Guest Accounts in Your Microsoft 365 Tenant: Finding and Removing the Forgotten Ones
Guest accounts make Microsoft 365 collaboration easier. They allow customers, suppliers, contractors and advisers to access selected Teams, SharePoint sites, applications and documents without receiving a full employee account.
The problem is that guest access often lasts much longer than the business relationship that created it.
A contractor finishes a project, but their account remains in Microsoft Entra ID. A supplier changes personnel, yet the former contact still belongs to a Team. A customer receives access to one SharePoint site and is never removed after the contract ends.
Over time, these forgotten accounts create unnecessary access paths into your Microsoft 365 environment.
Microsoft provides several ways to find, review and remove stale guests, including the Microsoft 365 admin centre, Microsoft Entra sign-in information and automated Access Reviews.
What Is a Microsoft 365 Guest Account?
A guest account is an external identity represented inside your Microsoft Entra tenant.
Guests may be invited through:
- Microsoft Teams
- SharePoint Online
- Microsoft 365 groups
- Microsoft Entra External ID
- Enterprise applications
- Access packages
Once created, the guest appears in the tenant’s user directory and in the Guest users section of the Microsoft 365 admin centre. Depending on the permissions granted, they may be able to attend meetings, participate in Teams conversations, access documents or use assigned business applications.
Guest users normally have more limited directory permissions than internal members, although the organisation’s external collaboration settings can alter those restrictions.
The important point is that being labelled Guest does not tell you whether the account still has a valid business purpose.
Why Forgotten Guest Accounts Matter
An old guest account may retain access through:
- Microsoft Teams membership
- Microsoft 365 groups
- SharePoint site permissions
- Direct file or folder sharing
- Enterprise application assignments
- Security groups
- Azure resources
- Shared channels
Even when the account has not signed in recently, it may still be capable of accessing information if its original identity remains active.
Forgotten guests increase the risk of:
- Former contractors accessing company files
- Departed supplier employees retaining permissions
- Compromised partner accounts reaching your resources
- Confidential information being available outside the organisation
- Poor audit and compliance outcomes
- Nobody being able to explain why access was granted
Microsoft specifically recommends monitoring and cleaning up stale guests because external collaboration can cause guest identities to accumulate over time.
Start With the Microsoft 365 Guest Users List
For a quick initial review:
- Open the Microsoft 365 admin centre.
- Expand Users.
- Select Guest users.
- Review the displayed external accounts.
- Export or document the list where necessary.
This gives you a basic tenant-wide inventory.
For each account, record:
Field | What to check |
Display name | Is the person recognisable? |
Email address | Does the organisation still work with them? |
Company | Is the external business relationship active? |
Created date | How long has the account existed? |
Last sign-in | Has the guest used the tenant recently? |
Sponsor or owner | Who is responsible for the access? |
Groups and Teams | What resources can the guest reach? |
Applications | Are enterprise apps assigned? |
The Microsoft 365 admin centre can also be used to delete a guest, but deletion should come after you understand the access and business impact.
Review Guests in Microsoft Entra ID
The Microsoft Entra admin centre provides more identity detail than the basic Microsoft 365 guest list.
Go to:
Microsoft Entra ID → Users → All users
Then filter User type to Guest.
Review properties such as:
- Account status
- Creation type
- External user state
- Invitation acceptance
- Group memberships
- Assigned applications
- Directory roles
- Sign-in activity
- Registered devices where applicable
Be careful when relying solely on the UserType property. Microsoft notes that it represents the user’s relationship with the organisation and can technically be changed between Guest and Member, so it should be interpreted alongside the account’s actual purpose and access.
Use Sign-In Activity as a Clue, Not the Final Decision
A guest who has not signed in for six months might be stale.
But inactivity alone does not prove the account is unnecessary.
The guest may:
- Access an annual reporting site
- Work on a seasonal project
- Be an emergency legal contact
- Use an application that generates less obvious sign-in activity
- Have access that has never yet been used
Likewise, recent activity does not prove the access is legitimate. A compromised external account may be actively signing in.
Use sign-in information alongside:
- Contract status
- Group and Team membership
- Application assignments
- Site ownership
- Business sponsor confirmation
- Audit activity
Microsoft Entra sign-in records are system generated and cannot be edited or deleted, making them useful evidence during an access review.
Identify Who Owns Each Guest Relationship
Every guest should have an internal business sponsor.
That sponsor should be able to answer:
- Why was this person invited?
- Which organisation do they represent?
- What resources do they require?
- Is the relationship still active?
- When should the access end?
- Who should replace them if their role changes?
Accounts without an identifiable sponsor should receive priority during the review.
IT should not be expected to guess whether an external solicitor, consultant or customer contact is still needed. The department that owns the relationship should confirm the decision.
A practical ownership model might assign responsibility to:
- The Team owner
- The SharePoint site owner
- The application owner
- The project manager
- The supplier manager
- The employee who requested the invitation
Check Group, Teams and Application Membership
Deleting a guest without reviewing their assignments can disrupt an active project.
Before removal, check whether the guest belongs to:
- Microsoft 365 groups
- Microsoft Teams
- Security groups
- Distribution lists
- Enterprise applications
- Access packages
- Azure subscriptions or resources
Also check whether they are:
- A Team owner
- A SharePoint site owner
- An application owner
- Assigned to an administrative role
- The only external contact for a workflow
A guest with ownership or privileged access deserves immediate investigation. Ownership should normally be transferred to an appropriate internal account before deletion.
Review SharePoint and OneDrive Access Separately
A guest may have access through a direct SharePoint permission or sharing invitation rather than an obvious Team membership.
Review:
- SharePoint site members
- Site visitors
- Direct file permissions
- Folder permissions
- Specific people links
- External sharing reports
- Microsoft 365 group membership
Microsoft advises that stopping external sharing may require removing the guest’s permissions from the shared content or deleting the guest identity from the directory.
This distinction matters because removing someone from one Team does not necessarily remove access they hold elsewhere.
Create a Simple Guest Classification
During the review, classify each account into one of four categories.
Keep
The guest has a current business need, an active sponsor and appropriate access.
Restrict
The guest is still required, but their permissions are broader than necessary.
Possible actions include:
- Removing them from old Teams
- Limiting SharePoint access
- Removing unused application assignments
- Replacing edit access with view access
Block Pending Review
The account appears stale or risky, but you need confirmation before deletion.
Blocking sign-in can provide a temporary safety measure while the sponsor is contacted.
Remove
The business relationship has ended, the access is unnecessary or no valid owner can justify keeping it.
Use Microsoft Entra Access Reviews
Manual reviews work for small tenants, but they become difficult as the number of guests grows.
Microsoft Entra ID Governance Access Reviews can periodically ask appropriate reviewers to confirm whether guests should retain access to groups, Teams and applications.
Reviews can be completed by:
- Group owners
- Application owners
- Selected internal reviewers
- The guest users themselves, where appropriate
Microsoft Entra can also create reviews that focus on inactive guests and apply results automatically. Depending on the selected settings, denied external identities can be blocked from signing in and deleted after a 30-day period.
Access Reviews can be configured to run:
- Once
- Monthly
- Quarterly
- Every six months
- Annually
A quarterly review is a sensible starting point for high-risk external access. Lower-risk collaboration may justify a six-monthly schedule.
Licensing varies according to the review features and users involved. Microsoft notes that inactive-user scoping and certain governance recommendations require appropriate Microsoft Entra ID Governance licensing.
Consider Entitlement Management for New Guests
Entitlement Management can make external access more structured by packaging groups, Teams, SharePoint sites and applications into controlled access packages.
An access package can include:
- Approval requirements
- Access expiration
- Periodic reviews
- Named sponsors
- Terms of use
- Automatic removal when the assignment ends
Microsoft can also remove an external user’s guest identity after they lose their final access-package assignment, when that option is configured.
This is considerably safer than inviting guests manually and relying on someone to remember them years later.
How to Remove a Guest Safely
Before deleting the account:
- Confirm the sponsor’s decision.
- Record the guest’s current access.
- Transfer any ownership responsibilities.
- Remove access from relevant groups, sites and applications.
- Preserve audit evidence if the account is under investigation.
- Notify the guest or business owner where appropriate.
- Delete the user from Microsoft Entra ID or the Microsoft 365 admin centre.
Deleted users normally enter a recoverable, soft-deleted state before permanent deletion. Administrators can restore them during that period or permanently delete them sooner when required.
Do not permanently delete an account immediately when there is a legal, HR, fraud or security investigation without confirming evidence-preservation requirements.
Do Not Automatically Delete Every Inactive Guest
Automated cleanup can be valuable, but careless automation can remove legitimate access.
Before applying automatic deletion:
- Define inactivity carefully.
- Exclude exceptional business cases.
- Give sponsors adequate notice.
- Use a block-first period where possible.
- Test the process with a pilot group.
- Confirm how application and non-interactive activity is represented.
- Document restoration procedures.
A guest who has not signed in for 90 days may still be required for an annual audit. Business context must remain part of the decision.
A Practical Guest Account Review Schedule
Monthly
Review:
- Newly created guests
- Guests with privileged roles
- Guests assigned to sensitive applications
- High-risk sign-ins
- Invitations from unexpected users
Quarterly
Review:
- Inactive guest accounts
- Teams and Microsoft 365 group membership
- High-risk SharePoint sites
- External application assignments
- Accounts without sponsors
Annually
Complete a wider review of:
- All guest identities
- Guest-access policies
- Cross-tenant access settings
- External collaboration defaults
- Access Review configuration
- Entitlement Management packages
- Guest-related Conditional Access
Common Guest Account Mistakes
Treating Every Guest as Low Risk
A guest may have access to sensitive documents, applications or Azure resources.
Reviewing Only the Guest Users List
The list tells you who exists, not everything they can access.
Deleting Without Checking Ownership
The guest may own a Team, application or important collaborative resource.
Using Inactivity as the Only Test
Some legitimate guests use resources infrequently.
Leaving Access Without an Expiry
Temporary collaboration becomes permanent access.
Allowing Guests to Accumulate Without Sponsors
Nobody takes responsibility for reviewing or removing them.
Relying on Manual Reviews Forever
Manual spreadsheets become unreliable as the tenant grows.
Guest Account Audit Checklist
- Export or review all guest identities.
- Identify last sign-in activity.
- Confirm the external organisation.
- Assign an internal sponsor.
- Review group and Team membership.
- Review SharePoint and OneDrive access.
- Check enterprise application assignments.
- Investigate privileged roles and ownership.
- Block or remove accounts without a valid purpose.
- Configure recurring Access Reviews.
- Introduce expiration for future guest access.
- Repeat the review regularly.
Final Thoughts
Guest accounts are essential for Microsoft 365 collaboration, but they should never be permanent by accident.
Every external identity should have:
- A current business purpose
- A named internal sponsor
- The minimum access required
- A review date
- A clear removal process
Start by inventorying the guests in Microsoft 365 and Microsoft Entra ID. Review sign-in activity, Teams, groups, SharePoint permissions and application assignments. Remove accounts connected to completed projects, former suppliers and departed partner employees.
For ongoing control, use Microsoft Entra Access Reviews and Entitlement Management to make external access expire, require approval and return for periodic confirmation.
The objective is not to eliminate guest collaboration.
It is to make sure every guest still belongs in your tenant.
Unsure Who Still Has Guest Access to Your Microsoft 365 Environment?
Hamilton Group can help you audit and secure external identities across Microsoft 365.
Our experts can help you:
- Inventory Microsoft Entra guest accounts
- Identify inactive and forgotten users
- Review Teams, groups and SharePoint access
- Find guests with privileged roles
- Configure Microsoft Entra Access Reviews
- Introduce access expiration and sponsorship
- Deploy Entitlement Management
- Restrict external collaboration
- Remove obsolete guests safely
- Build an ongoing guest-governance process
Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to find and remove the external accounts your organisation no longer needs.