{"id":52964,"date":"2026-06-30T14:42:39","date_gmt":"2026-06-30T12:42:39","guid":{"rendered":"https:\/\/firstware.com\/?p=52964"},"modified":"2026-09-25T16:39:53","modified_gmt":"2026-09-25T14:39:53","slug":"lifecycle-management-guest-accounts","status":"publish","type":"post","link":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/","title":{"rendered":"What is the best approach to managing the lifecycle of M365 guest accounts?"},"content":{"rendered":"<p>Guest accounts, much like user accounts, have a life of their own. It begins with an invitation to a tenant and ends\u2026 well, when, exactly? Inviting guests is, at best, extremely simple, but the \u201cnext\u201d and \u201cend\u201d steps prove to be difficult.<\/p>\n<p>What sounds really nice and collaborative in theory\u2014\u201cEveryone can invite guests to Microsoft Teams\u201d\u2014carries many risks. Microsoft offers some features to manage the lifecycle of guest accounts, but for most large companies, these <strong>are not sufficient<\/strong>.<\/p>\n<p>That\u2019s why today we\u2019re addressing the question: <strong>How do you classify a guest account and keep a close eye on it securely throughout its entire lifecycle?<\/strong><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52978 size-large\" title=\"Normal and advanced guest accounts in IDM-Portal\" src=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/06\/Manage-guest-accounts-IDM-Portal-1024x587.webp\" alt=\"Normal and advanced guest accounts in IDM-Portal\" width=\"1024\" height=\"587\" srcset=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/06\/Manage-guest-accounts-IDM-Portal-980x562.webp 980w, https:\/\/firstware.com\/wp-content\/uploads\/2026\/06\/Manage-guest-accounts-IDM-Portal-480x275.webp 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/p>\n<p>We&#8217;ve found a way to better manage and control guest accounts throughout their entire lifecycle for an enterprise customer with 10,000+ employees.<\/p>\n<p><a href=\"https:\/\/firstware.com\/en\/contact\/\" target=\"_blank\" rel=\"noopener\"><button class=\"ButtonBeratung2 aligncenter\">Is this exactly what you&#8217;re looking for?<\/button><\/a><\/p>\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Inhaltsverzeichnis<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#How_does_a_guest_join_the_tenant\" >How does a guest join the tenant?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#What_are_the_real_issues_with_the_lifecycle_of_guest_accounts\" >What are the real issues with the lifecycle of guest accounts?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#Our_solution_Multi-level_guest_accounts_and_clear_responsibilities\" >Our solution: Multi-level guest accounts and clear responsibilities<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#The_customers_situation_Loss_of_control_over_guest_accounts\" >The customer\u2019s situation: Loss of control over guest accounts<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#Normal_guest_account\" >Normal guest account<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#Extended_guest_account\" >Extended guest account<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#Conclusion\" >Conclusion<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#More_about_FirstWare_IDM-Portal\" >More about FirstWare IDM-Portal<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"How_does_a_guest_join_the_tenant\"><\/span>How does a guest join the tenant?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>First, let\u2019s briefly clarify how a guest actually joins your organization. This depends entirely on how it\u2019s configured at the tenant level, in Microsoft Teams, and in SharePoint.<\/p>\n<p>A <strong>global administrator<\/strong> can almost always create a guest in the Microsoft Entra Admin Center.<\/p>\n<p><img decoding=\"async\" class=\"imgshadow alignleft wp-image-49716 size-medium\" title=\"Der bequemste Weg: G\u00e4ste in Teams einladen\" src=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/04\/Gaeste-in-MS-Teams-hinzufuegen-300x235.png\" alt=\"G\u00e4ste in Teams einladen\" width=\"300\" height=\"235\" \/>However, <strong>guests are usually invited to MS Teams<\/strong>.<\/p>\n<p>Team owners can easily add external members to a team using their email address.<\/p>\n<p>To do this, files or folders can be shared with external users via SharePoint or OneDrive.<\/p>\n<p>However, the last two options are only available if this has been enabled within the organization. Microsoft offers various permission levels for this (ranging from \u201canyone can invite,\u201d \u201conly internal employees can invite,\u201d \u201conly specific employees or roles can invite,\u201d to \u201cno one except admins\u201d).<\/p>\n<p>Once the invitation is sent, the guest receives an invitation email from Microsoft. After accepting the invitation and successfully authenticating, the guest then has access to the shared resources.<\/p>\n<ul>\n<li>Many companies allow invitations via Teams, as this aligns with the app\u2019s collaborative nature.<\/li>\n<li>Others completely revoke these rights from their employees and allow invitations only through the IT department.<\/li>\n<li>Still others seek <strong>more granular solutions<\/strong>, one of which we\u2019d like to introduce to you.<\/li>\n<\/ul>\n<p>\ud83d\udca1<strong>Note:<\/strong> Through numerous projects with our customers, we know that the topic of \u201cguest accounts\u201d is a recurring headache. In our <strong>Guest Accounts Series<\/strong>, we examine various challenges that we\u2019ve been able to solve in our customer projects.<\/p>\n<p>If you&#8217;re interested, we also recommend these articles:<br \/>\n<a href=\"https:\/\/firstware.com\/en\/blog\/unaccepted-guest-accounts\/\">\u201eWhat happens to unaccepted guest accounts in Microsoft Entra?\u201c<\/a><br \/>\n<a href=\"https:\/\/firstware.com\/en\/blog\/guest-accounts-in-distribution-lists\/\">\u201eCan guest accounts be added to distribution lists?\u201c<\/a><\/p>\n<p><a href=\"\/#Unsere%20L%C3%B6sung\"><button class=\"ButtonBeratung aligncenter\">Here&#8217;s what our solution looks like<\/button><\/a><\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_are_the_real_issues_with_the_lifecycle_of_guest_accounts\"><\/span>What are the real issues with the lifecycle of guest accounts?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>So we\u2019ve already arrived at the obvious vulnerabilities: Inviting users is easy, but managing and monitoring guest accounts is challenging.<\/p>\n<p><strong>No lifecycle management due to a lack of accountability<\/strong><\/p>\n<p>In the standard tenant, a guest often \u201cbelongs\u201d to no one once they\u2019re in the system. When IT asks, \u201cWhy is alex@partner.de in our system?\u201d, no one knows the answer. While it\u2019s possible to trace who invited the guest, there\u2019s no permanent, visible link to a project manager. The guest simply exists.<\/p>\n<p><span style=\"color: #003a93;\"><strong>With our IGA solution, the <a href=\"https:\/\/firstware.com\/en\/why-idm-portal\/\">FirstWare IDM-Portal<\/a>, you can define not only the sponsor attribute (the employee who invited the guest) but also a specific person in charge, such as a manager. This person is responsible for the guest throughout the guest\u2019s entire lifecycle.<\/strong><\/span><\/p>\n<p><strong>Over-privileged default settings<\/strong><\/p>\n<p>The default permissions for guests are surprisingly generous. For example, they can search for other users in the directory. While they don\u2019t see everything, they often see more than necessary.<\/p>\n<p>While this can be restricted in various ways (maximum isolation: \u201cGuest user access is limited to properties and memberships of their own directory objects.\u201d), many companies need finer-grained control that Microsoft does not currently provide. For example, it is often desired that guests be allowed to see only people from their own project.<\/p>\n<p><span style=\"color: #003a93;\"><strong>Our IGA solution enables fine-grained customization of guest accounts, ranging from simple guest accounts to guest accounts with privileged status (e.g., for partner companies). Work with us to define the guest access levels you need.<\/strong><\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-52991 size-large\" title=\"Guest account levels in the IDM-Portal\" src=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/06\/Guest-accounts-with-expansion-in-IDM-Portal-1024x417.webp\" alt=\"Guest account levels in the IDM-Portal\" width=\"1024\" height=\"417\" srcset=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/06\/Guest-accounts-with-expansion-in-IDM-Portal-980x399.webp 980w, https:\/\/firstware.com\/wp-content\/uploads\/2026\/06\/Guest-accounts-with-expansion-in-IDM-Portal-480x195.webp 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/p>\n<p><a href=\"https:\/\/firstware.com\/en\/contact\/\" target=\"_blank\" rel=\"noopener\"><button class=\"ButtonBeratung2 aligncenter\">Contact us today<\/button><\/a><\/p>\n<p><strong>Guest accounts with no expiration date<\/strong><\/p>\n<p>Here\u2019s how it works in practice: An employee invites a partner to join a project. The project ends, the employee leaves the company, and the guest account remains <strong>forever<\/strong> in the system. That\u2019s because a guest account has <strong>no expiration date<\/strong> from the start. Unless you intervene (technically) by:<\/p>\n<ol>\n<li>Manual deletion: An administrator deletes the user in the Entra ID Portal.<\/li>\n<li>Automated lifecycle: Microsoft offers rigid solutions to work around this, such as \u201cNo login for 90 days = deletion.\u201d But not every company wants such a strict, automated process for guest accounts.<\/li>\n<\/ol>\n<p><span style=\"color: #003a93;\"><strong>With the IDM-Portal, both the guest and the manager receive a reminder after (for example) 80 days that the account is about to expire.<\/strong><\/span><\/p>\n<p><strong>Collaboration vs. compliance<\/strong><\/p>\n<p>As mentioned several times before, the default settings in Microsoft are very open, meaning almost anyone can invite guests. Owners are allowed to do so by default anyway. Members cannot add guests directly, but they can send them a request. The team owner then simply needs to confirm this request.<\/p>\n<p>Of course, as mentioned earlier, Microsoft does have levels of control in place.<\/p>\n<p>Microsoft asks for consent to the privacy policy upon the first login, but this is very generic. Large companies often need to ensure that guests digitally sign an <b>specific non-disclosure agreement (NDA)<\/b>. This is difficult to integrate natively with the standard invitations.<\/p>\n<p><span style=\"color: #003a93;\"><strong>We believe that collaboration and compliance don\u2019t have to be mutually exclusive. With the IDM-Portal, we reconcile both. <\/strong><\/span><\/p>\n<h2 id=\"Our Solution\"><span class=\"ez-toc-section\" id=\"Our_solution_Multi-level_guest_accounts_and_clear_responsibilities\"><\/span>Our solution: Multi-level guest accounts and clear responsibilities<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"The_customers_situation_Loss_of_control_over_guest_accounts\"><\/span>The customer\u2019s situation: Loss of control over guest accounts<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Our client, a large enterprise with more than 10,000 employees, had lost control over its guest accounts. The barriers to accessing the company as a guest via a guest account were low. The threshold for inviting guests was equally low. As is often the case, it was difficult to rein in processes once they had gotten out of hand.<\/p>\n<p>All of these questions remained unresolved:<\/p>\n<ul>\n<li><strong>How do you handle different types of guests?<\/strong><\/li>\n<li><strong>What happens after guests are onboarded?<\/strong><\/li>\n<li><strong>How do you control the permissions guests are granted?<\/strong><\/li>\n<li><strong>Who is responsible for the lifecycle of a guest account?<\/strong><\/li>\n<\/ul>\n<p>The customer uses the IDM-Portal for its entire Identity &amp; Access Management. Together with the FirstAttribute team, the IDM-Portal was expanded to include a <strong>\u201cGuest user interface\u201d<\/strong>. In doing so, the guest account process was divided into:<\/p>\n<p>\u27a1\ufe0f Normal guest account<\/p>\n<p>\u27a1\ufe0f Advanced guest account<\/p>\n<p>\ud83e\udd13 Preview: In a subsequent update, special rules were also introduced for \u201cguest accounts with partner status.\u201d<\/p>\n<p>Here\u2019s how the two related processes differ:<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Normal_guest_account\"><\/span>Normal guest account<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>Every employee<\/strong> can still <strong>invite guests via MS Teams<\/strong>.<\/p>\n<p>The guest receives an invitation link. The \u201csponsor\u201d attribute is set automatically, meaning the inviting user is listed. When the guest accepts the invitation, they receive a basic guest account.<\/p>\n<p><strong>What can this \u201cbasic guest\u201d do?<\/strong><\/p>\n<p>They can collaborate and chat in Teams channels, participate in group chats, and edit files within the channels. They can only collaborate within Teams but cannot, for example, receive software.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Extended_guest_account\"><\/span>Extended guest account<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A second option is the so-called <strong>\u201cextended guest accounts\u201d<\/strong>. These are treated as a separate identity type.<\/p>\n<p>These guests are <strong>created and invited exclusively through the IDM-Portal<\/strong> by <strong>specialized IT teams<\/strong>, such as super admins, on-site IT, or the ServiceDesk.<\/p>\n<p><img decoding=\"async\" class=\"imgshadow aligncenter wp-image-49809\" title=\"&quot;Create guest user&quot; interface in the IDM-Portal\" src=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/04\/Create-Guest-User-Interface-full-view.png\" alt=\"&quot;Create guest user&quot; interface in the IDM-Portal\" width=\"900\" height=\"466\" \/><\/p>\n<p>The process works as follows:<\/p>\n<ol>\n<li>The IT department receives a <strong>ticket<\/strong> requesting the <strong>creation of an advanced guest account<\/strong>.<\/li>\n<li>When filling out the form, the <strong>identity information<\/strong> (first and last name, as well as display name) must be entered, as well as the guest\u2019s <strong>email address<\/strong>.<\/li>\n<li>The <strong>Manager<\/strong> must be designated. This is independent of the sponsor attribute (the person who invited the guest). It represents the permanent, visible link between the guest account and an internal employee who is responsible for the guest. Permissions can only be granted once the manager has been designated.<\/li>\n<li>The guest is created and receives an invitation link.<\/li>\n<li>The invitation status remains \u201cPending Acceptance\u201d until the guest has confirmed.<br \/>\n<img decoding=\"async\" class=\"imgshadow aligncenter wp-image-49814 size-full\" title=\"Guest account in IDM-Portal with pending acceptance\" src=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/04\/Gast-Account-mit-Pending-Acceptance-IDM-Portal.png\" alt=\"Guest account in IDM-Portal with pending acceptance\" width=\"639\" height=\"292\" srcset=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/04\/Gast-Account-mit-Pending-Acceptance-IDM-Portal.png 639w, https:\/\/firstware.com\/wp-content\/uploads\/2026\/04\/Gast-Account-mit-Pending-Acceptance-IDM-Portal-480x219.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 639px, 100vw\" \/><\/li>\n<li>If the guest accepts the invitation, their display name, UPN, and email address are automatically transmitted and stored in the IDM portal.<\/li>\n<li>The invitation status changes to \u201cAccepted\u201d.<\/li>\n<li>The \u201cCurrent Status\u201d is displayed as \u201cactive\u201d by default.<\/li>\n<li>Only after IT has manually confirmed <strong>acceptance of the Non-Disclosure Agreement (NDA)<\/strong> is the new guest considered an \u201cextended guest\u201d and can be granted special permissions. If<span data-teams=\"\u201ctrue\u201d\"> there is no NDA, i.e., if the corresponding checkbox is not selected, the user cannot be granted permissions. If you try to add the user to a group in the IDM portal and save the changes, an error message appears.<br \/>\n<\/span><\/li>\n<li>After agreeing to the NDA, the guest has the rights of an extended guest account.<\/li>\n<\/ol>\n<p><strong>What can this \u201cextended guest\u201d do?<\/strong><br \/>\nAlthough this guest remains an external user with their own email address, the system treats them as an internal employee.<\/p>\n<p>This enables them to collaborate much <strong>more seamlessly in MS Teams and SharePoint<\/strong>: They can search the directory directly for contacts, join organization-wide Teams, and use <strong>exclusive project hubs<\/strong> that remain off-limits to regular external users. In addition, they receive controlled access to <strong>sensitive SharePoint libraries<\/strong> containing important documents, as well as to shared <strong>SaaS services<\/strong>.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span>Conclusion<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>In large organizations, uncontrolled guest access without clear lifecycle management quickly leads to a loss of oversight.<\/p>\n<p>Our solution addresses these vulnerabilities through intelligent differentiation within the IDM portal: While <b>\u201cBasic Guest Accounts\u201d<\/b> enable rapid collaboration in MS Teams, <b>\u201cAdvanced Guest Accounts\u201d<\/b> provide a highly secure framework for the entire duration of the collaboration.<\/p>\n<p>By establishing clear <b>manager responsibilities<\/b>, requiring manual <b>NDA confirmation<\/b>, and implementing a structured <b>lifecycle<\/b>, we ensure that external partners receive only as much access as they need. This process makes it possible to securely integrate trusted guests into business-critical applications and reliably revoke access once the project is complete.<\/p>\n<p><a href=\"https:\/\/firstware.com\/en\/contact\/\" target=\"_blank\" rel=\"noopener\"><button class=\"ButtonBeratung aligncenter\">Book an appointment with our team<\/button><\/a><\/p>\n<h2><span class=\"ez-toc-section\" id=\"More_about_FirstWare_IDM-Portal\"><\/span>More about FirstWare IDM-Portal<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><img decoding=\"async\" class=\"alignleft wp-image-36704\" title=\"Markenbeschreiber IDM-Portal\" src=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/08\/Markenbeschreiber_IDM-Portal_2000x2000_webp-1.webp\" alt=\"Markenbeschreiber IDM-Portal\" width=\"238\" height=\"199\" \/>The <a href=\"https:\/\/firstware.com\/en\/\">FirstWare IDM-Portal<\/a> from FirstAttribute is a user-friendly IAM solution for the automated provisioning and lifecycle management of all identities and groups in complex, hybrid IT environments.<\/p>\n<p>Through targeted delegation and role-based access management, it enables business departments to independently manage identity data and permissions\u2014supplemented by powerful Identity Governance &amp; Administration (IGA) features such as audit logs, recertification, and compliance reporting.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Guest accounts, much like user accounts, have a life of their own. It begins with an invitation to a tenant and ends\u2026 well, when, exactly? Inviting guests is, at best, extremely simple, but the \u201cnext\u201d and \u201cend\u201d steps prove to be difficult. What sounds really nice and collaborative in theory\u2014\u201cEveryone can invite guests to Microsoft [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":52963,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[75],"tags":[348,344,347],"class_list":["post-52964","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-projects","tag-guest-account-management","tag-lifecycle-management","tag-m365-guest-accounts"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Managing the lifecycle of M365 guest accounts - Extended options<\/title>\n<meta name=\"description\" content=\"Securely manage the lifecycle of guest accounts in the IDM-Portal: with qualified guest accounts, NDA checks, and clear responsibilities.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Managing the lifecycle of M365 guest accounts - Extended options\" \/>\n<meta property=\"og:description\" content=\"Securely manage the lifecycle of guest accounts in the IDM-Portal: with qualified guest accounts, NDA checks, and clear responsibilities.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/\" \/>\n<meta property=\"og:site_name\" content=\"FirstWare IDM-Portal\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-30T12:42:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-25T14:39:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/firstware.com\/wp-content\/uploads\/2026\/09\/Logistik_Projekt.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t<meta property=\"og:image:height\" content=\"215\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Sophia Tunui\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Tunui\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/\"},\"author\":{\"name\":\"Sophia Tunui\",\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/#\\\/schema\\\/person\\\/6cfe72964832aba81d1c59435d89db4e\"},\"headline\":\"What is the best approach to managing the lifecycle of M365 guest accounts?\",\"datePublished\":\"2026-06-30T12:42:39+00:00\",\"dateModified\":\"2026-09-25T14:39:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/\"},\"wordCount\":1750,\"publisher\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/firstware.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Logistik_Projekt.webp\",\"keywords\":[\"guest account management\",\"Lifecycle Management\",\"M365 guest accounts\"],\"articleSection\":[\"Projects\"],\"inLanguage\":\"en-US\",\"hasPart\":[{\"@type\":\"SiteNavigationElement\",\"name\":\"Table of Contents\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#ez-toc\",\"position\":1,\"hasPart\":[{\"@type\":\"SiteNavigationElement\",\"name\":\"How does a guest join the tenant?\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#how-does-a-guest-join-the-tenant\",\"position\":2},{\"@type\":\"SiteNavigationElement\",\"name\":\"What are the real issues with the lifecycle of guest accounts?\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#what-are-the-real-issues-with-the-lifecycle-of-guest-accounts\",\"position\":3},{\"@type\":\"SiteNavigationElement\",\"name\":\"Our solution: Multi-level guest accounts and clear responsibilities\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#our-solution-multi-level-guest-accounts-and-clear-responsibilities\",\"position\":4},{\"@type\":\"SiteNavigationElement\",\"name\":\"The customer\u2019s situation: Loss of control over guest accounts\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#the-customers-situation-loss-of-control-over-guest-accounts\",\"position\":5},{\"@type\":\"SiteNavigationElement\",\"name\":\"Normal guest account\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#normal-guest-account\",\"position\":6},{\"@type\":\"SiteNavigationElement\",\"name\":\"Extended guest account\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#extended-guest-account\",\"position\":7},{\"@type\":\"SiteNavigationElement\",\"name\":\"Conclusion\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#conclusion\",\"position\":8},{\"@type\":\"SiteNavigationElement\",\"name\":\"More about FirstWare IDM-Portal\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#more-about-firstware-idm-portal\",\"position\":9}]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/\",\"name\":\"Managing the lifecycle of M365 guest accounts - Extended options\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/firstware.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Logistik_Projekt.webp\",\"datePublished\":\"2026-06-30T12:42:39+00:00\",\"dateModified\":\"2026-09-25T14:39:53+00:00\",\"description\":\"Securely manage the lifecycle of guest accounts in the IDM-Portal: with qualified guest accounts, NDA checks, and clear responsibilities.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#primaryimage\",\"url\":\"https:\\\/\\\/firstware.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Logistik_Projekt.webp\",\"contentUrl\":\"https:\\\/\\\/firstware.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Logistik_Projekt.webp\",\"width\":350,\"height\":215,\"caption\":\"Logistik_Projekt\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/blog\\\/lifecycle-management-guest-accounts\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Start\",\"item\":\"https:\\\/\\\/firstware.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What is the best approach to managing the lifecycle of M365 guest accounts?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/\",\"name\":\"FirstWare IDM-Portal\",\"description\":\"Identit\u00e4ts- und Access Management\",\"publisher\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/firstware.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/#organization\",\"name\":\"FirstWare IDM-Portal\",\"url\":\"https:\\\/\\\/firstware.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/firstware.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FirstWare-Website-Icon.png\",\"contentUrl\":\"https:\\\/\\\/firstware.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/FirstWare-Website-Icon.png\",\"width\":1024,\"height\":1024,\"caption\":\"FirstWare IDM-Portal\"},\"image\":{\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/firstware.com\\\/en\\\/#\\\/schema\\\/person\\\/6cfe72964832aba81d1c59435d89db4e\",\"name\":\"Sophia Tunui\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Managing the lifecycle of M365 guest accounts - Extended options","description":"Securely manage the lifecycle of guest accounts in the IDM-Portal: with qualified guest accounts, NDA checks, and clear responsibilities.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/","og_locale":"en_US","og_type":"article","og_title":"Managing the lifecycle of M365 guest accounts - Extended options","og_description":"Securely manage the lifecycle of guest accounts in the IDM-Portal: with qualified guest accounts, NDA checks, and clear responsibilities.","og_url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/","og_site_name":"FirstWare IDM-Portal","article_published_time":"2026-06-30T12:42:39+00:00","article_modified_time":"2026-09-25T14:39:53+00:00","og_image":[{"width":350,"height":215,"url":"https:\/\/firstware.com\/wp-content\/uploads\/2026\/09\/Logistik_Projekt.webp","type":"image\/webp"}],"author":"Sophia Tunui","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sophia Tunui","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#article","isPartOf":{"@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/"},"author":{"name":"Sophia Tunui","@id":"https:\/\/firstware.com\/en\/#\/schema\/person\/6cfe72964832aba81d1c59435d89db4e"},"headline":"What is the best approach to managing the lifecycle of M365 guest accounts?","datePublished":"2026-06-30T12:42:39+00:00","dateModified":"2026-09-25T14:39:53+00:00","mainEntityOfPage":{"@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/"},"wordCount":1750,"publisher":{"@id":"https:\/\/firstware.com\/en\/#organization"},"image":{"@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#primaryimage"},"thumbnailUrl":"https:\/\/firstware.com\/wp-content\/uploads\/2026\/09\/Logistik_Projekt.webp","keywords":["guest account management","Lifecycle Management","M365 guest accounts"],"articleSection":["Projects"],"inLanguage":"en-US","hasPart":[{"@type":"SiteNavigationElement","name":"Table of Contents","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#ez-toc","position":1,"hasPart":[{"@type":"SiteNavigationElement","name":"How does a guest join the tenant?","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#how-does-a-guest-join-the-tenant","position":2},{"@type":"SiteNavigationElement","name":"What are the real issues with the lifecycle of guest accounts?","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#what-are-the-real-issues-with-the-lifecycle-of-guest-accounts","position":3},{"@type":"SiteNavigationElement","name":"Our solution: Multi-level guest accounts and clear responsibilities","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#our-solution-multi-level-guest-accounts-and-clear-responsibilities","position":4},{"@type":"SiteNavigationElement","name":"The customer\u2019s situation: Loss of control over guest accounts","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#the-customers-situation-loss-of-control-over-guest-accounts","position":5},{"@type":"SiteNavigationElement","name":"Normal guest account","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#normal-guest-account","position":6},{"@type":"SiteNavigationElement","name":"Extended guest account","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#extended-guest-account","position":7},{"@type":"SiteNavigationElement","name":"Conclusion","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#conclusion","position":8},{"@type":"SiteNavigationElement","name":"More about FirstWare IDM-Portal","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#more-about-firstware-idm-portal","position":9}]}]},{"@type":"WebPage","@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/","url":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/","name":"Managing the lifecycle of M365 guest accounts - Extended options","isPartOf":{"@id":"https:\/\/firstware.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#primaryimage"},"image":{"@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#primaryimage"},"thumbnailUrl":"https:\/\/firstware.com\/wp-content\/uploads\/2026\/09\/Logistik_Projekt.webp","datePublished":"2026-06-30T12:42:39+00:00","dateModified":"2026-09-25T14:39:53+00:00","description":"Securely manage the lifecycle of guest accounts in the IDM-Portal: with qualified guest accounts, NDA checks, and clear responsibilities.","breadcrumb":{"@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#primaryimage","url":"https:\/\/firstware.com\/wp-content\/uploads\/2026\/09\/Logistik_Projekt.webp","contentUrl":"https:\/\/firstware.com\/wp-content\/uploads\/2026\/09\/Logistik_Projekt.webp","width":350,"height":215,"caption":"Logistik_Projekt"},{"@type":"BreadcrumbList","@id":"https:\/\/firstware.com\/en\/blog\/lifecycle-management-guest-accounts\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Start","item":"https:\/\/firstware.com\/en\/"},{"@type":"ListItem","position":2,"name":"What is the best approach to managing the lifecycle of M365 guest accounts?"}]},{"@type":"WebSite","@id":"https:\/\/firstware.com\/en\/#website","url":"https:\/\/firstware.com\/en\/","name":"FirstWare IDM-Portal","description":"Identit\u00e4ts- und Access Management","publisher":{"@id":"https:\/\/firstware.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/firstware.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/firstware.com\/en\/#organization","name":"FirstWare IDM-Portal","url":"https:\/\/firstware.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/firstware.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/firstware.com\/wp-content\/uploads\/2026\/08\/FirstWare-Website-Icon.png","contentUrl":"https:\/\/firstware.com\/wp-content\/uploads\/2026\/08\/FirstWare-Website-Icon.png","width":1024,"height":1024,"caption":"FirstWare IDM-Portal"},"image":{"@id":"https:\/\/firstware.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/firstware.com\/en\/#\/schema\/person\/6cfe72964832aba81d1c59435d89db4e","name":"Sophia Tunui"}]}},"_links":{"self":[{"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/posts\/52964","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/comments?post=52964"}],"version-history":[{"count":9,"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/posts\/52964\/revisions"}],"predecessor-version":[{"id":53010,"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/posts\/52964\/revisions\/53010"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/media\/52963"}],"wp:attachment":[{"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/media?parent=52964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/categories?post=52964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/firstware.com\/en\/wp-json\/wp\/v2\/tags?post=52964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}