Table of Contents

Office 365 External Guest Access

Summary: How to configure External Guest Access in Office 365.
Date: Around 2018
Refactor: 8 March 2025: Checked links and formatting.

If you want to share data secure and in an universal way across all modules in Office 365 you could follow these steps to achieve that situation.

Please notice that you first need to restrict the number of users that can create office 365 groups: Manage Office 365 Group Creation

SharePoint Configuration

Resources

Settings

Go to the sharepoint admin portal: https://shift-admin.sharepoint.com/ → sharing
Sharing outside your organization:


Default Link Type


Default Link Permission


Additional Settings

Sharing per site

If required it is also possible to further restrict individual sites from sharing:

Skype for Business Configuration

Almost all settings are already transferred to the new Teams and Skype portal. But you can still configure the list of domains collaboration is allowed with:

Office 365 Configuration

Resources

Groups Settings

Go to https://portal.office.com/adminportal/home → Settings → Services & Add-ins → Office 365 Groups

Sharing Settings

Go to https://portal.office.com/adminportal/home → Settings → Security & privacy → Sharing → Edit

Azure AD Business-to-business User Settings

External User Settings

Go to https://portal.azure.com → Azure Active Directory → User Settings → External Users


Collaboration restrictions:

Require MFA for Guest Accounts

Resources

Policy Settings

Go to https://portal.azure.com → Security → Conditional Access → Policies

Note: Ask someone to check the settings before you enable the policy. Making errors could get you locked out.

Teams Configuration

Resources

Guest Access

Go to https://admin.teams.microsoft.com/dashboard → Org-Wide Settings → Guest Access

External access

Go to Org-Wide → External access

Teams Configuration

Go to Org-wide settings → Teams settings


Go to Org-wide settings → Teams upgrade

This enables teams and skype users to chat with each other

Manage Allowed Domain list

Keep a transparent list of all allowed domains and use this list for all modules within office 365. An exaple could be:

Module SharePoint and OneDrive Skype for Business Teams Teams Channel Email Azure AD External Users
Allowed Domains microsoft.com
customer.nl
getshifting.com
microsoft.com
customer.nl
getshifting.com
microsoft.com
customer.nl
getshifting.com
microsoft.com
customer.nl
getshifting.com
Remarks Imports the list from Skype for Business
The getshifting.com domain (your own) might not be required but I am not sure about that. = Shortlist on Adding Domains =

SharePoint & OneDrive

Skype for Business

Azure AD External Users

Teams