Microsoft 365: How Guest Users Are Added
Microsoft Entra
Mar 8, 2026 4:42 PM

Microsoft 365: How Guest Users Are Added

by HubSite 365 about Nick Ross [MVP] (T-Minus365)

Microsoft expert guide to guest users in Microsoft Three Sixty Five via Entra Teams SharePoint OneDrive auto creation

Key insights

  • Two main creation paths
    Guest accounts appear either by deliberate invites (via Microsoft Entra, Teams, or groups) or automatically when users share files or folders through SharePoint/OneDrive using SharePoint B2B integration.
  • Default external collaboration settings
    Many tenants allow regular users to invite guests by default in Microsoft Entra; review and tighten these settings to control who can send invitations.
  • SharePoint B2B integration
    File or link sharing can silently create guest identities on first access—check and disable the automatic guest-creation setting if you want to stop behind-the-scenes accounts.
  • Guest account behavior
    Invited guests get an email and accept via a link; automatically created guests appear when an external user first accesses a shared resource. Guests are lightweight directory objects that use their own credentials, not full member accounts.
  • Governance and roles
    Assign least-privilege roles (for example, Guest Inviter or User Administrator), run regular guest reviews, and use PowerShell or CSV bulk tools to manage large guest lists and enforce invitation restrictions.
  • Why tenants accumulate guests
    Unrestricted user invitations, implicit creation from sharing, and lack of periodic cleanup cause large numbers of unmanaged guests—schedule audits, disable automatic creation where needed, and limit who can invite external users.

Nick Ross [MVP] (T-Minus365) recently published a YouTube video that clearly explains how external or Guest users end up inside Microsoft 365 tenants. In plain terms, the video walks IT teams and managed service providers through the two main paths that create these accounts and why many organizations unknowingly collect hundreds or even thousands of them. Consequently, the piece reads as a practical field guide rather than a high-level theory session, and it focuses on real settings and behaviors that administrators encounter every day. As a result, viewers leave with specific checks they can run and settings they can change right away.


How guest accounts actually appear

First, the video separates guest account creation into two clear avenues: intentional invitations and automatic creation through collaboration tools. Intentional invitations happen when admins or permitted users add external people to Microsoft 365 groups or send invites from Microsoft Entra (formerly Azure AD). Meanwhile, automatic creation can occur behind the scenes when users share files or folders via SharePoint, Teams, or OneDrive and the tenant allows SharePoint B2B integration to create identities on first access.


Importantly, Nick shows that both paths result in a directory object listed under Users > Guest users, but the origin and governance for each differ. Thus, organizations need to treat these two flows differently when evaluating security, lifecycle, and cleanup. Moreover, knowing exactly which path created a guest account helps decide whether to revoke access, require reauthentication, or simply document partner relationships. Therefore, the distinction matters for both security audits and operational hygiene.


Intentional invitations and Teams membership

Next, the video drills into deliberate invitations: admins add external emails through the Microsoft Entra portal or by adding members to Teams and Microsoft 365 groups. Nick demonstrates the invite flow, including how a user accepts an email link and becomes a guest in the tenant, and he explains roles such as Guest Inviter and User Administrator that control who can perform these actions. As a result, administrators can lock down invitations by assigning least-privilege roles rather than broad administrator rights.


At the same time, intentional invites offer clear tradeoffs: they are straightforward and auditable, but if many people can invite guests the tenant can still grow quickly. Therefore, the video recommends controlled delegation, CSV or PowerShell for bulk invites, and policies that log invitations for review. In short, deliberate invites are easy to govern if teams apply consistent rules and monitoring.


Silent guest creation from SharePoint and OneDrive

Arguably the more subtle issue Nick highlights is automatic guest creation when users share content externally using file links. With default collaboration settings, a simple share can create a guest identity without an explicit invitation workflow, so organizations often wake up to a large set of unmanaged guest accounts. Consequently, this automatic path is the primary reason tenants accumulate unseen external users over time.


Because these creations happen during day-to-day collaboration, the challenge lies in detection and remediation rather than prevention alone. Nick points out that the SharePoint B2B integration setting governs whether these implicit accounts are created, so reviewing that setting is a practical first step. However, turning off automatic creation can break smooth partner workflows, which creates a balancing act between security and productivity.


Governance controls and discovery steps

The video then covers governance: administrators should review default Entra external collaboration settings and the SharePoint integration option that controls automatic guest creation. Nick shows how to find these settings and advises running regular guest account reviews, which can be automated with scripts or third-party tools to scale the effort. Consequently, systematic discovery and periodic cleanup prevent the directory from becoming a liability.


Nevertheless, tightening settings introduces tradeoffs: stricter controls reduce accidental guest creation but can also slow genuine collaboration with partners. Therefore, organizations must decide which teams need open sharing and which require stricter oversight. As a result, many IT teams adopt a hybrid approach—restrict auto-creation globally but allow exceptions for specific sites or service accounts.


Practical recommendations and tradeoffs for teams

In conclusion, Nick frames the guidance as practical steps: identify how guests are created in your tenant, check the SharePoint B2B integration toggle, assign invitation privileges carefully, and run regular cleanup or review cycles. He stresses automation for discovery and invites administrators to enforce policies that balance security with collaboration needs, because manual reviews alone rarely scale in larger organizations. Therefore, combining technical controls with clear policies and communication yields the best results.


Ultimately, the video is a useful, action-oriented resource for IT staff and MSPs who need to understand where guest users come from and how to manage them. While stricter settings can reduce risk, they also risk disrupting partner workflows, so teams must weigh control against convenience. By following the checks and tradeoffs Nick outlines, organizations can reach a workable balance that protects assets while keeping collaboration effective.


Microsoft Entra - Microsoft 365: How Guest Users Are Added

Keywords

guest users Microsoft 365, invite guest users Azure AD, add guest user Microsoft 365 tenant, Azure AD B2B collaboration guest users, external users Microsoft 365 guest access, create guest user Azure AD portal, Microsoft Teams guest access setup, manage guest user permissions Azure AD