question

SchwarzerADM-1460 avatar image
0 Votes"
SchwarzerADM-1460 asked emilyhua-msft answered

Some guests are added to AAD automatically, but setting is turned off

Hello!

I have a problem with creating guest accounts in AAD.
I don't want them to be created automatically.

1) In the External collaboration settings the following is set:
- No one in the organization can invite guest users including admins (most restrictive).
- Enable guest self-service sign up via user flows = set to no
2) External Identities are not yet configured.
3) Sharing in OneDrive is set to: New and existing external users

Problem:
When I share a file from OneDrive with an external person a guest account is created immediately.
BUT: This is not the case for all external persons. With my private email address this does not happen.

Questions:
a) Why are guest accounts created automatically despite my configuration?
b) Why are guests only partially created?
c) How do I turn this off?

Kind regards
Margit


office-onedrive-client-itpro
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

emilyhua-msft avatar image
0 Votes"
emilyhua-msft answered

@SchwarzerADM-1460

The tag "office-onedrive-client-itpro" focus more on general issues of OneDrive client, but you issue is more realted to OneDrive Admin Center, which is not supported on Q&A forum currently.
To better help you, I would suggest you post a new question on the following forum.
Microsoft Tech Community for Admin Center

The following content is my personal opinion.

Did you enable SharePoint and OneDrive integration with Azure AD B2B?
According to this article, "Secure external sharing recipient experience", if you enable this feature, after the external user enters the one-time passcode, they will authenticate with their account and have a guest account created in the host's organization.
84412-untitled1.png

Besides, you set "New and existing external users" for OneDrive, the new external users would have their guest account after passing the identity verification.
I suggest you change the organization-level external sharing setting to "Existing guests", then it would allow sharing only with guests who are already in your directory.


If an Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


untitled1.png (40.3 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.