Detecting Teams Guest Access Risk: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.
Guest accounts and broad Teams access can quietly expose sensitive data. These detections highlight risky guest activity and sharing.
Signals worth watching
- Guests added to Teams or groups that contain sensitive data or carry Confidential labels.
- Guests from personal email domains (gmail.com, outlook.com) added to internal Teams.
- Guests downloading large numbers of files.
- Guest accounts that haven't signed in for months but still have access.
- Anonymous "Anyone" links created for files in sensitive sites.
Where the data lives
- Entra ID audit logs: guest invitations and group membership changes.
- Microsoft 365 audit log (OfficeActivity / CloudAppEvents): Teams membership, file access, sharing link creation.
- Defender for Cloud Apps: policies for guest activity and mass downloads.
A starting query
Guests added to Teams:
OfficeActivity
| where Operation == "MemberAdded"
| mv-expand Member = Members
| extend UPN = tostring(Member.UPN)
| where UPN has "#EXT#"
| project TimeGenerated, UserId, TeamName, UPN
Correlate team names with your list of sensitive Teams or with sensitivity labels.
Response
- Confirm the business need with the Team owner.
- Remove guests who don't need access.
- Review files accessed by the guest.
- Apply sensitivity labels to restrict guest access for sensitive Teams going forward.
- The COVID-19 Remote Work Shift (Mar 2020): Teams Sprawl, Guest Access and Shadow IT Incident Teardowns
- How to Govern Teams Creation, Guest Access and Expiration Policies How-To & Hardening
- CIO Brief: Cleaning Up the Pandemic's Collaboration Mess CIO Briefings