How to Write Conditional Access Policies for Contractors and Guests
Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.
Contractors and guests often have less oversight than employees but similar access. Conditional Access lets you apply consistent — or stricter — controls. Here is how.
Step 1: Identify external users
- Guests (B2B collaboration): users from other tenants or personal accounts invited to your tenant.
- Contractors with member accounts in your directory. Mark them clearly with attributes (such as
employeeType) or groups. - Service provider users accessing via partner relationships.
Step 2: Require MFA for guests and contractors
Create a Conditional Access policy targeting Guest or external users (select the external user types) and your contractor group, requiring MFA with an appropriate authentication strength.
Use cross-tenant access settings to decide whether to trust MFA performed in a partner's home tenant. Trust only from partners whose MFA you're confident in.
Step 3: Require managed devices or limit access
Contractors often use their own or their employer's devices. Options:
- Require compliant devices (if you manage contractor devices).
- Trust compliant device claims from partner tenants via cross-tenant settings.
- Otherwise, allow browser-only access with app-enforced restrictions (no downloads) for SharePoint and Exchange.
Step 4: Limit session lifetime
Apply sign-in frequency controls for external users, for example every 12 hours.
Step 5: Restrict what they can access
Use access packages (entitlement management) with expiration dates, and exclude contractors from sensitive apps unless approved.
Step 6: Review regularly
Run quarterly access reviews for guests and contractors, and remove inactive accounts automatically.
Verify
Sign-in logs for external users should show MFA satisfied and the expected policies applied.