Agent Foskett Academy • Microsoft Entra • Module 1 • Lesson 12

Lesson 12 — External Identities and B2B Guest Access

Modern organisations rarely operate inside a single tenant. Partners, suppliers, consultants and contractors often need controlled access to applications, Teams, SharePoint sites and business resources.

Microsoft Entra External Identities supports secure business-to-business collaboration while allowing guest users to authenticate with identities they already own.

This lesson explains guest invitations, redemption, cross-tenant access settings, Conditional Access, access governance and the investigation process when external access becomes excessive or suspicious.

External collaboration should be easy to grant, deliberately governed and equally easy to remove.
Agent Foskett Microsoft Entra External Identities and B2B Guest Access lesson
What you will learn

This lesson explains how Microsoft Entra enables and governs collaboration with external users.

B2B guest invitations and redemption
Cross-tenant access settings
Conditional Access for guests
Guest reviews and investigations

Learning objectives

After completing this lesson, you should be able to explain, secure and investigate Microsoft Entra External Identities.

  • Describe B2B collaboration and guest user objects.
  • Explain invitation and redemption behaviour.
  • Understand cross-tenant access settings and trust controls.
  • Apply Conditional Access and governance to external users.
  • Investigate stale, over-privileged or suspicious guest access.

The problem this solves

External people need access to organisational resources, but creating permanent internal accounts for every partner or supplier increases administrative effort and security risk.

External Identities lets organisations collaborate while preserving separation between the home identity and the resource tenant.

What are External Identities?

Microsoft Entra External Identities is the collection of capabilities used to provide access to users who are not members of your workforce tenant.

External user authenticates with a home identity │ ├── Another Microsoft Entra tenant ├── Microsoft account ├── Email one-time passcode └── Supported federated identity provider │ ▼ Guest object exists in your tenant │ Access is evaluated against your policies │ User reaches only assigned resources
Agent Foskett principle:

A guest account is an identity bridge, not a reason to weaken your normal access controls.

B2B collaboration

Business-to-business collaboration allows an external user to access applications and resources in your tenant while authenticating through their own identity provider.

Your organisation controls authorisation, Conditional Access and resource assignment. The external organisation normally controls the user's password and primary authentication lifecycle.

The guest user object

When an external user is invited, Microsoft Entra creates a user object in the resource tenant. The object commonly has a guest user type and records information about the invitation and identity source.

This object can be placed in groups, assigned to applications and included in access reviews just like other identities, subject to tenant policy.

Member and guest accounts compared

Identity typeTypical useKey consideration
MemberEmployees and managed workforce identities.The organisation normally controls the identity lifecycle and authentication methods.
GuestPartners, contractors, suppliers and other external collaborators.The resource tenant controls access, but the home tenant may control authentication.
External memberSelected multi-tenant or cross-organisation scenarios.User type alone does not prove whether the identity is internal or externally governed.

Invitation and redemption

An administrator, application owner or authorised user may invite an external identity. The recipient then redeems the invitation using an accepted identity.

After redemption, the guest object becomes associated with the external identity used during the process.

Email one-time passcode

Where a user cannot authenticate through a supported Microsoft or federated identity, email one-time passcode can provide a temporary authentication path.

This improves accessibility, but it should still be protected with appropriate resource restrictions and review processes.

The B2B access flow

1. Resource owner identifies a collaboration requirement 2. External user is invited or provisioned 3. A guest object is created in Microsoft Entra 4. The user redeems the invitation 5. Authentication occurs through the user's identity provider 6. Cross-tenant and trust settings are evaluated 7. Conditional Access evaluates the sign-in 8. Group, app or resource permissions are checked 9. The user accesses the approved resource 10. Governance processes review and remove access when no longer needed

External collaboration settings

External collaboration settings control who may invite guests, which domains are allowed or blocked, and what directory information guest users can see.

These settings affect the broad tenant posture and should be reviewed before delegating guest invitation capability.

Who can invite guests?

Organisations can restrict invitations to administrators and approved guest inviters, or permit broader invitation rights.

Allowing all users to invite guests may improve collaboration speed, but it also increases the need for monitoring, ownership and access reviews.

Cross-tenant access settings

Cross-tenant access settings define how your tenant collaborates with users and organisations in other Microsoft Entra tenants.

ControlPurposeSecurity question
Inbound accessControls how external users and groups may access your resources.Which users, groups and applications should be allowed?
Outbound accessControls how your users access resources in another tenant.Should employees collaborate with this organisation?
Trust settingsDefines whether MFA, compliant-device or hybrid-join claims from another tenant are accepted.Do you trust the partner's security controls and identity governance?
Organisation-specific settingsOverrides defaults for a named external tenant.Does this partner require stricter or more permissive treatment?

Trusting external MFA

Cross-tenant trust can allow your tenant to accept an MFA claim issued by a partner tenant.

This can reduce repeated prompts, but it means your access decision partly depends on the partner's authentication controls. Trust should be intentional and organisation-specific.

Device trust claims

Organisations may choose to trust compliant-device or Microsoft Entra hybrid-joined-device claims from selected partners.

Before doing so, validate that the external organisation has mature device-management, compliance and incident-response processes.

Conditional Access for guest users

Guest and external identities should be included deliberately in Conditional Access design.

Policy controlGuest applicationCommon caution
Require MFAProtect external access to business resources.Confirm whether external MFA claims are trusted or local MFA registration is required.
Authentication strengthRequire stronger methods for sensitive applications.Not every external tenant supports the same authentication methods.
Terms of useRequire acceptance of collaboration or confidentiality conditions.Track reacceptance and language requirements.
Session controlsLimit persistence or apply app-enforced restrictions.Shared or unmanaged devices may require stricter sessions.
Risk controlsRespond to suspicious external sign-ins where signals are available.Identity-risk visibility may differ across tenancy boundaries.

Resource assignment

A guest should receive access through controlled groups, enterprise applications, Teams, SharePoint permissions or access packages.

Avoid broad tenant-wide access simply because the user is external. Assign only the resources required for the collaboration.

Use access packages

Entitlement Management can package applications, groups and SharePoint sites into a governed external-access process.

Approval, expiration, connected organisations and periodic reviews help ensure guest access has a clear business owner and end date.

Guest lifecycle and governance

Business need identified │ ▼ Invite or request access through an access package │ ▼ Approve, assign resources and apply Conditional Access │ ▼ Monitor sign-ins and resource use │ ▼ Run recurring access reviews │ ▼ Renew valid access or remove stale guest assignments │ ▼ Delete unused guest objects when appropriate

Access reviews for guests

Guest access reviews can ask sponsors, managers, resource owners or the guests themselves to confirm whether access is still required.

Reviewers should have enough context to understand the relationship, resource purpose and recent usage before making a decision.

Guest sponsors and ownership

Every external relationship should have an internal owner or sponsor responsible for validating continued need.

Without clear ownership, stale guest accounts often remain because nobody is accountable for removing them.

External identity investigation process

1. Identify the guest account and external organisation 2. Confirm who invited or sponsored the user 3. Review invitation and redemption state 4. Check assigned groups, applications and resource permissions 5. Review sign-in logs, IP addresses, device context and Conditional Access results 6. Inspect cross-tenant access and trust settings 7. Check access package assignments and expiration 8. Review recent access-review decisions 9. Confirm whether the business relationship still exists 10. Remove access, revoke sessions or disable the account if required 11. Document the root cause and improve governance controls
Investigation question:

Was the guest's activity genuinely required collaboration, or did old access remain after the business relationship had ended?

Real-world scenario: the contractor finished six months ago

1. A security analyst notices a guest signing into SharePoint 2. The account belongs to a former project contractor 3. The original sponsor has left the organisation 4. The guest still belongs to a project collaboration group 5. No access package expiration was configured 6. No guest access review has run for twelve months 7. Sign-in logs show the guest recently downloaded project documents 8. Security disables the guest and revokes active sessions 9. Resource owners confirm the contract ended six months earlier 10. Guest reviews, sponsor ownership and expiration are introduced for the project

Investigate the sign-in

Review the authentication requirement, identity provider, IP address, device information, application, Conditional Access result and session details.

A successful external sign-in is not automatically malicious, but it must align with an active business relationship and approved resource access.

Investigate the access path

Determine whether access came from direct assignment, group membership, an access package, a Teams membership or SharePoint permissions.

Removing only the guest object may not fix the governance weakness that allowed uncontrolled assignment.

Common mistakes

MistakeWhy it creates riskBetter practice
Everyone can invite guests without oversightGuest creation grows without ownership or consistent approval.Delegate invitation rights deliberately and monitor invitations.
Guest access has no expirationTemporary collaboration becomes permanent access.Use access-package expiration and recurring reviews.
External users are excluded from Conditional AccessGuests may bypass MFA, session or device controls.Include guest and external-user categories in policy design.
External MFA is trusted globallyYour tenant relies on unknown partner security standards.Use organisation-specific trust only after assessment.
No internal sponsor is recordedNobody can validate whether access remains necessary.Require a business owner and review sponsor changes.
Inactive guest objects are ignoredOld accounts remain available for future misuse.Review stale guests, remove assignments and delete unused objects where appropriate.

Key takeaways

  • Microsoft Entra External Identities enables secure collaboration with people outside your workforce tenant.
  • B2B users normally authenticate with an identity controlled by their home organisation.
  • The resource tenant still controls authorisation, Conditional Access and access governance.
  • Cross-tenant access settings define inbound, outbound and trust relationships.
  • External MFA and device claims should be trusted only for assessed partner organisations.
  • Access packages, sponsors, expiration and access reviews reduce stale guest access.
  • Investigations must connect sign-in evidence with the current business relationship and the actual resource assignment path.

Continue learning

Continue through Microsoft Entra identity security, or return to the academy roadmap.
⬅ Previous lesson
Lesson 11 — Lifecycle Workflows in Microsoft EntraAutomate joiner, mover and leaver identity lifecycle tasks.
🏠 Academy home
Microsoft Entra AcademyReview the roadmap and continue through the identity security learning path.
📘 Next lesson
Lesson 13 — Enterprise Applications in Microsoft EntraLearn how enterprise applications, service principals and application assignments control access.

Microsoft Entra External Identities and B2B Guest Access

Microsoft Entra External Identities enables secure B2B collaboration for partners, suppliers, contractors and guest users using invitations, cross-tenant access settings, Conditional Access and access reviews.

Microsoft Entra Academy Lesson 12 — External Identities and B2B Guest Access

This Agent Foskett lesson explains guest user objects, invitation redemption, cross-tenant trust, guest governance, sign-in investigation and stale external access remediation.