Post

Finding Guest Users with Elevated Permissions Across Microsoft 365

Diesen Beitrag auf Deutsch lesen

A PnP PowerShell script cross-checks guest accounts against Entra ID roles, Teams ownership and SharePoint site admin lists in one CSV report.

TL;DR

A PnP PowerShell script cross-checks guest accounts against Entra ID directory roles, Teams ownership, and SharePoint site collection administrator lists, then exports a CSV with display name, UPN, permission type and resource — closing a gap where no built-in Microsoft 365 report combines all three.

Original by Josiah Opiyo, on Microsoft 365 & Power Platform Community Blog. Read the original

This is our own summary, not a republication or full translation.

Governance takeaway

  • Security/Compliance: schedule this script as a recurring review, not a one-off audit — guest accounts routinely keep admin rights after a project ends simply because nobody re-checks three separate portals by hand.
  • Admins/CoE: get a concrete tool out of it — run it against Entra ID roles, Teams ownership, and SharePoint site admin lists in one pass instead of stitching results together manually.
  • Leadership/Business: treat a stale guest account with elevated rights as a live external-access risk, not a cleanup task that can wait for the next audit cycle.
This post is licensed under CC BY 4.0 by the author.