Ask the Advisor

Does MFA Have to Apply to Every Microsoft 365 Guest?

Asked anonymously5 minutes read18 August 2026
WhatsAppEmail
Does MFA Have to Apply to Every Microsoft 365 Guest?

Not all external access to Microsoft 365 is the same. A Teams meeting attendee is different from a guest added to a Team. A Specific People SharePoint link is different from an anonymous Anyone link. Microsoft 365 gives you fine-grained control over guest MFA through Conditional Access and sharing settings — the key is matching the security requirement to the actual risk.

This question has been published anonymously. Details that could identify the person or organisation have been removed.

“We enforce MFA in Microsoft 365, but do external guests really need MFA every time? When you invite someone to a Teams meeting or share one specific SharePoint file or folder with them, their access can already be very limited. I thought MFA for guest users could be controlled separately. Are we making external collaboration more difficult than it needs to be?”

Advisor’s short answer

Yes. Microsoft 365 guest MFA can be controlled separately, and this is a good example of where a blanket security policy can create unnecessary friction.

The first thing to understand is that not all external access is the same. A Teams meeting attendee is not the same as a guest added to a Team. A Specific People SharePoint link is not the same as an anonymous Anyone link. Each carries different risk and different authentication options.

Last checked: 18 August 2026.

A Teams meeting attendee isn’t necessarily a guest

Inviting an external person to a Teams meeting does not automatically give them access to your Microsoft 365 environment. They may simply be attending that meeting.

That is very different from adding someone as a guest to a Team, where they can access conversations, files and other resources in that Team on an ongoing basis.

Requiring your organisation’s guest MFA policy simply because somebody attends a meeting is not necessarily appropriate. The access level and the duration are both far more limited.

SharePoint sharing links aren’t all the same either

Microsoft 365 provides several ways of sharing information externally, and the security implications differ significantly.

A Specific People link requires the recipient to prove they are the intended person. Because they are authenticating, Microsoft Entra Conditional Access policies can potentially require MFA as part of that process.

An Anyone link works differently. It can allow access without the recipient authenticating at all — the link itself is effectively the credential.

You cannot meaningfully enforce MFA against an anonymous Anyone link, because there is no authenticated identity against which to enforce it. Anyone links are instead controlled through other means: expiry dates, view-only restrictions, and limiting which domains can use them.

So should you disable MFA for guests?

No. That is the wrong conclusion.

The better question is: which types of external access actually justify MFA?

External access typeSensible approach
Attending an external Teams meetingUsually no guest MFA requirement
Added as a guest member of a TeamMFA
Ongoing SharePoint guest accessMFA
Sensitive SharePoint file or folderAuthentication and MFA
One-off, low-risk documentControlled sharing link may be sufficient
Anonymous/Anyone linkRestrict permissions and use an expiry date
Confidential or sensitive informationAvoid anonymous links entirely

Limiting access and proving identity are different controls

The important distinction is between limiting what somebody can access and proving who they are.

Giving somebody access to only one file limits the potential damage if something goes wrong. MFA reduces the chance of the wrong person gaining that access in the first place.

They are complementary controls, not substitutes for each other.

Cross-tenant access: trust MFA from another organisation

If you regularly collaborate with another organisation that also uses Microsoft 365, there is another option worth knowing about.

Microsoft Entra’s cross-tenant access settings can be configured to trust MFA that has already been performed in the other organisation’s Microsoft 365 tenant. If their staff have already authenticated securely using their own organisation’s MFA, you do not necessarily need to require them to go through a separate MFA process on your side as well.

This is particularly useful for established supplier or partner relationships where the other organisation has equivalent security standards to your own.

Using Conditional Access to apply the right policy

Microsoft Entra Conditional Access lets you create separate policies for guest users. You can require MFA for guests who access Teams or SharePoint resources without applying the same friction to meeting attendees who have no access to your environment.

Your Microsoft 365 external sharing settings control which link types are available and what restrictions apply. Conditional Access controls what authentication is required for users who sign in to access shared resources.

Between the two, you have considerably more control than a simple on/off switch for guest MFA.

Advisor’s view

Don’t choose between “MFA for every external interaction” and “no MFA for guests.” Microsoft 365 gives you much more control than that.

Use Conditional Access and your Microsoft 365 sharing settings to match the security requirement to the actual risk of each type of external access.

Security should make inappropriate access difficult — not legitimate collaboration unnecessarily difficult.

Related reading

Other IT Club articles on Microsoft 365 security:

Microsoft 365 Security Baseline Checklist for SMEs

Microsoft Secure Score: What It Means and What to Do About It

Microsoft Is Retiring SMS and Voice MFA: What Businesses Need to Do

Not sure whether your Microsoft 365 security settings are protecting your business or simply making everyone’s life harder?

Ask the IT Club Advisor. We’ll give you a practical answer without turning it into a sales pitch.

Ask Your IT Question →

Plain-English Takeaway

Microsoft 365 guest MFA can be controlled separately from internal user MFA. Not all external access is equivalent — a Teams meeting attendee is not the same as a guest added to a Team, and a Specific People SharePoint link is not the same as an anonymous Anyone link. Use Conditional Access and your Microsoft 365 sharing settings to match the security requirement to the actual risk, rather than applying a blanket policy in either direction.

Follow The IT Club Briefing on WhatsApp

Tap to follow The IT Club Briefing on WhatsApp.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor