Does MFA Have to Apply to Every Microsoft 365 Guest?
IT Club — Powered by Altitude IT (opens in a new tab)

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
Not all external access to Microsoft 365 is the same. A Teams meeting attendee is different from a guest added to a Team. A Specific People SharePoint link is different from an anonymous Anyone link. Microsoft 365 gives you fine-grained control over guest MFA through Conditional Access and sharing settings — the key is matching the security requirement to the actual risk.
This question has been published anonymously. Details that could identify the person or organisation have been removed.
“We enforce MFA in Microsoft 365, but do external guests really need MFA every time? When you invite someone to a Teams meeting or share one specific SharePoint file or folder with them, their access can already be very limited. I thought MFA for guest users could be controlled separately. Are we making external collaboration more difficult than it needs to be?”
Advisor’s short answer
Yes. Microsoft 365 guest MFA can be controlled separately, and this is a good example of where a blanket security policy can create unnecessary friction.
The first thing to understand is that not all external access is the same. A Teams meeting attendee is not the same as a guest added to a Team. A Specific People SharePoint link is not the same as an anonymous Anyone link. Each carries different risk and different authentication options.
Last checked: 18 August 2026.
A Teams meeting attendee isn’t necessarily a guest
Inviting an external person to a Teams meeting does not automatically give them access to your Microsoft 365 environment. They may simply be attending that meeting.
That is very different from adding someone as a guest to a Team, where they can access conversations, files and other resources in that Team on an ongoing basis.
Requiring your organisation’s guest MFA policy simply because somebody attends a meeting is not necessarily appropriate. The access level and the duration are both far more limited.
SharePoint sharing links aren’t all the same either
Microsoft 365 provides several ways of sharing information externally, and the security implications differ significantly.
A Specific People link requires the recipient to prove they are the intended person. Because they are authenticating, Microsoft Entra Conditional Access policies can potentially require MFA as part of that process.
An Anyone link works differently. It can allow access without the recipient authenticating at all — the link itself is effectively the credential.
You cannot meaningfully enforce MFA against an anonymous Anyone link, because there is no authenticated identity against which to enforce it. Anyone links are instead controlled through other means: expiry dates, view-only restrictions, and limiting which domains can use them.
So should you disable MFA for guests?
No. That is the wrong conclusion.
The better question is: which types of external access actually justify MFA?
| External access type | Sensible approach |
|---|---|
| Attending an external Teams meeting | Usually no guest MFA requirement |
| Added as a guest member of a Team | MFA |
| Ongoing SharePoint guest access | MFA |
| Sensitive SharePoint file or folder | Authentication and MFA |
| One-off, low-risk document | Controlled sharing link may be sufficient |
| Anonymous/Anyone link | Restrict permissions and use an expiry date |
| Confidential or sensitive information | Avoid anonymous links entirely |
Limiting access and proving identity are different controls
The important distinction is between limiting what somebody can access and proving who they are.
Giving somebody access to only one file limits the potential damage if something goes wrong. MFA reduces the chance of the wrong person gaining that access in the first place.
They are complementary controls, not substitutes for each other.
Cross-tenant access: trust MFA from another organisation
If you regularly collaborate with another organisation that also uses Microsoft 365, there is another option worth knowing about.
Microsoft Entra’s cross-tenant access settings can be configured to trust MFA that has already been performed in the other organisation’s Microsoft 365 tenant. If their staff have already authenticated securely using their own organisation’s MFA, you do not necessarily need to require them to go through a separate MFA process on your side as well.
This is particularly useful for established supplier or partner relationships where the other organisation has equivalent security standards to your own.
Using Conditional Access to apply the right policy
Microsoft Entra Conditional Access lets you create separate policies for guest users. You can require MFA for guests who access Teams or SharePoint resources without applying the same friction to meeting attendees who have no access to your environment.
Your Microsoft 365 external sharing settings control which link types are available and what restrictions apply. Conditional Access controls what authentication is required for users who sign in to access shared resources.
Between the two, you have considerably more control than a simple on/off switch for guest MFA.
Advisor’s view
Don’t choose between “MFA for every external interaction” and “no MFA for guests.” Microsoft 365 gives you much more control than that.
Use Conditional Access and your Microsoft 365 sharing settings to match the security requirement to the actual risk of each type of external access.
Security should make inappropriate access difficult — not legitimate collaboration unnecessarily difficult.
Related reading
Other IT Club articles on Microsoft 365 security:
Microsoft 365 Security Baseline Checklist for SMEs →
Microsoft Secure Score: What It Means and What to Do About It →
Microsoft Is Retiring SMS and Voice MFA: What Businesses Need to Do →
Not sure whether your Microsoft 365 security settings are protecting your business or simply making everyone’s life harder?
Ask the IT Club Advisor. We’ll give you a practical answer without turning it into a sales pitch.
Plain-English Takeaway
Microsoft 365 guest MFA can be controlled separately from internal user MFA. Not all external access is equivalent — a Teams meeting attendee is not the same as a guest added to a Team, and a Specific People SharePoint link is not the same as an anonymous Anyone link. Use Conditional Access and your Microsoft 365 sharing settings to match the security requirement to the actual risk, rather than applying a blanket policy in either direction.
Related Articles
Why has my iPhone screen suddenly turned blue?
A sudden blue tint does not necessarily mean your iPhone screen has failed. Check its Accessibility display settings first.
Read articleHow Do I Get My First Cybersecurity Job When Entry-Level Roles Want Three Years' Experience?
Matheus is changing direction from financial risk management into cybersecurity, but entry-level vacancies keep asking for three years' experience. The answer is not to pretend he has no experience — it is to translate the risk, technical and practical evidence he already has.
Read articleDoes Sage 200 Still Work with Microsoft 365?
Yes — Sage 200 can still work with Microsoft 365, but the answer depends on your Sage version, the feature, licensing, Office architecture, onboarding and client environment.
Read articleNeed help putting this into practice?
IT Club helps you understand the technology. If you need implementation, support or consultancy, the teams behind IT Club can help.
Altitude IT (opens in a new tab) — IT support, cyber security, Microsoft 365 and technology operations.
Altitude AI (opens in a new tab) — AI discovery, automation, governance and implementation.
