Lesson 12 — External Identities and B2B Guest Access
Modern organisations rarely operate inside a single tenant. Partners, suppliers, consultants and contractors often need controlled access to applications, Teams, SharePoint sites and business resources.
Microsoft Entra External Identities supports secure business-to-business collaboration while allowing guest users to authenticate with identities they already own.
This lesson explains guest invitations, redemption, cross-tenant access settings, Conditional Access, access governance and the investigation process when external access becomes excessive or suspicious.

What you will learn
This lesson explains how Microsoft Entra enables and governs collaboration with external users.
Learning objectives
After completing this lesson, you should be able to explain, secure and investigate Microsoft Entra External Identities.
- Describe B2B collaboration and guest user objects.
- Explain invitation and redemption behaviour.
- Understand cross-tenant access settings and trust controls.
- Apply Conditional Access and governance to external users.
- Investigate stale, over-privileged or suspicious guest access.
The problem this solves
External people need access to organisational resources, but creating permanent internal accounts for every partner or supplier increases administrative effort and security risk.
External Identities lets organisations collaborate while preserving separation between the home identity and the resource tenant.
What are External Identities?
Microsoft Entra External Identities is the collection of capabilities used to provide access to users who are not members of your workforce tenant.
A guest account is an identity bridge, not a reason to weaken your normal access controls.
B2B collaboration
Business-to-business collaboration allows an external user to access applications and resources in your tenant while authenticating through their own identity provider.
Your organisation controls authorisation, Conditional Access and resource assignment. The external organisation normally controls the user's password and primary authentication lifecycle.
The guest user object
When an external user is invited, Microsoft Entra creates a user object in the resource tenant. The object commonly has a guest user type and records information about the invitation and identity source.
This object can be placed in groups, assigned to applications and included in access reviews just like other identities, subject to tenant policy.
Member and guest accounts compared
| Identity type | Typical use | Key consideration |
|---|---|---|
| Member | Employees and managed workforce identities. | The organisation normally controls the identity lifecycle and authentication methods. |
| Guest | Partners, contractors, suppliers and other external collaborators. | The resource tenant controls access, but the home tenant may control authentication. |
| External member | Selected multi-tenant or cross-organisation scenarios. | User type alone does not prove whether the identity is internal or externally governed. |
Invitation and redemption
An administrator, application owner or authorised user may invite an external identity. The recipient then redeems the invitation using an accepted identity.
After redemption, the guest object becomes associated with the external identity used during the process.
Email one-time passcode
Where a user cannot authenticate through a supported Microsoft or federated identity, email one-time passcode can provide a temporary authentication path.
This improves accessibility, but it should still be protected with appropriate resource restrictions and review processes.
The B2B access flow
External collaboration settings
External collaboration settings control who may invite guests, which domains are allowed or blocked, and what directory information guest users can see.
These settings affect the broad tenant posture and should be reviewed before delegating guest invitation capability.
Who can invite guests?
Organisations can restrict invitations to administrators and approved guest inviters, or permit broader invitation rights.
Allowing all users to invite guests may improve collaboration speed, but it also increases the need for monitoring, ownership and access reviews.
Cross-tenant access settings
Cross-tenant access settings define how your tenant collaborates with users and organisations in other Microsoft Entra tenants.
| Control | Purpose | Security question |
|---|---|---|
| Inbound access | Controls how external users and groups may access your resources. | Which users, groups and applications should be allowed? |
| Outbound access | Controls how your users access resources in another tenant. | Should employees collaborate with this organisation? |
| Trust settings | Defines whether MFA, compliant-device or hybrid-join claims from another tenant are accepted. | Do you trust the partner's security controls and identity governance? |
| Organisation-specific settings | Overrides defaults for a named external tenant. | Does this partner require stricter or more permissive treatment? |
Trusting external MFA
Cross-tenant trust can allow your tenant to accept an MFA claim issued by a partner tenant.
This can reduce repeated prompts, but it means your access decision partly depends on the partner's authentication controls. Trust should be intentional and organisation-specific.
Device trust claims
Organisations may choose to trust compliant-device or Microsoft Entra hybrid-joined-device claims from selected partners.
Before doing so, validate that the external organisation has mature device-management, compliance and incident-response processes.
Conditional Access for guest users
Guest and external identities should be included deliberately in Conditional Access design.
| Policy control | Guest application | Common caution |
|---|---|---|
| Require MFA | Protect external access to business resources. | Confirm whether external MFA claims are trusted or local MFA registration is required. |
| Authentication strength | Require stronger methods for sensitive applications. | Not every external tenant supports the same authentication methods. |
| Terms of use | Require acceptance of collaboration or confidentiality conditions. | Track reacceptance and language requirements. |
| Session controls | Limit persistence or apply app-enforced restrictions. | Shared or unmanaged devices may require stricter sessions. |
| Risk controls | Respond to suspicious external sign-ins where signals are available. | Identity-risk visibility may differ across tenancy boundaries. |
Resource assignment
A guest should receive access through controlled groups, enterprise applications, Teams, SharePoint permissions or access packages.
Avoid broad tenant-wide access simply because the user is external. Assign only the resources required for the collaboration.
Use access packages
Entitlement Management can package applications, groups and SharePoint sites into a governed external-access process.
Approval, expiration, connected organisations and periodic reviews help ensure guest access has a clear business owner and end date.
Guest lifecycle and governance
Access reviews for guests
Guest access reviews can ask sponsors, managers, resource owners or the guests themselves to confirm whether access is still required.
Reviewers should have enough context to understand the relationship, resource purpose and recent usage before making a decision.
Guest sponsors and ownership
Every external relationship should have an internal owner or sponsor responsible for validating continued need.
Without clear ownership, stale guest accounts often remain because nobody is accountable for removing them.
External identity investigation process
Was the guest's activity genuinely required collaboration, or did old access remain after the business relationship had ended?
Real-world scenario: the contractor finished six months ago
Investigate the sign-in
Review the authentication requirement, identity provider, IP address, device information, application, Conditional Access result and session details.
A successful external sign-in is not automatically malicious, but it must align with an active business relationship and approved resource access.
Investigate the access path
Determine whether access came from direct assignment, group membership, an access package, a Teams membership or SharePoint permissions.
Removing only the guest object may not fix the governance weakness that allowed uncontrolled assignment.
Common mistakes
| Mistake | Why it creates risk | Better practice |
|---|---|---|
| Everyone can invite guests without oversight | Guest creation grows without ownership or consistent approval. | Delegate invitation rights deliberately and monitor invitations. |
| Guest access has no expiration | Temporary collaboration becomes permanent access. | Use access-package expiration and recurring reviews. |
| External users are excluded from Conditional Access | Guests may bypass MFA, session or device controls. | Include guest and external-user categories in policy design. |
| External MFA is trusted globally | Your tenant relies on unknown partner security standards. | Use organisation-specific trust only after assessment. |
| No internal sponsor is recorded | Nobody can validate whether access remains necessary. | Require a business owner and review sponsor changes. |
| Inactive guest objects are ignored | Old accounts remain available for future misuse. | Review stale guests, remove assignments and delete unused objects where appropriate. |
Key takeaways
- Microsoft Entra External Identities enables secure collaboration with people outside your workforce tenant.
- B2B users normally authenticate with an identity controlled by their home organisation.
- The resource tenant still controls authorisation, Conditional Access and access governance.
- Cross-tenant access settings define inbound, outbound and trust relationships.
- External MFA and device claims should be trusted only for assessed partner organisations.
- Access packages, sponsors, expiration and access reviews reduce stale guest access.
- Investigations must connect sign-in evidence with the current business relationship and the actual resource assignment path.
Related Agent Foskett resources
Continue learning
Microsoft Entra External Identities and B2B Guest Access
Microsoft Entra External Identities enables secure B2B collaboration for partners, suppliers, contractors and guest users using invitations, cross-tenant access settings, Conditional Access and access reviews.
Microsoft Entra Academy Lesson 12 — External Identities and B2B Guest Access
This Agent Foskett lesson explains guest user objects, invitation redemption, cross-tenant trust, guest governance, sign-in investigation and stale external access remediation.
