Microsoft 365 External Sharing and Guest Access Cleanup
Every Microsoft 365 tenant that has collaborated with the outside world for a few years is holding access it never consciously granted: guest accounts from projects that finished years ago, 'Anyone' links pasted into emails in 2022, sites shared with everyone in the organization by someone who has since left, and external members of teams nobody reviews. Microsoft applies no expiry to any of it unless you switch expiry on. This is a fixed-price, two-week cleanup for one tenant. IT Partner inventories every guest in Microsoft Entra ID — invitation source, sponsor, last sign-in, and every group, team and site the guest can reach — plus every anonymous and organization-wide sharing link across the SharePoint sites and OneDrive accounts in scope, every externally shared team and shared channel, and every site whose sharing settings sit outside the baseline we agree with you. We then remove what the owners confirm is finished, tighten the tenant and site defaults that let it accumulate — default link type, link expiry, guest expiry, domain allow and block lists, who may invite — and leave recurring owner-driven reviews running, with a dated before-and-after evidence pack. $2,950 fixed, covering one tenant with up to 500 guest accounts and 100 sites in the cleanup scope; larger estates are quoted per tenant in writing before anything starts. Microsoft licensing, and any metered Microsoft Entra ID Governance charge for governed guests, are yours.
What this engagement is
External access in Microsoft 365 accumulates because nothing in the platform makes it stop. A guest invited for a two-month project keeps the invitation forever; an 'Anyone' link created to get a file to a client keeps working long after the deal closes; a site shared with 'everyone except external users' quietly becomes tenant-wide reading; a partner's staff turn over and their accounts stay. None of it expires by default — guest lifetime, sharing-link lifetime and site-level review are all opt-in settings that most tenants have never turned on. The bill usually arrives as a question rather than a breach: an auditor asking who outside the company can read the finance site, a cyber-insurance questionnaire asking how external access is reviewed, a departed partner nobody thought to remove, or a Microsoft 365 Copilot rollout that makes every over-broad permission suddenly easy to exercise. This engagement answers that question with evidence and then fixes what the evidence shows, in two weeks, for one tenant. We inventory four surfaces, not one. Guests in Microsoft Entra ID: every guest account with its invitation source, sponsor where one was recorded, last sign-in, creation date, and the groups, teams and sites it can reach. Sharing links in SharePoint and OneDrive: anonymous 'Anyone' links, organization-wide links, and links that reach people outside the company, per site and per library across the sites in scope, including the OneDrive accounts of people who have left. Teams and channels: teams with external members, shared channels running on Microsoft Entra B2B direct connect, and the cross-tenant access settings that permit them. Site and tenant settings: the external-sharing level of every in-scope site compared with the baseline you agree, plus externally shared sites with no surviving owner. Everything then lands in one decision workbook — one row per finding, with the owner who has to decide and our recommendation — and removal runs in waves against that workbook, never against a script's opinion. The part most cleanups get wrong is what happens after. Deleting a thousand stale guests and leaving the tenant configured exactly as it was buys you about six months. So the second week is spent on the settings that stop re-accumulation: default sharing link type and permission, expiry on anonymous and guest links, guest access expiry for sites, domain allow or block lists at the Microsoft Entra and SharePoint levels, who is allowed to invite guests at all, per-site sharing levels that match what the site actually holds, and recurring reviews that ask site and team owners — not IT — whether external access is still needed. Where your licensing supports it, those reviews are automated: SharePoint Advanced Management site access reviews delegated to site owners, and Microsoft Entra access reviews scoped to guests. Where it does not, you get the same cadence as a runbook your admins run, and we say so before the project starts rather than at the handover. One structural honesty note, because it changes what a guest cleanup can promise. Guest accounts are only one of the doors. External participants in Teams shared channels connect through Microsoft Entra B2B direct connect and never get a guest object in your directory at all — they stay in their home tenant, and they are governed by your cross-tenant access settings, not by your guest list. Deleting guests does nothing to them. This engagement covers both, and the inventory says plainly which external person reaches you through which mechanism. Boundaries are drawn where the neighbouring services begin. Teams lifecycle governance — naming, creation, expiration, ownerless-team attestation — is Microsoft Teams Governance and Sprawl Cleanup; here we touch Teams only where external access lives. What your own employees can over-reach internally, and what Copilot can therefore surface, is Microsoft 365 Copilot Oversharing Assessment and Remediation. The monthly cycle after this cleanup is Managed Entra ID Identity Hygiene and Access Reviews. And the wider identity-governance programme — access packages, entitlement management, lifecycle workflows for external users — is Microsoft Entra ID Governance Implementation.
Success criteria
What you receive
How the work unfolds
We take the time-bound delegated access you approve, confirm what your licensing makes visible, and run the discovery: guest accounts and their reach from Microsoft Entra ID and Microsoft Graph, sharing-link and permission reports from the SharePoint admin center (data access governance reports where SharePoint Advanced Management is entitled, PowerShell and Graph inventory where it is not), Teams external membership and shared channels, cross-tenant access settings, and per-site sharing configuration. Read-only: nothing changes this week without a decision behind it.
A two-hour working session with whoever owns security and collaboration. We agree the target external-sharing baseline (who may invite, default link type, expiry periods, allowed or blocked domains, which site tiers may share externally at all), the removal posture (remove access, disable then delete, or delete outright, and the response window before the default applies), and the review model you will live with afterwards. Every setting we change traces back to a decision made in this session.
The decision workbook goes to site and team owners through your communications channel: here is who from outside can reach your site, here is what they last did, tell us what to keep. We chase, consolidate the answers, and escalate the sites whose owners do not respond or no longer exist to your named decision-maker — they are never silently deleted and never silently kept.
Execution against the attested workbook, in waves and in a deliberate order: replace live collaborations that depend on anonymous links with specific-people links first, then revoke the stale links, then remove guest access from groups, teams and sites, then disable or delete the guest accounts per the agreed policy. Each wave is logged, checked against Microsoft's audit records, and paused if anything looks wrong.
The tenant and site settings that let it all accumulate are brought to the approved baseline — Microsoft Entra external collaboration settings, cross-tenant access, SharePoint and OneDrive sharing defaults, link and guest expiry, domain lists, per-site sharing levels. Then the reviews are configured and started: site access reviews delegated to site owners, and guest access reviews in Microsoft Entra ID, with the scope, cadence and non-response behaviour agreed at the workshop.
Discovery is re-run for the before-and-after report, the runbook is walked through with your admins, the first review cycle is inspected together, and the residual backlog — anything outside the fixed scope — is written down and costed so nothing quietly disappears at the end of the engagement.
Prerequisites
Who does what
IT Partner
- Run the discovery across all four surfaces and present it as evidence a non-specialist can act on, not as raw exports.
- Put every policy choice in front of you with its trade-off before implementing it, and record the decision.
- Drive the attestation: prepare the owner communications, chase, consolidate, and escalate what nobody answers.
- Execute removals in the agreed order and posture, with logging, verification against Microsoft's audit records, and a documented restore path for each type of action.
- Implement the tenant and site sharing baseline and the recurring reviews, and prove they work by watching one cycle complete.
- Deliver the before-and-after report and the runbook, and hand over the residual backlog costed and in writing.
Your team
- Approve the delegated access request and confirm the licensing position we verify at kickoff.
- Make the baseline decisions at the workshop — this is your external-collaboration policy, not a template we impose.
- Send the owner communications through your channel, on the agreed schedule.
- Arbitrate escalations: sites and teams where no owner responds need a business decision, not an IT default applied quietly.
- Approve each removal wave before it runs, and the deletion queue explicitly.
- Own the review cycle after handover — or move it to the managed service if you would rather we ran it.
What's not included
Limitations & technical notes
Frequently asked questions
Will removing guests and links break work that is still going on?
That is the risk the whole method is built around, so the order of operations is deliberate. Nothing is removed until the site or team owner has looked at the row and answered. Live collaborations that depend on an anonymous link are re-shared as specific-people links before the old link is revoked, so the partner keeps working through a link that is now attributable. Guest accounts can be removed from resources, disabled for an agreed period, or deleted — your choice, recorded before the first wave. And a deleted guest account is restorable inside Microsoft's documented 30-day window, so a mistake in week two is recoverable in week six.
What actually counts as 'external access' in Microsoft 365?
Four different mechanisms, which is why counting guest accounts alone under-reports the problem. Guest accounts in Microsoft Entra ID (B2B collaboration) are the visible ones. Anonymous 'Anyone' links in SharePoint and OneDrive grant access with no account at all — whoever holds the URL. Organization-wide links are internal but frequently behave like external exposure once a link leaves the building. And Teams shared channels use Microsoft Entra B2B direct connect, where the external person keeps working in their own tenant and never appears in your guest list. This engagement inventories all four and tells you which people reach you through which door.
Do we need SharePoint Advanced Management for this?
No, but it changes how the reporting is produced. SharePoint Advanced Management supplies the data access governance reports and the site access reviews that let you delegate a finding straight to a site owner. Microsoft makes most of its features available to SharePoint administrators once at least one Microsoft 365 Copilot licence is assigned in the tenant; otherwise it is a paid add-on, and not every feature is covered by the Copilot route. We check your exact entitlement in the first two days. Without it, we produce the same inventory through PowerShell and Microsoft Graph and run the attestation through your own communications — more manual to build, identical decisions at the end.
Do we need Microsoft Entra ID P2 or ID Governance for the recurring reviews?
It depends on the review you want. Access reviews of groups and applications, including reviews scoped to guest users, are a Microsoft Entra ID P2 capability. The features that make guest review genuinely low-effort — reviews scoped to inactive guests using a tenant-level inactivity threshold, machine-learning reviewer recommendations, catalogue reviews and lifecycle workflows for guests — are Microsoft Entra ID Governance features. Those are billed by Microsoft per monthly active governed guest and require an Azure subscription linked to your tenant; that charge is yours and we will not pretend otherwise. If you hold neither, the review cadence ships as a runbook and we execute one cycle with your admins.
How do you work out who invited a guest nobody remembers?
In order of reliability: the Sponsors field on the guest object, where it was populated at invitation; the invitation and audit records showing which account created the guest and when; and the resources the guest can reach, which tells you which site owner has to decide. Microsoft documents a gap here — guests created by SharePoint sharing do not get a sponsor recorded — so for the oldest accounts the honest answer is often that accountability has to be re-established rather than looked up. Setting sponsors correctly going forward is part of the baseline we implement.
Will you delete guest accounts, or just remove their access?
Whichever you decide, and the decision is made at the workshop before anything is executed. Removing a guest from a group, team or site ends the access but keeps the account, which is right when the relationship is dormant rather than over. Disabling the account blocks sign-in while keeping everything reversible — the pattern Microsoft's own guidance uses for stale guests is to block sign-in first and delete after a defined period. Deleting removes the account entirely, with the 30-day restore window as the safety net. Most clients land on: remove access at the resource for anything ambiguous, disable-then-delete for guests inactive beyond the threshold they set.
What happens to Teams shared channels and the partners in them?
They are inventoried and governed separately from guests, because they are a different mechanism. Shared-channel participants connect through Microsoft Entra B2B direct connect and stay in their home tenant, so removing guest accounts does nothing to them — what governs them is your cross-tenant access settings, which decide which external organizations may connect inbound and outbound at all. We show you which organizations are currently trusted, which shared channels exist, and who is in them, and we implement the model you approve: usually a named list of partner tenants instead of an open default.
What will our own users notice after the cleanup?
Three things, and we would rather you heard them here than from the service desk. Sharing gets a different default — usually a specific-people link with an expiry, instead of an anonymous link that lives forever. Sharing outside allowed domains, or inviting guests at all, may now be restricted to a defined group of people or require a request. And owners start receiving review prompts on a schedule. The mitigation is the communication plan and the response windows; the alternative is a tenant where nobody can answer the auditor's question.
Do 'Anyone' links stop working immediately when you revoke them?
Yes — that is the point of them, and the reason we never revoke in bulk without evidence. The inventory shows which links exist, where they point, and where we can see recent activity against them. Anything that looks live goes back to the owner first and is replaced with a specific-people link before the anonymous one is cut. Anything with no activity and no owner claim is revoked in the wave, and the workbook records who approved it — if a request comes back later, the row explains exactly what happened and who decided.
How is this different from your Copilot oversharing service?
Direction of exposure. This service is about people outside your organization: guests, anonymous links, external channels, partner tenants. The Copilot oversharing service is about your own employees and what Copilot makes easy for them to find — 'everyone except external users' grants, broken inheritance, unlabeled sensitive content in sites that were never meant to be tenant-wide. They overlap in the reports and share some remediation, but they answer different questions. If a Copilot rollout is the trigger, most tenants need both; we will tell you which one to do first based on what your discovery actually shows.
How is this different from your managed identity hygiene subscription?
This is the one-time cleanup that makes a monthly cycle affordable; Managed Entra ID Identity Hygiene and Access Reviews is that monthly cycle. Running a recurring service against years of untriaged backlog means paying a monthly fee to look at the same thousand-row report every month. Clear the backlog once, set the baseline that stops re-accumulation, then either run the runbook yourselves or hand the cycle to the managed service. Both work; doing them in the other order does not.
What if we have far more than 500 guests or 100 sites?
The guest inventory and the tenant-level settings review always run across the whole tenant — a partial guest list is not evidence, and you get the complete identity picture regardless of size. What the fixed fee bounds is the deep work: the site-by-site sharing scan, the owner attestation and the removal waves, for up to 500 guest accounts and 100 sites. Larger estates are prioritized by risk — anonymous links first, then guests with no sign-in and broad reach, then everything else — and the remainder is quoted per tenant, in writing, before that work starts. We would rather tell you at the scoping call that this is a two-phase job than discover it on day eight.
Can you do this without disrupting an active audit or legal hold?
Yes, and it has to be planned for. Removing access is not the same as deleting content, but retention, holds and eDiscovery obligations can still make a removal the wrong move at the wrong moment. We ask at kickoff whether any hold, investigation or audit is live, and anything covered is flagged in the workbook and left alone until your compliance owner releases it. We will not run a removal wave over an unresolved hold to hit a milestone date.
What do we get at the end, and what does it cost?
$2,950 fixed for one tenant, two weeks, covering up to 500 guest accounts and 100 sites in the cleanup scope. You get the four inventories, the signed decision workbook, the executed removal waves with their evidence, the implemented sharing baseline, the recurring reviews configured and one cycle observed, the runbook, and the dated before-and-after report that answers the auditor's or the insurer's question. The quote is in writing before work begins and you pay after you approve delivery. Microsoft licence costs and any metered Microsoft Entra ID Governance guest charges are billed by Microsoft to you, not by us.