11 Jan 2022
This article originally appeared on AvePoint.
Before configuring Microsoft 365 to enable access to outsiders, several basic policy decision points must be addressed first.
While there are many ways to develop and tailor the appropriate policies for your organization’s unique needs at a granular level, here are a few of the most important top-line considerations.
Determine if the agility, regulatory, and sensitivity levels of your work environment are more appropriate for a policy that is everyone except or a policy that is no one except those from specific organizations or domains.
Once that determination has been made, coordinate with business stakeholders to either build a list of common collaborators (such as vendors) to whitelist or to identify organizations that may need to be blacklisted (such as competitors).
In general, highly regulated and sensitive environments will want to deploy a “no one except” policy while most organizations will want to deploy an “everyone except” policy while layering on more protections for specific workspaces and files downstream.
Note: The allow/deny list is NOT infinite. The entire policy can consist of only 25,000 characters. This means if you are a large organization and want to granularly specify hundreds of allowed domains, you will likely run into this limitation.
In most cases, it would be inappropriate for guests to be able to look up or contact anyone within the organization. The best practice is to limit access to only those who are members of the same Team as the guest.
When a user would like to have a guest added, there needs to be a process for admitting them into the environment. There are two people who can add an external user to a Team using Microsoft 365 native functionality: an IT admin or the owner of the Team.
Microsoft 365 will never let a member of a Team invite a net new external guest. Depending on the selected settings, however, members could add and share with guests who are already in Active Directory but not members of that specific Team.
The challenge with having only IT admins add new guest users creates a bottleneck. They’re also not as close to the business needs, so managing the lifecycle of a guest — when they need to be onboarded and offboarded — can be a challenge.
On the other hand, not every organization is comfortable with enabling any Team owner to admit new guests which then presents two options:
To find out more about Microsoft 365 Guest Access, AvePoint Cloud Governance and how Pact IT can help, please contact us today.