In Focus
No items found.
thinformatics
Back to the blog
Access Packages
Compliance
Entitlement Management
Governance
Microsoft Teams
Security

Teams Invitation Processes - A comparison

Hi, in this blog article, I deal with Microsoft Teams and Guest User handling. If you’ve read my latest articles here you might have recognized that I’ve talked a lot about Identity Governance and its relevance for Teams. Now I want to share a short comparison about the different methods to invite guests...

Jakob Schaefer
Jakob Schaefer
Consultant & SME Team GRC[br]Governance, Risk & Compliance
July 8, 2021
6 Minuten
Reading time

Hi,

in this blog article, I deal with Microsoft Teams and Guest User handling. If you’ve read my latest articles here you might have recognized that I’ve talked a lot about Identity Governance and its relevance for Teams.

Now I want to share a short comparison about the different methods to invite guests to Teams which also cares about the costs that will come up while using the different approaches

Let’s say a company plans to use Teams to collaborate with external users. The external Users should be able to communicate in Teams Conversation with Members of the organization and access Files which that were shared in the Teams SharePoint Site. Other Applications used within Teams should be available for external users too.

There are different ways available how external users can gain access. I will describe the common scenarios here:

1. Non managed native Teams Guest Invitation

The native and default way to invite guests to a team is to allow Team Owners to invite their members as they want. The Owners can use the Teams build-in Feature to add guests. If they use an external E-Mail address to identify the external user here, in the background an AAD Guest Object will be generated, and an invitation is sent out to the targeted external user. The user can accept the invitation and will receive a mail that contains a link that allows him to navigate to the shared team.

The guest is a member of the Team until a team owner or an admin removes him from the underlying Microsoft 365 Group, or until an admin removes his guest account from the Azure AD. The guest User AD object will persist in the Azure AD until an admin will delete it.

2. Managed native Teams Guest Invitations

A variant of the first option is to allow Team owners to invite only external Users which already exist in the AAD. So, the general Guest Onboarding is decoupled from the native Teams experience. In this case, the guest user must be created administratively in the AAD before a Teams Owner can invite him in any Team. When the Guest object exists and the Teams owner uses the native Teams member add function, the guest user receives a mail that contains a link that allows him to navigate to the shared team.

The guest is a member of the Team until a team owner or admin removes him from the underlying Microsoft 365 Group, or until A admin removes his guest account from the Azure AD. The guest User AD object will persist in the Azure AD until an admin will delete it.

3. Access Packages

An access Package can be used to assign Team Memberships. The assignment can be an administrative task, but it also allows Self Service. Team Owners and other users that are aware of the link can send out an Access Package Link to allow external users to request their Team membership. The membership request is managed by policies that were defined primarily. The policy can contain e.g. an approval process with multiple stages to verify and justify the team membership of every single guest. The policy also contains an expiry process for assignments that allows authorized or defined persons and access package requestors to recertificate their team membership in intervals.

An approved Access Package Requests will generate an Azure AD Guest object for the approved external identity.

Using this option, the Team Owner cannot/should not use the native Teams way to invite guests. He must use the link to invite new guests.

The guest is now a member of the Team until an authorized user/admin removes the access package assignment, or until a user/reviewer does not recertify his membership when the Access Package expires, or an active review is started. The Azure AD Guest Object can be deleted automatically if it loses all Access Packages assignment to support the AAD hygiene.

Decision Making

An organization can decide which option should be used. The options 1. & 3., or 2. & 3. can be combined. Options 1. and 2. are an “either-or” decision.

It depends on requirements or your Business, your IT Dept, and maybe regulatory requirements, which option fits best.

If costs are a factor for a decision, you can use the following information to include it into your decision making:

Option 1 & 2 is included in the smaller Microsoft 365 Licenses, no additional Licenses are needed

Option 3 requires an AAD P2 License for every involved person. An (eligible) internal Requestor, an approver, a reviewer needs to have an AAD P2 License assigned. For external Users, every Guest that has been assigned an Access Package is relevant for licensing. (You can read here the official Licensing requirements)

You don’t need to assign AAD P2 Licenses to Guest Users. Right now, there are two different methods guilty to count the external identities usage of the AAD B2B Features:

1:5 Ratio: For every AAD P2 License which was assigned to an internal member, five guests user are allowed to use the same features

50.000 Guests flat rate: The first 50.000 Guests users are free to use AAD P1+P2 Features. After that, every additional external identity will generate costs (0.002741 € per monthly active user).

The second model replaces the first and is the new default if you have connected your M365 Tenant to an Azure Subscription. You can read about it here.

Option 1 is rarely used in enterprise organizations because of the missing management capabilities. The potential spillage and danger of potential data loss of this option lead in most cases to higher costs afterward.

Option 2 is a common way to manage external identities in larger organizations. The potential spillage and danger of potential data loss are moderate. Costs in the AAD operation Team and Service Desk will be generated for the onboarding of external identities, and the AAD hygiene.

Option 3 is an enterprise solution to manage access to resources. The potential spillage and danger of potential data loss is low (Read the Blog Article ‘Use more Access Packages!’ if you need to know more about Access Packages and their possibilities). Costs will be generated in the Service Desk / User Admin Team to support the handling of access packages. These costs can be reduced with adequate user training.

It is a strong recommendation to include Option 3 in a Teams deployment process to automate the creation of access packages for teams. This generates initial costs but reduces the operation costs throughout the lifetime.

Option 3 can be used for internal access management also, but because of the licensing requirement, it often starts with the management of external access.

Other Considerations:

The following considerations can also impact a decision for one or another option.

Azure AD Guests are not synced with the OnPrem AD DS and can only be Managed via AAD DS, so you can’t use well-tried onprem solutions to manage Guests.

If you use SMS / Phone-Based MFA for External Identities, there will be additional costs per authentication attempt using the new external identities billing model.

You can configure on M365 Group base which Teams should be enabled for external usage at all. You can define and solve this by a specific setting per Team or assigning a Sensitivity Label.

Access Packages can not only be used for Teams, but you can also manage the access to SharePoint Online Sites and Azure Applications.

manage-external-communications-in-teams
Manage external Communications in Teams
September 18, 2025
6 Minuten
Microsoft Teams
Security
Collaboration
Microsoft 365
ansatz-zum-behandeln-des-datenabflusses-bei-der-nutzung-von-m365-fr-sensible-accounts
Isolation von sensiblen Accounts in M365
January 9, 2025
10 Minuten
Identity
Security
Enterprise
Compliance
SSE
GSA
export-archiv-mailbox-content-using-ediscovery
Export Exchange Online Archiv Mailbox content using eDiscovery
September 6, 2024
6 Minuten
Compliance
Microsoft Purview
Export
Exchange Online
Archiving
PowerShell
cloning-entra-cloud-sync-jobs
Cloning Entra Cloud Sync Jobs
May 6, 2024
7 Minuten
Entra ID
PowerShell
Cloud Sync
Hybrid
Microsoft Graph API
entra-cloud-sync-group-provisioning-mappings
Entra Cloud Sync - Group Provisioning
February 21, 2024
6 Minuten
Entra ID
Active Directory
Hybrid
Identity
TIL
do-more-with-less-or-do-less-with-more
“Do more with less” or „Do less with more“?
January 10, 2024
8 Minuten
Allgemein
wie-wandle-ich-meine-sharepoint-liste-in-eine-mini-app
Wie wandle ich meine SharePoint-Liste in eine Mini-APP
July 31, 2023
4 Minuten
Citizen Development
Lists
SharePoint
shared-channels-in-microsoft-teams
Shared Channels in Microsoft Teams: So bringen wir unsere Unternehmensgruppe zusammen
April 24, 2023
7 Minuten
Allgemein
Microsoft 365
User Adoption
Entra ID
Security
Microsoft Teams
datengetriebenes-change-management
Datengetriebenes Change Management? Analyse von Nutzungszahlen und deren Aussagekraft bei der Erfolgsmessung der Digitalisierung und User Adoption
April 13, 2023
8 Minuten
Change Management
Messbarkeit
teams-inventory-implement-membership-requests
Teams Inventory – Implement Membership Requests
March 1, 2023
5 Minuten
Allgemein
Governance
Microsoft 365
Power Automate
Power Platform
SharePoint
Microsoft Teams
how-to-build-a-simple-teams-inventory
How to build a simple Teams Inventory
February 17, 2023
9 Minuten
Logic Apps
update-power-automate-dein-day-summary-flow
Update: Power Automate: Dein „Day Summary“-Flow
February 1, 2023
2 Minuten
Citizen Development
Power Automate
power-automate-dein-day-summary-flow
Power Automate: Dein „Day Summary“-Flow
January 4, 2023
2 Minuten
Citizen Development
Power Automate
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-v
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part V
December 27, 2022
5 Minuten
Allgemein
Exchange Online
Microsoft 365
Migrations
PowerShell
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-iv
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part IV
November 30, 2022
5 Minuten
Allgemein
Exchange Online
Microsoft 365
Migrations
PowerShell
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-iii
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part III
November 25, 2022
4 Minuten
Allgemein
Azure
Exchange Online
Microsoft 365
Migrations
PowerShell
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-ii
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part II
November 18, 2022
5 Minuten
Allgemein
Compliance
Exchange Online
Microsoft 365
Microsoft Purview
Migrations
PowerShell
tenant-to-tenant-pst-based-exchange-migration-automation-approach-part-i
Tenant-to-Tenant – PST based Exchange Migration automation approach – Part I
November 16, 2022
5 Minuten
Allgemein
Compliance
Exchange Online
Microsoft 365
Microsoft Purview
Migrations
PowerShell
ignite-impressionen-was-ist-neu-in-microsoft-viva
Ignite Impressionen: Was ist neu in Microsoft Viva?
October 28, 2022
5 Minuten
Employee Experience
ignite-impressionen-summary-und-persoenliches-fazit
Ignite Impressionen: Summary und persönliches Fazit zur Session „Microsoft To Do is good for your mental health!“
October 28, 2022
5 Minuten
Allgemein
Microsoft 365
Planner
To Do
ignite-impressionen-microsoft-entra-workload-identities
Ignite Impressionen: Microsoft Entra Workload Identities
October 28, 2022
4 Minuten
Microsoft 365
Entra ID
Conditional Access
Identity
Identity Governance
Identity Protection
ignite-impressionen-microsoft-syntex-die-freundliche-ki-von-nebenan
Ignite Impressionen: Microsoft Syntex – die freundliche KI von nebenan
October 28, 2022
3 Minuten
Allgemein
Microsoft 365
Governance
Information Governance
Power Automate
Power Platform
SharePoint
ignite-impressionen-uebersetzung-mit-ai-builder
Ignite Impressionen: Übersetzung mit AI Builder
October 28, 2022
3 Minuten
Allgemein
Microsoft 365
Citizen Development
Power Automate
Power Platform
SharePoint
how-to-retain-exchange-online-content-an-overview-of-the-different-compliance-options-in-microsoft-365
How to retain Exchange Online content – An overview of the different compliance options in Microsoft 365
September 28, 2022
10 Minuten
Archiving
Compliance
Governance
Retention
azure-ad-guest-governance-automation
Azure AD Guest Governance Automation
August 16, 2022
6 Minuten
Governance
Log Analytics
Logic Apps
assign-teams-app-permission-policies-to-groups
Assign Teams app permission policies to Groups(-Members)
July 1, 2022
8 Minuten
Allgemein
Microsoft 365
Governance
PowerShell
Microsoft Teams
powerautomate-prozente-in-einer-html-tabelle
PowerAutomate: Prozente in einer HTML-Tabelle
May 30, 2022
2 Minuten
Citizen Development
planner-e-mail-report-mit-aufgaben-gruppiert-nach-bucket
Planner E-Mail-Report mit Aufgaben gruppiert nach Bucket
March 31, 2022
3 Minuten
Citizen Development
sharepoint-liste-als-e-mail-uebersicht-mit-personen-feldern-und-odata-meistern
SharePoint-Liste als E-Mail-Übersicht mit Personen-Feldern (und OData meistern)
March 29, 2022
2 Minuten
Citizen Development
Power Automate
use-graph-directory-schema-extensions-for-microsoft-teams-governance
Use Graph Directory Schema Extensions for Microsoft Teams Governance
October 15, 2021
9 Minuten
Microsoft Graph API
teams-invitation-processes-a-comparison
Teams Invitation Processes - A comparison
July 8, 2021
6 Minuten
Access Packages
Compliance
Entitlement Management
Governance
Microsoft Teams
Security
use-more-access-packages
Use more Access Packages!
June 28, 2021
8 Minuten
Access Packages
Identity Governance
Compliance
Governance
Security
Microsoft Teams
microsoft-teams-fulfill-advanced-guest-access-requirements
Microsoft Teams – Fulfill Advanced Guest Access Requirements
December 4, 2020
6 Minuten
Allgemein
Entra ID
Governance
Identity Governance
Microsoft 365
Microsoft Teams
microsoft-365-language-confusion
Microsoft 365 – Language Confusion
September 30, 2020
12 Minuten
Language
another-microsoft-teams-governance-approach-using-azure-ad-identity-governance
Another Microsoft Teams Governance Approach – Using Azure AD Identity Governance
September 18, 2020
21 Minuten
Governance
Identity Governance
Microsoft Teams
planner-migration-tenant-to-tenant
Planner Migration Tenant to Tenant
July 9, 2020
3 Minuten
Migrations
Planner
PowerShell
Tenant to Tenant
flow-instant-raumbuchung
Flow: Instant Raumbuchung
February 25, 2020
2 Minuten
Citizen Development
Power Automate
ai-integrations
ai-solutions
ai-applications
ai-solutions
intranet-solutions
digital-workplace
endpoint-security
security
compliance-regulatorik
security-compliance-zero-trust
plattform-engineering
cloud-plattformen-engineering
endpoint-management-2
workplace
ai-assistants
ai-solutions
cloud-security
security-compliance-zero-trust
cloud-transformation
cloud-strategie-architektur
system-integration
intelligence-automation
business-applications
custom-software
identity-security
security
container-platforms
platform
employee-experience
modern-workplace
collaboration-productivity
modern-workplace
transformation-management
cloud-transformation
application-modernization
cloud-transformation
cloud-governance-und-betriebsmodell
cloud-strategie-architektur
workflow-automation
intelligence-automation
sharepoint-solutions
digital-workplace
security-monitoring
security
collaboration-platforms
workplace
cloud-platforms
platform
virtualization-operations
infrastructure
server-operations
infrastructure
ai-security-compliance
ai-digital-innovation
endpoint-management
modern-workplace
cyber-resillience
security-compliance-zero-trust
identity-access
security-compliance-zero-trust
change-enablement
cloud-transformation
workload-modernization
cloud-transformation
plattformautomatisierung
cloud-plattformen-engineering
hybrid-connectivity
cloud-plattformen-engineering
landing-zones
cloud-plattformen-engineering
business-process-automation
intelligence-automation
microsoft-365-extensions
digital-workplace
apis-integrationen
custom-software
web-applications
custom-software
ai-for-modern-workplace
ai-digital-innovation
aitransformation-adoption
ai-digital-innovation
ai-platforms-engineering
ai-digital-innovation
ai-strategie-und-governance
ai-digital-innovation
workplace-security
modern-workplace
zero-trust
security-compliance-zero-trust
cloud-migration
cloud-transformation
cloud-foundations
cloud-plattformen-engineering
cloud-assesments
cloud-strategie-architektur
hybrid--multi-cloud-strategie
cloud-strategie-architektur
modern-work-adoption
modern-workplace
hybrid--multi-cloud-architektur
cloud-strategie-architektur