Your input shapes our product. Suggest a feature now →
  1. Home
  2. Blog
  3. SharePoint Guest Access Reviews

SharePoint Guest Access Reviews: What Admins Need to Know

Published: 9 August 2026  |  Category: Permissions and Governance

Eighteen months ago a project team invited a dozen consultants into their SharePoint environment. The project finished. The consultants moved on. The external user records did not. Today those accounts still appear in every permissions report, and no one who owns the site even remembers the engagement. This is one of the most common governance problems in Microsoft 365, and in 2026 Microsoft addressed it by making access reviews mandatory rather than optional.

For SharePoint admins, mandatory guest access reviews change both the day-to-day operational picture and the compliance obligations around external sharing.

What Are Guest Access Reviews in SharePoint Online?

Guest access reviews are periodic audits managed through Microsoft Entra ID that prompt assigned reviewers to confirm whether external users still need access to SharePoint sites, Teams channels, and Microsoft 365 groups. Each reviewer sees a list of guests associated with a resource and either approves or denies their continued access. Denied or unreviewed guests are then automatically removed.

Reviews live in Microsoft Entra ID under Identity Governance > Access Reviews and operate at the group membership level. Because modern SharePoint team sites are backed by Microsoft 365 groups, a guest removed from the group also loses access to the associated SharePoint document library, list, and pages.

The review cadence is configurable. Microsoft defaults to quarterly, which strikes a reasonable balance between governance thoroughness and reviewer burden for most tenants. You can adjust this to monthly for high-risk sites or annually for low-activity resources.

What Changed in 2026: Microsoft's Mandatory Review Enforcement

Before 2026, access reviews required an admin to navigate to Entra ID, create a review policy, assign reviewers, and enable the feature explicitly. Many organisations, particularly smaller tenants without a dedicated identity governance function, never completed this setup.

Starting with Message Centre notification MC1398452, Microsoft now creates a baseline guest review policy for all commercial tenants automatically - no admin setup required. The policy runs on a quarterly schedule, targets all external users in Microsoft 365 groups connected to SharePoint, and defaults to removing access for guests not reviewed within the window.

The practical consequence for admins who have not yet reviewed Entra ID access review settings: a default policy is already running in your tenant. If review notifications are landing in an inbox that no one monitors, guests may be losing access automatically. Check Audit Logs > Access Reviews in Entra ID to see which guests were removed and when.

Note: The mandatory policy applies to guests in Microsoft 365 groups. External users invited to a classic SharePoint site via direct site-level sharing, rather than through a Microsoft 365 group, fall under a different governance model and may not be captured by the Entra ID review. Classic site external access requires a separate permissions audit.

Which Resources Are Covered

The access review targets any Microsoft 365 group that has external members. In practice this covers:

  • Modern SharePoint team sites: Every modern team site created through SharePoint admin or Microsoft 365 Groups has a backing group. External members of that group appear in the review.
  • Microsoft Teams-connected sites: Teams channels are group-backed. A guest in a Teams team is also a guest member of the group, so they appear in the SharePoint review for the same resource.
  • Microsoft 365 Group-connected resources generally: A guest invited to a group gets access to the group's SharePoint site, Planner board, and shared mailbox. The access review covers all of this via the single group membership record.

What the review does not cover: directly-assigned SharePoint permissions. If an admin or site owner assigned a guest user unique permissions on a specific library, list, or folder, that assignment bypasses group membership and is invisible to the Entra ID access review. This gap matters more than most admins realise; it is where the longest-standing stale guest permissions tend to accumulate.

Configuring Reviews to Match Your Governance Needs

Review frequency and duration

Quarterly is the right default for most tenants. Sites with sensitive content, such as legal matter sites, financial model libraries, or HR documentation, warrant monthly reviews. The review duration, the window during which reviewers must act, defaults to 14 days. Extend this to 21 or 28 days if your organisation has slow approval workflows or if site owners are frequently unavailable during review periods.

Action on non-response

This is the setting that matters most. The options are:

Setting What happens to unreviewed guests Best for
Remove access (default from 2026) Access is automatically revoked when the review period closes Most tenants; provides the highest security posture
Approve access Access is silently extended as if approved Low-risk tenants with high reviewer-completion risk; generally not recommended
No action Access remains but the review is flagged as pending for manual resolution Organisations that require manual sign-off before any removal occurs

The remove-on-inaction default is the right posture for most organisations. The risk of a stale guest retaining access indefinitely outweighs the inconvenience of re-inviting a guest who was removed by mistake. Re-inviting takes minutes; discovering a stale account with broad site access can take months.

Audit guest access with ShareMaster

What Happens After a Review: The Gaps That Remain

Even a well-configured access review leaves a significant gap. Guests removed from group membership still retain any directly-assigned SharePoint permissions. A consultant who was shared a document library folder directly, rather than via a Teams or group invite, may not be a group member at all. The access review never touches that permission assignment.

A complete guest access governance programme requires two components working together: the Entra ID access review to handle group-based access, and a SharePoint permissions audit to surface direct assignments. The permissions audit should run at least quarterly, and more often for tenants where sharing links are created frequently.

ShareMaster's Shared Links and Permissions tool generates a full export of all external user assignments across your SharePoint tenant, including direct permissions, sharing links, and inherited access from parent sites. It makes the gap between what the access review removed and what external access still exists visible in a single report. For the complete external user audit workflow, see the guide to auditing SharePoint external users.

Building Reviews Into Your Quarterly Admin Cadence

Treating access reviews as a one-time setup creates a false sense of security. A sustainable cadence looks like this:

  • Before each quarterly review cycle: Confirm that reviewer assignments are still correct. A site owner who left the organisation cannot complete a review. Update assignments in Entra ID before the review window opens, not after it has expired.
  • During the review window: Monitor completion rates. Entra ID shows which reviews are in progress and which are past their deadline. Follow up with non-responding reviewers before the window closes.
  • After each review cycle: Run a SharePoint permissions report to catch direct assignments that the group-based review missed. Remove or confirm access for any guest who still appears in the direct-assignment report but was not renewed in the Entra ID review.
  • Annually: Review the access review policy configuration itself. Adjust scope, frequency, and reviewer assignments as your tenant's external sharing profile changes.

The quarterly permissions report is the step most admin teams skip, and it is precisely the step that finds the permissions lingering for years after a project ends.

Frequently Asked Questions

What are guest access reviews in SharePoint Online?

Guest access reviews are periodic checks managed in Microsoft Entra ID that prompt site owners or assigned reviewers to confirm whether external users still need access to SharePoint sites and Microsoft 365 groups. Unreviewed guests can be automatically removed based on the action-on-non-response setting.

Can I opt out of mandatory guest access reviews in Microsoft 365?

You cannot fully disable the mandatory review policy in most commercial Microsoft 365 tenants. You can adjust the review frequency, change who acts as reviewer, and modify what happens when reviews are not completed. All controls are in the Microsoft Entra admin centre under Identity Governance.

Do guest access reviews cover directly-assigned SharePoint permissions?

No. Entra ID access reviews only cover group-based access. Guests assigned direct permissions on a SharePoint library or folder are not visible to the access review. A separate SharePoint permissions audit is needed to surface and remove direct guest assignments.

What happens when a reviewer misses the access review deadline?

The default from 2026 is to remove access for guests who were not reviewed before the deadline. Admins can change this to approve access automatically or leave access unchanged for manual follow-up, but remove-on-inaction is the most secure posture.

How does ShareMaster help with guest access cleanup after an access review?

ShareMaster's Shared Links and Permissions tool audits all external users across your SharePoint tenant, including those with directly-assigned permissions that access reviews miss. You can identify stale guests, bulk-remove shared links, and reset broken permission inheritance across multiple sites in one operation.

Try ShareMaster free for 14 days