
Nick Ross [MVP] (T-Minus365) recently published a YouTube video that clearly explains how external or Guest users end up inside Microsoft 365 tenants. In plain terms, the video walks IT teams and managed service providers through the two main paths that create these accounts and why many organizations unknowingly collect hundreds or even thousands of them. Consequently, the piece reads as a practical field guide rather than a high-level theory session, and it focuses on real settings and behaviors that administrators encounter every day. As a result, viewers leave with specific checks they can run and settings they can change right away.
First, the video separates guest account creation into two clear avenues: intentional invitations and automatic creation through collaboration tools. Intentional invitations happen when admins or permitted users add external people to Microsoft 365 groups or send invites from Microsoft Entra (formerly Azure AD). Meanwhile, automatic creation can occur behind the scenes when users share files or folders via SharePoint, Teams, or OneDrive and the tenant allows SharePoint B2B integration to create identities on first access.
Importantly, Nick shows that both paths result in a directory object listed under Users > Guest users, but the origin and governance for each differ. Thus, organizations need to treat these two flows differently when evaluating security, lifecycle, and cleanup. Moreover, knowing exactly which path created a guest account helps decide whether to revoke access, require reauthentication, or simply document partner relationships. Therefore, the distinction matters for both security audits and operational hygiene.
Next, the video drills into deliberate invitations: admins add external emails through the Microsoft Entra portal or by adding members to Teams and Microsoft 365 groups. Nick demonstrates the invite flow, including how a user accepts an email link and becomes a guest in the tenant, and he explains roles such as Guest Inviter and User Administrator that control who can perform these actions. As a result, administrators can lock down invitations by assigning least-privilege roles rather than broad administrator rights.
At the same time, intentional invites offer clear tradeoffs: they are straightforward and auditable, but if many people can invite guests the tenant can still grow quickly. Therefore, the video recommends controlled delegation, CSV or PowerShell for bulk invites, and policies that log invitations for review. In short, deliberate invites are easy to govern if teams apply consistent rules and monitoring.
Arguably the more subtle issue Nick highlights is automatic guest creation when users share content externally using file links. With default collaboration settings, a simple share can create a guest identity without an explicit invitation workflow, so organizations often wake up to a large set of unmanaged guest accounts. Consequently, this automatic path is the primary reason tenants accumulate unseen external users over time.
Because these creations happen during day-to-day collaboration, the challenge lies in detection and remediation rather than prevention alone. Nick points out that the SharePoint B2B integration setting governs whether these implicit accounts are created, so reviewing that setting is a practical first step. However, turning off automatic creation can break smooth partner workflows, which creates a balancing act between security and productivity.
The video then covers governance: administrators should review default Entra external collaboration settings and the SharePoint integration option that controls automatic guest creation. Nick shows how to find these settings and advises running regular guest account reviews, which can be automated with scripts or third-party tools to scale the effort. Consequently, systematic discovery and periodic cleanup prevent the directory from becoming a liability.
Nevertheless, tightening settings introduces tradeoffs: stricter controls reduce accidental guest creation but can also slow genuine collaboration with partners. Therefore, organizations must decide which teams need open sharing and which require stricter oversight. As a result, many IT teams adopt a hybrid approach—restrict auto-creation globally but allow exceptions for specific sites or service accounts.
In conclusion, Nick frames the guidance as practical steps: identify how guests are created in your tenant, check the SharePoint B2B integration toggle, assign invitation privileges carefully, and run regular cleanup or review cycles. He stresses automation for discovery and invites administrators to enforce policies that balance security with collaboration needs, because manual reviews alone rarely scale in larger organizations. Therefore, combining technical controls with clear policies and communication yields the best results.
Ultimately, the video is a useful, action-oriented resource for IT staff and MSPs who need to understand where guest users come from and how to manage them. While stricter settings can reduce risk, they also risk disrupting partner workflows, so teams must weigh control against convenience. By following the checks and tradeoffs Nick outlines, organizations can reach a workable balance that protects assets while keeping collaboration effective.
guest users Microsoft 365, invite guest users Azure AD, add guest user Microsoft 365 tenant, Azure AD B2B collaboration guest users, external users Microsoft 365 guest access, create guest user Azure AD portal, Microsoft Teams guest access setup, manage guest user permissions Azure AD