Explainer

Unredeemed guest invitations, explained

You share a file with an outside email address. Microsoft 365 records the grant right away — but the person can't open anything until they accept the invitation and pick up a guest identity in your directory. That in-between state is an unredeemed invitation: a standing grant that isn't active access yet. It's genuinely low-risk, easy to wave away, and still worth seeing.

Pending, not powerless — the honest distinction

This is the finding type where it matters most to be precise about what is and isn't true. Before the invitation is accepted, the grant exists on the item, but the invited person cannot actually reach the content. Their identity isn't live in your tenant yet. So an unredeemed invitation is pending exposure, not active access — and anyone who tells you otherwise is overstating it.

It is not nothing, either. It is a standing grant that flips to active the moment it's accepted, with no further action from you — and it captures an intent to share outside the organisation that may already have been forgotten. That balance is exactly why it sits at LOW severity rather than HIGH: real enough to surface, not urgent enough to alarm.

Directory view vs. effective reach

A guest list or directory export can make this confusing. The invited address may appear as a pending guest — present in a view — while its effective reach is still zero. Reading the directory alone, you can't tell a guest who can open your files from one who was invited last week and never clicked the link. An audit that's honest about sharing has to hold both facts at once: the grant is on record, and it isn't live yet.

Why an audit should still surface it

  • It will activate silently. Acceptance needs nothing from your side — the pending grant becomes real reach on the invited person's schedule, not yours.
  • It records forgotten intent. A long-pending invitation to a stale or personal address is worth withdrawing before it's ever redeemed.
  • It's cheap to clear. Pending grants you didn't mean to leave open are among the easiest external exposures to tidy up — once you can see them.

How TRACER365 tracks it

TRACER365 emits an unredeemed invitation as its own LOW-severity finding type, so it appears in the audit without being dressed up as active access. The pending exposure is tracked from invitation onward, and when the invitation is redeemed the finding transitions to the shape the access actually takesa specific-people external link or a direct external grant, whichever the real reach becomes. Withdraw the invitation and the finding resolves on the next scan. You see the whole arc, labelled honestly at each step.

Where it fits in guest hygiene

Unredeemed invitations are one small part of the wider B2B guest lifecycle — the accounts and grants that pile up because guest accounts don't clean up after themselves. To see the pending ones alongside the guests who can already reach your files and sites, start with the guest access audit how-to or the narrower SharePoint guest access report.

See the pending grants, not just the active ones

Unredeemed invitations surfaced LOW and tracked through to acceptance — pending exposure named honestly, never overstated. Free 30-day trial at launch.