Microsoft 365 Security

Microsoft 365 Guest MFA: Are You Securing External Access or Just Making It Harder?

MFA is important. But Microsoft 365 external access is more nuanced than applying the same control to every scenario.

8 min read — Altitude IT Support

If MFA Is Good, Surely Everyone Should Always Use It?

It is a reasonable assumption. MFA improves security. External users are outside the organisation. Therefore every external user should always be forced through MFA before accessing anything. Simple.

The problem is that Microsoft 365 external access is not one thing. It is a collection of different mechanisms — Teams meeting attendance, Entra B2B guests, SharePoint sharing links, Conditional Access policies, cross-tenant trust — each with different security characteristics, different identity models, and different appropriate controls.

Applying the same restriction to every scenario does not necessarily improve security. It can create unnecessary friction for legitimate collaboration while leaving genuinely higher-risk access scenarios underexamined.

Good Microsoft 365 security isn't about switching on every restriction. It's about applying the right control to the right risk.

Not All External Users Are the Same

When someone joins a Teams meeting from outside your organisation, they are not automatically a guest in your Microsoft 365 tenant. They attend the meeting. They do not gain access to your Teams channels, SharePoint sites, shared files, email groups, or any other Microsoft 365 resources. The meeting ends and they have no ongoing access.

This is a fundamentally different scenario from a guest who is actually added into your organisation's Microsoft 365 environment as a Microsoft Entra B2B guest. That person has a presence in your tenant directory. They may be added to Teams channels, SharePoint sites, shared notebooks, or other resources. Their access persists after any single meeting or interaction. They can potentially access whatever they have been given access to at any time — from any device.

Treating these two scenarios identically produces either unnecessary friction for meeting attendees or insufficient control for persistent guests. Neither outcome is good.

SharePoint Sharing Also Varies

Not all SharePoint sharing links are the same either. Microsoft 365 offers different sharing modes with meaningfully different security characteristics.

Specific People Links

A Specific People link is shared with a named recipient — a particular email address. The recipient must authenticate as that identity before accessing the content. Because there is an authenticated identity, identity-based security controls including Conditional Access and MFA can be applied. If you want to require MFA before a particular person opens a shared document, Specific People links and the identity policies surrounding them give you the tools to do that.

Anyone Links

An Anyone link can allow anonymous access. There is no authenticated identity — the link itself grants access to whoever holds it. Because there is no identity, MFA cannot meaningfully be applied. You cannot require authentication from someone who is not authenticating.

That does not mean Anyone links are necessarily wrong to use. It means they should be controlled using different mechanisms that suit their nature:

  • Expiry dates, so links do not remain active indefinitely
  • View-only access, to prevent downloading or editing
  • Blocking downloads where appropriate
  • Restricting their use for sensitive or regulated information

Using an Anyone link to share a publicly available document or a low-sensitivity asset with a brief expiry is a reasonable use of the tool. Using an Anyone link to share financial data, personal information, or confidential business documents is not — and MFA cannot rescue that decision, because there is no identity to authenticate.

Limited Access and Identity Verification Are Different Controls

This distinction is worth stating clearly because the two are sometimes conflated.

Giving someone access to only one document limits what they can reach. It constrains the scope of the access but says nothing about who is accessing it.

MFA helps establish who is accessing it. It verifies that the person presenting a credential is genuinely the person that credential was issued to. It does not limit what they can reach once authenticated.

One control does not replace the other. For sensitive information, both may be appropriate: restricted access scope and verified identity. For lower-sensitivity information, scope restriction alone may be sufficient. For publicly accessible content, neither may be necessary. The question to ask is not "have I applied MFA?" but "what is the actual risk of this access scenario, and what combination of controls addresses that risk proportionately?"

Security should make inappropriate access difficult without making legitimate collaboration unnecessarily difficult.

A Practical Starting Point for SMEs

The table below sets out sensible starting-point controls for common external access scenarios. These are starting points, not universal configurations — the right approach for any organisation depends on its specific risk profile, licensing, regulatory context, and how it actually works with external parties.

External access scenario Typical approach
External Teams meeting attendee Usually no separate guest MFA requirement
Guest added to a Microsoft Team MFA
Ongoing SharePoint guest access MFA
Sensitive file or folder — authenticated sharing Authenticated access (Specific People link) + MFA
Low-risk, temporary document sharing Controlled sharing link with expiry may be sufficient
Anonymous / Anyone link View-only, expiry dates, limited use — not for sensitive content
Confidential or regulated information Avoid anonymous sharing; authenticated access + MFA

These are sensible starting points rather than a universal configuration for every organisation. Your specific context — licensing, regulatory requirements, and how your team collaborates externally — should shape the final approach.

Conditional Access Gives You More Control

Microsoft Entra Conditional Access allows businesses to design authentication and access policies that are significantly more precise than a simple on/off switch for MFA. Policies can target guest and external users separately from internal users, and can be scoped to specific applications, groups, types of access, or authentication requirements.

In practice, this means businesses do not have to choose between "MFA for absolutely everything" and "no MFA for guests." It is possible to require MFA for guests accessing SharePoint, while applying a different policy to guests joining Teams meetings, while applying yet another policy to guests accessing particularly sensitive applications. The granularity exists — using it appropriately is the work.

Conditional Access policies also interact with device compliance, location, sign-in risk, and other signals. A well-designed set of policies can provide meaningful protection without creating the situation — common in organisations where policies have been applied without thought for user journeys — where legitimate work is constantly interrupted by authentication prompts that do not align with how people actually work.

The Microsoft 365 Security Baseline Review that Altitude provides covers Conditional Access policy design as part of a broader assessment of authentication, identity, external access and endpoint compliance — identifying gaps and misconfigurations rather than simply listing settings.

Working with Trusted External Organisations

Where two organisations work together regularly — a long-standing supplier, a professional services firm, a partner organisation — Microsoft Entra cross-tenant access settings can be used to establish a degree of trust between the two tenants.

In appropriate configurations, Microsoft 365 can trust MFA that has already been performed in the external organisation's tenant. The practical effect is that a colleague from a trusted partner organisation can access shared resources without being prompted to complete a separate MFA step for every interaction — because their own organisation's authentication, including MFA, is recognised.

This improves both security and usability. The external user is still authenticated and has passed MFA — it has simply been performed within their own organisation's managed environment rather than creating a separate credential process in yours. Cross-tenant access settings require careful configuration and mutual trust assessment, but for organisations with regular external partnerships they are worth understanding.

Where Businesses Get Microsoft 365 Security Wrong

There are consistent patterns in how Microsoft 365 external access and security controls can go wrong in practice:

  • MFA enabled without considering user journeys — policies switch on but nobody has reviewed how authentication prompts interact with how the team actually works. The result is friction for internal users, frustrated external partners, and shadow workarounds.
  • Guest access left completely open — no review of who has been added as a guest, what they can access, or whether they still need it. Former contractors, old partners and lapsed relationships may still have active guest accounts.
  • Anonymous sharing enabled without controls — Anyone links available with no expiry, no download restrictions, and no policy on what can be shared using them.
  • Security policies copied from generic templates — a Conditional Access policy that looks correct in a template may not reflect how the organisation actually operates. A policy designed for a US enterprise with Intune-enrolled devices may be inappropriate for a UK SME with a mix of managed and personal devices.
  • Conditional Access rules that disrupt legitimate work — overly broad policies that block access from locations, devices or scenarios that the business uses every day. Sometimes the policy is technically "more secure" in isolation but breaks workflows in practice.
  • Microsoft 365 security capabilities paid for but not configured — Defender for Business, Microsoft Entra ID P1 or P2, and Conditional Access features may all be included in existing Microsoft 365 licensing. Whether they are actually configured and active is a separate question.
  • IT policies designed around technology rather than business reality — security that works in theory but creates enough friction that people find alternatives. A sharing policy that is technically robust but leads users to email attachments or use a personal cloud storage account achieves less than a proportionate policy that people actually follow.

The Altitude IT View

Microsoft 365 gives businesses powerful security controls. The difficult part isn't switching them on — it's configuring them so they protect the business without getting in the way of people doing their jobs.

For many SMEs across Manchester and the North West, the challenge is not a lack of available security capability. Microsoft 365 Business Premium includes Conditional Access, Defender for Business, Microsoft Entra ID P1, and a range of other security tools. The challenge is configuring them for how the organisation actually operates — what external collaboration is legitimate and necessary, where the real risk sits, and which controls address that risk without creating problems of their own.

Altitude can help businesses review and configure:

  • Microsoft 365 security settings and licensing
  • Microsoft Entra ID and identity management
  • Multi-factor authentication and passkey adoption
  • Conditional Access policies for internal and guest users
  • External and guest access controls
  • SharePoint sharing settings and policies
  • Cyber Essentials readiness where relevant

The starting point is understanding what the business is actually doing and where the risks genuinely sit — not applying the same controls to every scenario because they look like the right answer on a configuration checklist.

Related Reading

Frequently Asked Questions

Should Microsoft 365 guests be required to use MFA?

For guests with ongoing access — added to Teams channels, SharePoint sites, or other Microsoft 365 resources — MFA is generally appropriate. For people attending a Teams meeting without being added to the tenant as a guest, a separate MFA requirement is usually not applicable in the same way. Conditional Access allows organisations to apply different policies to different types of external access.

What is a Microsoft Entra B2B guest?

A Microsoft Entra B2B guest is an external user who has been added to your Microsoft 365 tenant directory. Unlike a Teams meeting attendee, a B2B guest has a persistent presence in your environment and may be given access to Teams channels, SharePoint sites, or other resources. They authenticate using their own Microsoft or social identity, and security policies including Conditional Access and MFA can be applied to their access.

What is the difference between an Anyone link and a Specific People link in SharePoint?

A Specific People link is shared with a named recipient who must authenticate before accessing the content — enabling identity-based controls including MFA. An Anyone link allows anonymous access to whoever holds the link, regardless of identity. MFA cannot be applied to anonymous access because there is no identity to authenticate. Anyone links should be controlled using expiry dates, view-only permissions and restricted use for non-sensitive content.

Can Microsoft 365 MFA be applied to external meeting attendees?

A Teams meeting attendee who has not been added to your tenant as a B2B guest does not have authenticated access to your Microsoft 365 resources through that attendance. The meeting lobby and meeting-specific controls govern what meeting attendees can do. MFA as a Conditional Access policy applies to authenticated access to Microsoft 365 services — which a non-guest meeting attendee does not have in the same way.

What is Microsoft Entra Conditional Access?

Conditional Access is a Microsoft Entra feature that allows organisations to define policies controlling how and when users — including guests — can access Microsoft 365 and other applications. Policies can require MFA, enforce device compliance, restrict access by location, and target specific user groups or applications. It allows significantly more precise control than a simple MFA toggle.

What is Microsoft Entra cross-tenant access?

Cross-tenant access settings in Microsoft Entra allow two Microsoft 365 organisations to establish trust between their tenants. Where configured, this can allow one organisation to trust authentication — including MFA — already performed in a partner organisation's tenant, improving both security and usability for regular external collaboration.

Is it safe to use Anyone links in Microsoft 365?

Anyone links can be appropriate for low-sensitivity, non-confidential content with short expiry dates and view-only permissions. They should not be used for confidential, sensitive or regulated information. Because they allow anonymous access, MFA cannot protect them — link management (expiry, permissions, scope) is the appropriate control.

Can Altitude IT review our Microsoft 365 guest and external access settings?

Yes. Altitude's Microsoft 365 Security Baseline Review covers authentication, Conditional Access, guest access, SharePoint sharing and identity configuration — identifying where settings are misaligned, underused or creating unnecessary risk or friction for Manchester and North West businesses.

Not sure whether your Microsoft 365 security policies are protecting your business or simply creating unnecessary friction?

Altitude IT can review your Microsoft 365 configuration and identify where security can be strengthened, simplified or better aligned with the way your team actually works.

Talk to an Expert Back to All Blog Posts