Cloud Security Stack
Tools and buyer guides

Tools

Securing Microsoft Teams external access without blocking the business

External access, guest access and anonymous meeting joins are three different settings that get conflated. What each one actually controls.

10 min read · Reviewed 22 August 2026 · Written against Microsoft's published Teams and Entra external identity settings.

Three settings, constantly confused

External access, sometimes called federation, controls whether your users can chat and call people in other Teams organisations. Guest access controls whether people from outside can be added to your teams and see content. Anonymous join controls whether someone without an account can enter a meeting.

They are configured in different places, they have different risks, and requests to open one are routinely satisfied by opening all three.

What each setting exposes
What the outsider can do
External access (federation)Chat and call your users. No access to content
Guest accessJoin teams, read channel content, open files
Anonymous meeting joinAttend a meeting without any account
Shared channels (B2B direct connect)Access one channel without a guest account

Guest access is the one that reaches your data. It deserves the most scrutiny and usually receives the least.

A configuration that works

01

Allow external access to specific domains, not everyone

Federating with named partner domains gives the business the chat it wants without opening contact from any Teams tenant in the world.

02

Allow guests, but govern them

Blocking guests entirely pushes collaboration to personal email and consumer file sharing, which is worse. Allow it, and use access reviews to remove guests who have stopped participating.

03

Set the lobby, do not disable anonymous join

Anonymous participants wait in the lobby by default for external meetings. That is the correct balance for most organisations, and disabling anonymous join entirely breaks meetings with customers.

04

Review guest accounts quarterly

Entra ID access reviews can do this automatically. Guests from a project that ended two years ago are the population nobody thinks about.

The verdict

Our pick

Domain-restricted federation, governed guest access, lobby for anonymous

It gives the business what it actually asks for while keeping the setting that reaches your content under review.

Who should skip

Do not block guest access as a security decision. It moves the collaboration somewhere you cannot see, and that is a worse outcome than a governed guest.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.