Finding Guest Users with Elevated Permissions Across Microsoft 365
Diesen Beitrag auf Deutsch lesen
A PnP PowerShell script cross-checks guest accounts against Entra ID roles, Teams ownership and SharePoint site admin lists in one CSV report.
TL;DR
A PnP PowerShell script cross-checks guest accounts against Entra ID directory roles, Teams ownership, and SharePoint site collection administrator lists, then exports a CSV with display name, UPN, permission type and resource — closing a gap where no built-in Microsoft 365 report combines all three.
Original by Josiah Opiyo, on Microsoft 365 & Power Platform Community Blog. Read the original
This is our own summary, not a republication or full translation.
Governance takeaway
- Security/Compliance: schedule this script as a recurring review, not a one-off audit — guest accounts routinely keep admin rights after a project ends simply because nobody re-checks three separate portals by hand.
- Admins/CoE: get a concrete tool out of it — run it against Entra ID roles, Teams ownership, and SharePoint site admin lists in one pass instead of stitching results together manually.
- Leadership/Business: treat a stale guest account with elevated rights as a live external-access risk, not a cleanup task that can wait for the next audit cycle.
