{"id":756,"date":"2020-06-22T14:51:28","date_gmt":"2020-06-22T19:51:28","guid":{"rendered":"https:\/\/itblog.ldlnet.net\/?p=756"},"modified":"2020-06-22T14:57:54","modified_gmt":"2020-06-22T19:57:54","slug":"grant-an-external-user-guest-access-to-your-m365-tenant","status":"publish","type":"post","link":"https:\/\/itblog.ldlnet.net\/index.php\/2020\/06\/22\/grant-an-external-user-guest-access-to-your-m365-tenant\/","title":{"rendered":"Grant an External User Guest Access to your M365 Tenant"},"content":{"rendered":"\n<p>Microsoft365 allows the tenant administrators to grant external users access to content in their tenant by setting them up as a guest in their M365 Tenant. Microsoft365 provides a guest access feature that you can use to grant content access to contractors, partners or others who need access to certain content.<\/p>\n\n\n\n<p>However, the process of setting up a guest user works differently from that of setting up a normal, licensed user from within your organization.<\/p>\n\n\n\n<p>By default, Microsoft365 Admin Center contains a Guest Users screen. You will also notice, however, that this screen does not contain an option to create a guest user. In fact, the only things that you can do are search for a user or delete a user.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"449\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-5-1024x449.png\" alt=\"\" class=\"wp-image-757\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-5-1024x449.png 1024w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-5-300x132.png 300w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-5-768x337.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-5-1536x674.png 1536w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-5.png 1819w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Limited Access to Administrate Guest Users in M365<\/figcaption><\/figure>\n\n\n\n<p>Being that the Guest Users screen doesn&#8217;t give you a way to create a guest user, you will need to either delve into PowerShell or perform the task within Azure Active Directory. I prefer using PowerShell, and will write a post about how to perform this via PowerShell, but unless you need to create a large number of guest users, it is usually going to be easier to use the GUI. Below is how to create a guest user via Azure AD.<\/p>\n\n\n\n<p>To create a guest user, expand the Admin Centers container and then click on <strong>Azure Active Directory<\/strong>. When the Azure Active Directory Admin Center opens, click on the <strong>Users<\/strong> container. You can see that just to the right of the New User option, there is an option to create a <strong>New Guest User<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"332\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-7-1024x332.png\" alt=\"\" class=\"wp-image-759\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-7-1024x332.png 1024w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-7-300x97.png 300w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-7-768x249.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-7-1536x498.png 1536w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-7.png 1917w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Create New Guest User<\/figcaption><\/figure>\n\n\n\n<p class=\"has-text-color has-small-font-size has-medium-pink-color\"><strong>NOTE: Creating a guest user account isn&#8217;t like creating a normal user account. Rather than providing the account details and clicking a Create button, you will instead need to send an invitation to the user. <\/strong><br><br><strong><em>Make Sure You Verify Their E-Mail Address Beforehand!!!<\/em><\/strong><\/p>\n\n\n\n<p><strong>Choose Invite User <\/strong>&gt; <strong>Enter the Identity Information<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"650\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-8-1024x650.png\" alt=\"\" class=\"wp-image-760\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-8-1024x650.png 1024w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-8-300x190.png 300w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-8-768x487.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-8-1536x974.png 1536w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-8-2048x1299.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Initial Data Entry<\/figcaption><\/figure>\n\n\n\n<p><strong>Next Enter A Personal Message (optional)<\/strong> &gt; <strong>Choose their Group Membership<\/strong> &gt; <strong>Update any AAD or M365 Permissions under Roles<\/strong> &gt; <strong>Update their Sign In Settings<\/strong> &gt; <strong>Click Invite to send the invitation<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"738\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-10-1024x738.png\" alt=\"\" class=\"wp-image-762\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-10-1024x738.png 1024w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-10-300x216.png 300w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-10-768x553.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-10-1536x1107.png 1536w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-10-2048x1476.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Enter Data and Settings Then Click Invite Button<\/figcaption><\/figure>\n\n\n\n<p>After a few minutes, the specified user will receive an e-mail invitation that looks something like the one shown below. The recipient will need to click the Accept Invitation button and accept the terms of use.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"705\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-11-1024x705.png\" alt=\"\" class=\"wp-image-763\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-11-1024x705.png 1024w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-11-300x207.png 300w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-11-768x529.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-11-1536x1058.png 1536w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-11-2048x1411.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Example of Email Generated Invitation<\/figcaption><\/figure>\n\n\n\n<p>When the guest user completes the registration process, they are logged into Microsoft365 however, there are no applications initially available to the user. <strong><em>This is because unlike a standard user, external users do not automatically get access to applications.<\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"494\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-16-1024x494.png\" alt=\"\" class=\"wp-image-772\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-16-1024x494.png 1024w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-16-300x145.png 300w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-16-768x371.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-16-1536x742.png 1536w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-16.png 1860w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>User Has Verified Access and Accepted the Invitation<\/figcaption><\/figure>\n\n\n\n<p>If you go back to the Guest Users screen, you will see the newly created guest user listed (you may have to refresh the screen). As previously noted, you can&#8217;t do much from this screen. You can, however, click on the user to see a few extra details now. Example is below.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"490\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-12-1024x490.png\" alt=\"\" class=\"wp-image-764\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-12-1024x490.png 1024w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-12-300x144.png 300w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-12-768x368.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-12-1536x736.png 1536w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-12-2048x981.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>More Details Available<\/figcaption><\/figure>\n\n\n\n<p>The way that you grant an external user access to data is to add the user to a group that has access to the data. Let&#8217;s suppose, for example, that for whatever reason, you need to add an external user to a Teams Group named <strong>Microsoft Exchange Guys<\/strong>. To do so, you would go to the Groups folder within the Microsoft 365 Admin Center, click on the <strong>Microsoft Exchange Guys<\/strong> group, and then edit the Membership list, as shown below.<\/p>\n\n\n\n<p class=\"has-small-font-size\"><strong><em>After clicking the Edit button, click on Add Members and then select the external user that you wish to add. Click Save to complete the process,<\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"530\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-13-1024x530.png\" alt=\"\" class=\"wp-image-765\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-13-1024x530.png 1024w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-13-300x155.png 300w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-13-768x397.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-13-1536x795.png 1536w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-13-2048x1060.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>The New Guest User Will Show When Searching To Add Users To The Group<\/figcaption><\/figure>\n\n\n\n<p>If you now go back to the Group&#8217;s membership, you are able to see the Microsoft Exchange Guys group membership showing the new guest user as a member.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"904\" height=\"1024\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-14-904x1024.png\" alt=\"\" class=\"wp-image-766\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-14-904x1024.png 904w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-14-265x300.png 265w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-14-768x870.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-14-1356x1536.png 1356w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-14.png 1608w\" sizes=\"auto, (max-width: 904px) 100vw, 904px\" \/><figcaption>Guest User Has Been Added To The Group<\/figcaption><\/figure>\n\n\n\n<p>Granting access in this way does not provide the external user with blanket access to the Teams Group. However, another group member is now able to e-mail the external user a link to the Teams Group. The external user can use this link to access the Group within the Teams app.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"577\" src=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-15-1024x577.png\" alt=\"\" class=\"wp-image-767\" srcset=\"https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-15-1024x577.png 1024w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-15-300x169.png 300w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-15-768x433.png 768w, https:\/\/itblog.ldlnet.net\/wp-content\/uploads\/2020\/06\/image-15.png 1490w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>User is now in Teams Group<\/figcaption><\/figure>\n\n\n\n<p class=\"has-text-color has-small-font-size has-medium-pink-color\"><strong>NOTE: Keep in mind that I am only using the Teams Group as an example. You can use somewhat similar techniques to provide access to a variety of Microsoft365 AND Azure AD content.<\/strong><\/p>\n\n\n\n<h2 class=\"has-text-align-center wp-block-heading\">MORE M365 CONTENT TO COME!<br>POSITIVE ATTITUDE = POSITIVE RESULTS<\/h2>\n\n\n\n<p class=\"has-small-font-size\"><strong>REFERENCES:<\/strong><br><a href=\"https:\/\/redmondmag.com\/articles\/2018\/12\/12\/enable-guest-access-for-office-365.aspx\" target=\"_blank\" rel=\"noreferrer noopener\">How To Enable Guest Access for Office 365<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft365 allows the tenant administrators to grant external users access to content in their tenant by setting them up as a guest<\/p>\n<p class=\"link-more\"><a class=\"myButt \" href=\"https:\/\/itblog.ldlnet.net\/index.php\/2020\/06\/22\/grant-an-external-user-guest-access-to-your-m365-tenant\/\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":769,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48,195,2,194],"tags":[248,90,190,192,250,238,177,252,88,77,153,251,249],"class_list":["post-756","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-active-directory","category-azure","category-general","category-office365","tag-admin-center","tag-azure","tag-azure-ad","tag-azure-portal","tag-guest-access","tag-m365","tag-microsoft-365","tag-microsoft-teams","tag-o365","tag-office365","tag-permissions","tag-teams","tag-users","odd"],"_links":{"self":[{"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/posts\/756","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/comments?post=756"}],"version-history":[{"count":4,"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/posts\/756\/revisions"}],"predecessor-version":[{"id":773,"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/posts\/756\/revisions\/773"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/media\/769"}],"wp:attachment":[{"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/media?parent=756"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/categories?post=756"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itblog.ldlnet.net\/index.php\/wp-json\/wp\/v2\/tags?post=756"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}