We have been running into a problem sharing sensitive information with external guest accounts

James Kenneally 0 Reputation points
2025-06-18T20:45:24.2633333+00:00

We have been running into a problem sharing sensitive information with external guest accounts. we are configured for external sharing using guest accounts. now emails are not able to be sent and sharing via onedrive is failing as well.

encryption, password protection, changing file format... nothing seems to work. I am creating users for them. is that the only way?

Microsoft Security | Microsoft Purview
{count} votes

1 answer

Sort by: Most helpful
  1. Smaran Thoomu 24,575 Reputation points Microsoft External Staff Moderator
    2025-06-19T02:33:40.99+00:00

    Hi @James Kenneally
    If you're having issues sharing sensitive data with external guest accounts, even after enabling external sharing, the problem likely stems from either Microsoft Purview Information Protection policies or Microsoft Entra B2B collaboration settings.

    Here are the key areas to check:

    1. Sensitivity labels and DLP policies Review the sensitivity labels applied through Microsoft Purview. Make sure they permit sharing with guests. Also, check for any DLP policies that might be blocking sharing or email delivery when sensitive data is involved.
    2. OneDrive and Microsoft 365 external sharing settings Go to the OneDrive admin center and ensure external sharing is enabled for guests. Confirm that the sharing link type allows access to specific people or guests, not just internal users.
    3. Microsoft Entra ID (formerly Azure AD) external collaboration policies In the Microsoft Entra admin portal, check the external identities configuration. Ensure guests are not blocked by restrictions like conditional access policies, required MFA, or blocked domains.
    4. Email encryption and delivery behavior When sending encrypted content, guests may need to authenticate with a Microsoft account or another identity provider. If the guest user doesn't meet the expected authentication model, access will fail. You can temporarily test this by sending the same file without encryption to rule out the cause.

    If none of these options work, then yes, creating users directly in your tenant might be necessary if your organization requires full control over access, compliance, and auditing for external collaboration.

    I hope this information helps. Please do let us know if you have any further queries.


    Kindly consider upvoting the comment if the information provided is helpful. This can assist other community members in resolving similar issues.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.