First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management

Guest and External Users in Microsoft 365: Who Needs a License and Who Does Not

2026-09-13·IT PartnerNewMicrosoft EntraLicensingSecurityTeams

Outside people reach a Microsoft 365 tenant in at least five ways, and only some of them create an account you can see. Licensing follows the mechanism, not the person. This is which paths need a license, which are metered by monthly active users, and which cost nothing but control.

Five doors into your tenant

Microsoft's external collaboration overview lists the ways people outside your organization can reach your resources, and the account each one uses. File, folder, site and team sharing use a guest account, and all three are enabled by default. Shared channels in Teams and external chat and meetings use the person's existing Microsoft 365 account in their own organization; external chat is on by default, shared channels are off. Anonymous meeting join and unauthenticated Anyone links use no account at all, and both are on by default. Cross-cloud sharing and multitenant organization sharing are off until you configure them.

Nothing happens until one of your users initiates it, and each door has a different licensing answer, because a guest object, a federated identity and an anonymous link are three different things to Microsoft's billing.

B2B guests: no license for most collaboration, a meter for identity

A guest is a user object in your Microsoft Entra directory created through B2B collaboration. They sign in with their own work, school or social credentials, or with an email one-time passcode, which Microsoft now turns on by default. You manage the object like any other user, add it to groups and assign it to apps, but you never hold their password.

On the Microsoft 365 side the rule is stated plainly in Microsoft's collaboration overview: guests do not require a license for most features of collaboration. They see only what you share with them.

On the identity side the model is different. Microsoft Entra External ID bills by monthly active users: the count of unique external users who authenticate to your tenant in a calendar month. It applies to any user whose UserType is Guest, including internal guests created with local credentials, and not to Members. Microsoft's licensing page says External ID core features are available at no charge for the first 50,000 monthly active users, and the billing page says a workforce tenant must be linked to an Azure subscription for proper billing and feature access. Microsoft's guest billing documentation ties premium guest features to that monthly-active-user model rather than to per-guest P1 or P2 licenses; confirm the current terms on the External ID pricing page before you plan on it.

Optional add-ons carry their own meters: SMS-based authentication per authentication event, Microsoft Entra ID Governance for guests per monthly active user, and Global Secure Access for guests.

Shared channels and B2B direct connect: no guest object at all

Teams shared channels use B2B direct connect, a mutual trust between two Microsoft Entra organizations set in each side's cross-tenant access settings. Both organizations must enable it. The external user stays in their home tenant, signs in with their home credentials, and reaches your channel from their own Teams client without switching accounts. Microsoft says the access token is valid for one hour and that these users have no presence in your directory; the channel owner manages them inside Teams.

The access boundary is the channel. A direct connect user sees the shared channel, its files and apps, and nothing else in the team or tenant. The reverse is also true: a B2B guest invited to a team cannot see or take part in any shared channel in it.

If your Conditional Access policies require multifactor authentication, you must configure inbound trust settings to accept the partner's MFA claims, otherwise their users are blocked. Microsoft's overview states that licensing and billing for External ID, direct connect included, are based on monthly active users, so there is no license to buy for the partner's staff.

External access, anonymous join and Anyone links

External access, sometimes called federation, lets your users chat, call and meet with people in other Microsoft 365 organizations, and with unmanaged Teams and Skype accounts if you allow it. No guest account is created; the other party stays signed in to their own organization and has no access to your teams or channels. You can allow or block specific domains, or block all. Nothing is licensed on your side.

Anonymous meeting join lets someone with the link enter a meeting after typing a display name. Microsoft is blunt that the identity of an anonymous participant cannot be verified before, during or after the meeting; the lobby and meeting policies are your only controls.

Anyone links on files and folders in Teams, SharePoint and OneDrive give access to whoever holds the link, with no authentication and no audit trail of who used it. Owners can revoke a link at any time. None of these three needs a license, and all three need a policy decision.

Entra External ID for customer-facing apps

Customers of your own application are not guests, and they should not be in the workforce tenant that holds your staff. Microsoft Entra External ID in an external tenant is the customer identity and access management configuration: a separate tenant holding your app registrations and a directory of consumer or business-customer accounts, with self-service sign-up flows, email or one-time-passcode sign-in, Google, Facebook, Apple, Microsoft Entra ID or custom OpenID Connect federation, per-app branding, and custom authentication extensions for your own business logic.

The boundaries matter. Single sign-on to Microsoft 365 is not supported from an external tenant; it exists for your SaaS or custom apps, not for Teams and SharePoint. The external tenant must be linked to an Azure subscription owned by a workforce tenant.

Billing is the same monthly-active-user model, applied to every user in the external tenant, administrators included. Premium add-ons are transaction- or MAU-based: machine-to-machine authentication per authentication transaction, SMS authentication per authentication event, and Go-Local data residency, currently Australia and Japan only. Your customers never need Microsoft 365 licenses. Our Microsoft Entra External ID Implementation service sets up the tenant, the user flows and the app integration.

The meters that surprise, and the cleanup that prevents them

Microsoft Entra ID Governance for guests is the one that catches finance off guard. Guests are billed only in a month when a governance-only feature acts on them: a lifecycle workflow runs, an access review with machine-learning recommendations or an inactive-guest review includes them, an access package is auto-assigned, or an administrator marks them as governed. Each guest is charged once per month however many actions occur; P2 features are not billed. Members from a tenant in your multitenant organization do not accrue to the meter, though a multitenant organization itself requires Microsoft Entra ID P1 in every participating tenant.

The older cost is stale access. By default every user in your organization, guests included, can invite more guests. External collaboration settings decide who may invite and which domains are allowed; cross-tenant access settings decide which organizations can authenticate at all. A guest object with no sponsor, no review and no expiry is a permanent permission, and Microsoft 365 Copilot will index whatever it can reach, as we described in Copilot oversharing: the hidden risk and how to fix it.

A practical baseline for a 20-to-500-seat tenant: restrict invitations to a role, set a default cross-tenant policy and add partner-specific ones, run recurring access reviews on groups that admit guests, and record a sponsor on every invitation. Managed Entra ID Identity Hygiene and Access Reviews keeps that running month to month.

FAQ: guest and external licensing questions we hear most

Do guests need a Microsoft 365 license to edit our files?

No. Microsoft states guests do not require a license for most collaboration features; they see only what you share. Some premium workloads carry their own guest rules, so check the product page for anything beyond files, sites and teams.

Do we pay per guest?

Not per seat. External ID bills by monthly active users who actually authenticate, with core features at no charge for the first 50,000 per month, plus optional add-on meters. The tenant must be linked to an Azure subscription for that billing.

Are shared channel members guests?

No. B2B direct connect users have no object in your directory and are managed by the channel owner in Teams. A guest invited to the team cannot see shared channels.

Do partner users need Entra ID P1 for our Conditional Access policies?

Microsoft's guest billing documentation places guests under the External ID monthly-active-user model rather than per-user P1 or P2 licenses; check the pricing page for current terms. For direct connect users, configure inbound trust settings so their home tenant's MFA and device claims are accepted.

Should customers of our app be guests in our tenant?

No. Put them in an External ID external tenant, which is built for consumer and business-customer sign-in and keeps them out of your staff directory.

Who needs what: external access paths compared

Scenario Account in your tenant Default License from you What Microsoft meters
Share a file, site or team with a partner Guest (B2B collaboration) Enabled None for most collaboration features External ID monthly active users; first 50,000 at no charge
Teams shared channel with another organization None; B2B direct connect Disabled None External ID monthly active users
Chat, call or meet with another Microsoft 365 organization None; external access Enabled None Nothing
Anonymous meeting join None Enabled None Nothing
Anyone link on a file or folder None Enabled None Nothing
Customers signing in to your own app Separate external tenant Not applicable None; Microsoft 365 SSO not supported External ID monthly active users, plus add-ons such as M2M and SMS
Governance actions on guests Guest Off until configured None ID Governance for guests, per guest per month with a billable action
Multitenant organization Member or guest, synced Disabled Microsoft Entra ID P1 in every tenant ID Governance meter skipped for participating tenants

Sources

  • Microsoft Learn, "IT Admins - Overview of external collaboration options in Microsoft 365" (microsoft-365/enterprise/external-guest-access)
  • Microsoft Learn, "Microsoft Entra External ID pricing and billing overview" (entra/external-id/external-identities-pricing)
  • Microsoft Learn, "What is Microsoft Entra B2B collaboration?" (entra/external-id/what-is-b2b)
  • Microsoft Learn, "B2B direct connect overview" (entra/external-id/b2b-direct-connect-overview)
  • Microsoft Learn, "Introduction to Microsoft Entra External ID" (entra/external-id/external-identities-overview)
  • Microsoft Learn, "Overview: Secure your apps using External ID in an external tenant" (entra/external-id/customers/overview-customers-ciam)
  • Microsoft Learn, "Understand and manage the properties of B2B guest users" (entra/external-id/user-properties)
  • Microsoft Learn, "Microsoft Entra ID Governance licensing for guest users" (entra/id-governance)
  • Microsoft Learn, "Microsoft Entra licensing" (entra/fundamentals/licensing)
  • Microsoft Learn, "Plan for multitenant organizations in Microsoft 365" (microsoft-365/enterprise/plan-multi-tenant-org-overview)

Key takeaways

  • Guests do not need a Microsoft 365 license for most collaboration; the identity side is metered by monthly active users, with External ID core features at no charge for the first 50,000 per month.
  • Shared channel members come through B2B direct connect and never exist in your directory; both organizations must enable the trust, and there is nothing to license.
  • External chat and meetings, anonymous join and Anyone links need no account and no license, only a policy decision on whether to allow them.
  • Customers of your own app belong in an Entra External ID external tenant, which has no SSO to Microsoft 365 and is billed per monthly active user.
  • The surprise meters are ID Governance actions on guests and stale guest access; restrict who can invite, set cross-tenant policies and run access reviews.

Building a customer-facing app, or unsure how many guests you actually have? Microsoft Entra External ID Implementation sets up the external tenant, sign-up flows and app integration for your customers, and Microsoft 365 External Sharing and Guest Access Cleanup inventories every guest, Anyone link and cross-tenant relationship before tightening the defaults. Both are fixed-price and quoted in writing; External ID monthly-active-user charges are billed by Microsoft to your Azure subscription.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.