0:00–0:10
Recap
0:10–0:40
Lecture
0:40–1:40
Guided Lab
1:40–1:50
Bonus
1:50–2:00
Debrief
⟷ Inter-tenant lab pairing — set up before class begins

Students are paired for this lab. Each pair consists of Student A (the inviting tenant) and Student B (the guest). Both students experience both roles during the lab. Exchange the following with your partner before the lecture begins:

0:00 – 0:10Recap · 10 min

Day 2 review & the external collaboration gap

0:10 – 0:40Lecture · 30 min

Guest access vs external access — two very different models

The single most commonly confused distinction in Teams administration. Both let external people communicate with your team — but the architecture, capabilities, and governance are completely different.

Guest Access (B2B)
External person is invited → Entra ID creates a guest account in your tenant → they authenticate with their home credentials → they see your tenant's Teams interface → they appear in your user directory → subject to your CA policies → can access files, chats, channels, apps you permit
External Access (Federation)
External person is not invited → no account in your tenant → they use their home tenant's Teams → can only search for and chat/call people in your org → cannot access teams, channels, files, or apps → no entry in your user directory
CapabilityGuest access (B2B)External access (federation)
Account in your tenant?Yes — Entra ID guest account createdNo — uses their home tenant account
Can join a Teams team?Yes — invited as a team memberNo
Can access channel files?Yes (if permitted by guest settings)No
Can chat with internal users?YesYes — 1:1 and group chat only
Can make audio/video calls?YesYes
Subject to host CA policies?Yes — your CA policies evaluate guest sign-insNo — governed by their home tenant
Appears in your user directory?Yes — as a guest userNo
Requires invite?Yes — team owner or admin must inviteNo — available if federation is enabled
Configured where?Teams Admin Centre → Org-wide settings → Guest accessTeams Admin Centre → Org-wide settings → External access
Instructor note: The inter-tenant lab makes this distinction observable rather than theoretical. When Student B receives a guest invitation from Student A's tenant, they will see it from both sides simultaneously — Student A sees a new guest account appear in their Entra ID, Student B experiences signing into an unfamiliar tenant as a guest. This dual perspective is the most effective way to teach the guest model.
0:40 – 1:40Guided lab · 60 min

Lab 5-C: Inter-tenant guest access and external federation

Paired with a classmate's tenant, students configure guest access settings, update the SharePoint allow list to permit their partner's domain, invite their partner as a guest to the Sales team, experience the guest sign-in from the other side, test guest limitations, configure external access federation, and compare the two collaboration models side by side.

Before starting: You need your partner's tenant domain and their admin UPN. If you haven't exchanged these yet, do it now. Record both in your Lab Journal before Step 1.
Instructor note: The tenant switcher experience in Step 4 is a moment students consistently find surprising. Signing into Teams with your normal credentials and switching to a completely different organisation's tenant — and seeing how limited your access is — makes the guest model viscerally real. Walk the class through this on the projector simultaneously. The contrast between "what I can see in my own tenant" and "what I can see as a guest" is the lesson.
1:40 – 1:50Bonus · 10 min

⭐ Bonus: Guest policy settings & monitoring

⭐ Bonus A — Configure per-team guest permissions
  • In the Sales team settings (Teams Admin Centre → the Sales team → Settings tab), configure the guest-specific permissions to be more restrictive than the org-wide guest settings: disable Allow guests to create/update channels, disable Allow guests to delete channels
  • Verify from your partner's guest perspective — can they still post messages after this change?
  • In your Lab Journal: explain the relationship between org-wide guest settings and per-team guest settings — which takes precedence when they conflict?
⭐ Bonus B — Monitor guest activity
  • Navigate to Teams Admin Centre → Analytics & reports → Usage reports → Teams user activity. Review the report for your tenant. Can you identify guest activity vs internal user activity?
  • Navigate to entra.microsoft.comUsers → your partner's guest account → Sign-in logs. Review the sign-in events from today's lab — what resource did they authenticate to, what IP, and what conditional access result is shown?
  • In your Lab Journal: what governance value does monitoring guest sign-in activity provide? What specific risk does it help detect?
1:50 – 2:00Debrief · 10 min

Reflection & preview

Learning outcomes — by end of Day 3, students can…

Distinguish guest vs external accessExplain the architectural, capability, and governance difference between B2B guest accounts and federation
Configure guest access settingsEnable and tune org-wide guest capabilities in the Teams Admin Centre
Invite an inter-tenant guestInvite a real M365 user from another tenant and observe the Entra ID guest account creation
Experience the guest perspectiveSign into another tenant as a guest and document what is and is not accessible
Configure external accessSet up domain-specific federation and compare the experience with guest access
Explain CA policy interactionDescribe how conditional access evaluates guest sign-ins and when MFA is or isn't triggered

What you need ready

Lab partners pre-assigned (A ↔ B) Each student knows their partner's tenant domain and admin UPN SharePoint allow list from Lab 4-C accessible Teams client (teams.microsoft.com) Lab 5-C step sheet
Day 4 →Week 5 Overview