Purview Sensitivity label: User defined permissions doesn't allow access to consumers that are not guest in my tenant

Sergio Londono 566 Reputation points
2024-07-29T22:57:56.9466667+00:00

Hello team,

Purview Sensitivity label: User defined permissions doesn't allow access to consumers that are not guest in my tenant.

Issue:

User defined permissions not allowed access to remote users that are not present as guest in my Entra ID directory.

 

Scenario:

  1. User apply sensitivity label user-defined permissions to grant access to remote users are not present in the entra ID that is applying the protection.

 

  1. The consumer try to open the file with the account granted the permissions, however, it can't access to the content. Entra ID is requesting to create the account as guest in the tenant that apply the protection.

 

Problem:

This is a big issue because for any file protected by user-defined permissions, the remote user needs to be added as a guest.

 

The same behavior apply for OfficeApps and PDFs.

 

Question

is there any way to allow users granted with user-defined permissions access the protected data without need to create the guest account?

User's image

User's image

User's image

User's image

Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,166 questions
0 comments No comments
{count} votes

Accepted answer
  1. Ahamed Musthafa Careem 461 Reputation points
    2024-07-31T14:38:09.3533333+00:00

    Hi @Sergio Londono ,

    As of my last knowledge update, there isn’t a direct way to bypass the guest account requirement for external users with user-defined permissions in Microsoft Purview Sensitivity Labels. However, you can explore Azure AD Business-to-Business (B2B) collaboration. B2B collaboration enables external users to access resources without being guests in your tenant. Keep in mind that this approach might not align perfectly with user-defined permissions.

    Thanks


1 additional answer

Sort by: Most helpful
  1. Sergio Londono 566 Reputation points
    2024-07-30T17:37:34.33+00:00

    Hello team,

    I found other Microsoft documentation specific to this issue:

    Apply encryption using sensitivity labels | Microsoft Learn

    User's image

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.