Microsoft 365 makes it easy to collaborate with people outside your organization. Invite a consultant to a Teams channel, share a folder with an auditor or add a vendor to a SharePoint site, and they become a guest user in your tenant. That is convenient. The problem is that guests rarely get removed. Months or years later, former contractors and old partners still hold access to documents that may include sensitive information.
A regular guest review is a simple way to tighten that exposure.
Forgotten access. The project ended, but the invitation never expired.
Weaker controls on their side. A guest's own organization or personal email account may have weaker security than yours, and a compromise there can lead to your data.
Overly broad permissions. Guests added to a Microsoft 365 group or Team may see more than intended, including files and conversations.
Unclear ownership. Nobody remembers who invited them or why.
Pending invitations. Invitations sent but never accepted can linger and be redeemed later.
Compliance concerns. In healthcare, outside access to protected health information needs a business purpose, appropriate agreements and monitoring.
Your administrators can list guest users in the Microsoft 365 or Microsoft Entra admin center, usually filtered by user type. Export the list and review fields such as:
Display name and email address.
The domain they come from. Personal email domains deserve extra attention.
When the account was created.
Invitation status, accepted or pending.
Last sign-in activity, where available.
Which groups, Teams and sites they belong to.
Even a quick look often turns up surprises.
Before cleaning up, set expectations.
Who may invite guests? Limit this to specific roles or require approval.
What can guests do? Review tenant settings for guest permissions and external sharing, and set them to the minimum your work requires.
Which domains are acceptable? You can allow or block specific domains.
What agreements are needed? If a guest may touch protected health information, confirm a business associate agreement or similar arrangement is in place, and involve your compliance officer.
Flag guests with no sign-in for a set period, such as 90 days, and any pending invitations older than a few weeks.
For remaining guests, ask the internal owner or sponsor whether the access is still needed. Where licensing supports it, Microsoft offers access review features that can automate sending these questions to owners and removing access when there is no answer. Otherwise a spreadsheet and an email works.
Delete guests who are no longer needed. For those who stay, trim group memberships and permissions to what they actually use.
Review files and folders shared with anyone with a link or with external recipients. Remove links that are no longer needed.
Note what was reviewed, who approved and what was removed. This documentation supports your HIPAA access management and audit practices.
Expire guest access. Where possible, set access to end automatically, or require periodic recertification.
Name a sponsor. Every guest should have an internal person responsible for them.
Require strong sign-in. Apply multifactor authentication requirements to guest access through conditional access, where your licensing allows.
Use groups wisely. Grant access to specific Teams or sites, not broad ones.
Review on a schedule. Quarterly is a good rhythm for most small organizations, and more often for sensitive data.
Monitor activity. Watch for unusual guest downloads or sign-ins from unexpected locations.
You do not have to build a perfect governance program. Begin with a one-time cleanup, then set a recurring calendar reminder. Even this basic habit removes a large portion of the risk.
UnityCare IT can audit your Microsoft 365 tenant for guest users and external sharing, clean up stale access and set policies so new invitations are controlled and expire. We can also set up a recurring review so outside access stays limited to people who truly need it.
Microsoft 365, cloud storage and tested backups with access controls built in.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172