TJ Hoag

Guest Account Sprawl in Entra ID

TJ
Timothy J. Hoag
IAM & IT Operations Specialist

How many guest accounts are in your Entra ID tenant right now?

If you have to think about it for more than a few seconds, that is the answer. You do not know. And if you do not know, you cannot govern them.

Guest accounts in Microsoft Entra ID (formerly Azure Active Directory) are one of the most consistently overlooked access governance problems in enterprise IT. They accumulate quietly, for understandable reasons, and they rarely get cleaned up until an audit or an incident forces the issue.

How Does Guest Account Sprawl Happen?

Guest accounts in Entra ID are created when external users are invited to collaborate through Teams, SharePoint, or application access. The invitation takes seconds. The provisioning is automatic. The access is real.

Each account is created for a legitimate reason at the time:

  • A vendor partner is invited to a Teams channel for a project
  • A contractor is given SharePoint access to review documentation
  • A consultant is added to an application for a temporary engagement
  • A former employee's personal email is used as a workaround during a transition

The project ends. The contractor finishes the engagement. The consultant's work is complete. The former employee no longer needs access.

The guest accounts remain.

Guest account sprawl is not caused by negligence. It is caused by the absence of a deprovisioning workflow matched to the provisioning workflow.

Every organization has a process for adding external access. Far fewer have a process for removing it on a defined schedule.

Why This Matters

A guest account is an active identity in your tenant. It can receive invitations to additional resources, maintain access to previously shared files, and in some configurations, enumerate other users and groups in the directory.

A guest account belonging to someone who left a vendor organization three months ago represents an identity that your vendor no longer controls. You do not know the current status of that person's credentials. You do not know if they are still employed. You do not know if their former employer's email domain has been compromised.

In healthcare and higher education environments, where data classification and access governance are compliance requirements, not just best practices, this is a material risk:

  • Healthcare: Unauthorized access to a system containing protected health information by a stale guest account is a HIPAA incident, not an IT housekeeping issue
  • Higher education: Guest access to systems containing student records may violate FERPA if the access was not properly authorized and documented

Even outside regulated industries, a guest account from a former vendor or partner with access to internal documentation or communication channels is an unnecessary exposure.

What Does a Review Process Look Like?

Effective guest account governance requires answering four questions on a regular schedule:

1. Who are all the guest accounts in the tenant? Entra ID provides reporting on guest users through the portal and via Microsoft Graph API. A regular export of all accounts with type "Guest" is the starting point.

2. Who owns each account? Every guest account should have an internal sponsor: the person or team that invited the external user and is responsible for the legitimacy of their access. If no sponsor can be identified, the account is a candidate for immediate review.

3. Is the access still needed? This requires contacting the account sponsor and confirming whether the external user still has a legitimate business need for access. If the project is over, the contractor is finished, or the relationship has ended, the access should be removed.

4. What can the account access? Entra ID allows reporting on which applications and resources a guest account has been granted access to. Accounts with broad access or access to sensitive systems warrant closer scrutiny than accounts with narrow, limited permissions.

Recommended Review Cycle

For most organizations, a quarterly review of guest accounts is a reasonable baseline. In environments with frequent external collaboration or high data sensitivity, monthly reviews are more appropriate.

The review does not need to be manual. Entra ID Access Reviews can be configured to automatically send periodic review requests to account sponsors, requiring them to confirm or revoke access on a schedule. Accounts whose sponsors do not respond within the review window can be automatically disabled.

The Practical Starting Point

If your organization has never conducted a guest account review, the first step is simply generating the list. Run a report on all Entra ID users with UserType equal to "Guest." Sort by account creation date. Look for accounts older than 90 days. For each one, identify the sponsor and confirm whether the access is still needed.

The volume of stale accounts in the first review is usually surprising. In environments without a formal review process, it is not unusual to find that a significant portion of guest accounts have outlived their intended purpose by months or years.

The cleanup is the easy part. The harder part is building the process that prevents the sprawl from accumulating again.

Opportunities
Open to Remote Roles

IAM Analyst, Junior Systems Administrator, or IT Operations Analyst - ideally in healthcare or higher education. Direct hire, W-2.

Discuss opportunities