How-to guide

How to audit guest access in Microsoft 365

Sooner or later every tenant collects guests — project partners, consultants, a client who needed one folder years ago. The question that eventually lands on IT's desk isn't "do we have guests?" but "which external guests can reach our files, and what exactly can they open?" This guide is about answering that question for files and sites — SharePoint and OneDrive. Mailbox guest access is a different audit, and we say so explicitly below.

What the native tools tell you

Microsoft gives you two honest, useful instruments here, and it's worth being precise about the question each one answers:

  • Entra sign-in logs answer an activity question: which guests signed in, when, and from where. Useful for spotting dormant accounts and odd access patterns.
  • Access reviews (Entra ID Governance) answer a membership question: should this guest still belong to this group or Microsoft Teams team? Reviewers recertify or revoke membership on a schedule.

Both are about identity, activity, and membership. Neither is about resources.

Signed-in is not the same as can-reach

A guest who hasn't signed in for a year still holds every permission ever granted. A guest who sails through an access review as a legitimate member of one group may also hold direct file grants nobody remembered to review. Neither the sign-in log nor the access review enumerates what a given guest can actually open across every SharePoint site and every OneDrive — and especially not access that arrives through inheritance, where the file itself shows no share at all.

The shapes guest access takes

To audit guest access to files and sites, there are four distinct shapes to find:

  • Direct grants to a guest. A file or folder shared straight with a B2B guest, on a SharePoint site or in someone's OneDrive. The item's sharing panel shows it — on that one item, if you know to look there.
  • Guest access through group membership. A guest inside a Microsoft 365 group can reach everything the group's site holds. No file shows a share, because the "share" is a membership, not a permission on any item.
  • Inherited guest access. A grant on a parent folder or site makes every descendant file reachable — including files added long after the grant. This is the most under-audited shape of all; we wrote a full explainer on inherited guest access.
  • Pending invitations. An invitation sent but not yet accepted is exposure in waiting: the recipient can't open anything yet, but the moment they redeem it, they can. An honest audit tracks it from invitation to acceptance.

Guest access is one half of external exposure; anonymous and specific-people sharing links are the other — those are covered in the externally shared files guide.

Auditing it in one read-only scan

TRACER365 answers the resource question directly. One read-only scan covers every SharePoint site and every OneDrive in the tenant and surfaces all four shapes as severity-ranked finding types: direct grants to guests, guest access arriving through Microsoft 365 group membership, inherited guest access (ranked HIGH, because nothing on the file itself warns you), and pending unredeemed invitations.

Then it removes the noise. Inherited duplicates collapse under the single grant that caused them — in our testing, roughly 91% of raw findings collapsed as duplicates. What's left is the list you can actually review: the ~200 findings that matter, not the 50,000 rows a raw permissions walk produces. Scans run on a schedule from a locally installed Windows app with verifiable read-only scopes — no Copilot or Advanced Management licence required, and nothing in the tenant is ever changed.

If what you need first is the flat list — who the external users are, site by site — start with the companion guide: how to get a SharePoint guest access report.

The honest boundary: this audit covers SharePoint and OneDrive file and site sharing. TRACER365 does not audit Exchange mailbox guest access, Microsoft Forms, or Planner, and it is not a full internal-access map — internal sharing surfaces only as specific conditions, such as organisation-wide links and "Everyone except external users" grants.

See what your guests can actually reach

Every guest, every site, every OneDrive — deduplicated and ranked, in one read-only scan. Free 30-day trial at launch.