance
October 15, 2021
9 Minuten
Microsoft Graph API
teams-invitation-processes-a-comparison
Teams Invitation Processes - A comparison
July 8, 2021
6 Minuten
Access Packages
Compliance
Entitlement Management
Governance
Microsoft Teams
Security
use-more-access-packages
Use more Access Packages!
June 28, 2021
8 Minuten
Access Packages
Identity Governance
Compliance
Governance
Security
Microsoft Teams
microsoft-teams-fulfill-advanced-guest-access-requirements
Microsoft Teams – Fulfill Advanced Guest Access Requirements
December 4, 2020
6 Minuten
Allgemein
Entra ID
Governance
Identity Governance
Microsoft 365
Microsoft Teams
microsoft-365-language-confusion
Microsoft 365 – Language Confusion
September 30, 2020
12 Minuten
Language
another-microsoft-teams-governance-approach-using-azure-ad-identity-governance
Another Microsoft Teams Governance Approach – Using Azure AD Identity Governance
September 18, 2020
21 Minuten
Governance
Identity Governance
Microsoft Teams
planner-migration-tenant-to-tenant
Planner Migration Tenant to Tenant
July 9, 2020
3 Minuten
Migrations
Planner
PowerShell
Tenant to Tenant
flow-instant-raumbuchung
Flow: Instant Raumbuchung
February 25, 2020
2 Minuten
Citizen Development
Power Automate
ai-integrations
ai-solutions
ai-applications
ai-solutions
intranet-solutions
digital-workplace
endpoint-security
security
compliance-regulatorik
security-compliance-zero-trust
plattform-engineering
cloud-plattformen-engineering
endpoint-management-2
workplace
ai-assistants
ai-solutions
cloud-security
security-compliance-zero-trust
cloud-transformation
cloud-strategie-architektur
system-integration
intelligence-automation
business-applications
custom-software
identity-security
security
container-platforms
platform
employee-experience
modern-workplace
collaboration-productivity
modern-workplace
transformation-management
cloud-transformation
application-modernization
cloud-transformation
cloud-governance-und-betriebsmodell
cloud-strategie-architektur
workflow-automation
intelligence-automation
sharepoint-solutions
digital-workplace
security-monitoring
security
collaboration-platforms
workplace
cloud-platforms
platform
virtualization-operations
infrastructure
server-operations
infrastructure
ai-security-compliance
ai-digital-innovation
endpoint-management
modern-workplace
cyber-resillience
security-compliance-zero-trust
identity-access
security-compliance-zero-trust
change-enablement
cloud-transformation
workload-modernization
cloud-transformation
plattformautomatisierung
cloud-plattformen-engineering
hybrid-connectivity
cloud-plattformen-engineering
landing-zones
cloud-plattformen-engineering
business-process-automation
intelligence-automation
microsoft-365-extensions
digital-workplace
apis-integrationen
custom-software
web-applications
custom-software
ai-for-modern-workplace
ai-digital-innovation
aitransformation-adoption
ai-digital-innovation
ai-platforms-engineering
ai-digital-innovation
ai-strategie-und-governance
ai-digital-innovation
workplace-security
modern-workplace
zero-trust
security-compliance-zero-trust
cloud-migration
cloud-transformation
cloud-foundations
cloud-plattformen-engineering
cloud-assesments
cloud-strategie-architektur
hybrid--multi-cloud-strategie
cloud-strategie-architektur
modern-work-adoption
modern-workplace
hybrid--multi-cloud-architektur
cloud-strategie-architektur