External users accumulate quietly. A project begins, a contractor is invited, the engagement ends, but the guest account stays. Six months later that person still has access to document libraries containing commercial data that is no longer relevant to them. Multiply that pattern across a growing Microsoft 365 tenant and an external user audit becomes long overdue.
This guide covers every method for finding and reviewing external users in SharePoint Online: the Microsoft 365 admin centre, the per-site sharing report, PnP PowerShell, and ShareMaster's Report Master for a library-level breakdown exportable to Excel. By the end you will have a clear list of every guest account with access to your environment and the context to decide what to do with each one.
What counts as an external user in SharePoint Online?
An external user is anyone accessing your SharePoint Online sites without a licensed account in your Microsoft 365 tenant. Two categories matter here:
- Authenticated guests: People who signed in using a Microsoft account or an account from another Entra ID tenant. They appear in your directory as B2B guest users with
#EXT#in their user principal name, such ascontractor#EXT#@example.com. - Sharing link recipients: Anyone who received an "Anyone" or "People with the link" sharing link. Depending on the link type, these users may have no directory entry in your tenant at all.
This guide focuses on authenticated guests because their access is the most persistent and the most often overlooked. Sharing link audit is its own discipline; the companion guide on auditing shared links across your tenant covers that side of the picture.
Why external user access audits matter
Three situations make a periodic external user audit non-negotiable.
Contractor and partner offboarding. When an engagement ends, IT is rarely notified in time to remove guest access before the final invoice. Without a formal offboarding checklist that includes SharePoint permissions, former contractors routinely retain access for months or longer. A quarterly audit catches what offboarding missed.
Compliance requirements. ISO 27001, SOC 2, and most industry-specific frameworks require organisations to maintain a current, accurate list of who has access to information systems. A guest list that has never been reviewed is a gap that auditors will flag. Demonstrating a documented review cycle closes that gap.
Conditional access and identity hygiene. A large population of stale Entra ID guest accounts creates noise in identity reports, complicates conditional access policy targeting, and can interfere with Microsoft Entra ID Governance features if those are in use.
How to find external users in the Microsoft 365 admin centre
Check the Guest users list
- Go to the Microsoft 365 admin centre (admin.microsoft.com) and sign in with a global admin or user management admin account.
- Expand Users, then select Guest users. Every guest added through Teams, SharePoint or Microsoft Entra appears here.
- Review the list. Guest accounts show no assigned Microsoft 365 licence and typically have a display name set to the external user's email address or their full name from their home organisation.
- For sign-in activity, open the same account in the Microsoft Entra admin centre, whose user overview shows the last sign-in. Accounts with no sign-in activity in 90 days or more are strong candidates for removal.
The admin centre guest list is tenant-wide. It tells you which guest accounts exist but not which SharePoint sites or libraries each person can access. For that you need a site-level permissions export.
Run the site sharing report
- Open the site and go to Settings, then Site usage. You need to be a site admin.
- Under Shared with external users, select Run report and choose a library on the site to save it in. Pick a folder that only owners can open.
- When it finishes, open the CSV. It has one row per shared item and user or link, with the permission, the user or group type and the link type. Despite the heading, internal shares are included too.
- Filter the user columns for addresses outside your own domains to isolate external access.
The sharing report works one site at a time and lists SharePoint groups without expanding their members, so a guest who sits inside the site's Members group shows up only as the group. Use it to rank your sites, then use the steps below to drill into each one.
How to audit external users across a site with ShareMaster
The native tools give you account lists and per-site share lists. Report Master's Security Matrix report gives you, for the lists and libraries you choose on a site, who holds which permission level, with every SharePoint group expanded to the people inside it, all exported to Excel in one operation. It is free on the Community licence.
Connect to the site
- Open ShareMaster, go to Reports and choose Security Matrix.
- Connect to the site you want to audit with an account that can read its permissions, such as a site collection administrator. For a broad audit, work through your highest-risk sites as identified in the sharing report above.
Generate the permissions matrix
- Tick the lists and libraries to include. Tick Show Hidden Items if you also need system lists.
- Select Create Report. ShareMaster reads the site's permissions, its SharePoint groups and their members, the hidden sharing-link groups, and every item with unique permissions in the lists you picked.
The permissions matrix is especially effective at surfacing external users who were given access to a single file or folder rather than through a site-level group. Those item-level grants are precisely the ones admin centre views most often miss.
Filter the workbook for guests
- Save the workbook and open it in Excel. It has a Web Permissions sheet, a SharePoint Groups sheet, a Sharing Links sheet, and a sheet per list that has items with unique permissions.
- On the SharePoint Groups and Sharing Links sheets, each member is listed with their name, login name and email. Filter the login name column for cells containing
#EXT#to isolate authenticated guests. - On the Web Permissions and per-list sheets, people granted access directly are listed by display name, with an X under each permission level they hold. Check those names against your guest list. Full Control or Edit access held by an external user warrants immediate scrutiny.
- Cross-reference with the guest account list from the admin centre. Any guest account that appears in the permissions export but has not signed in recently is a priority for removal.
What to do with your audit results
Once you have a filtered list of external users with their permission scopes, work through it in three passes.
Pass 1: Remove clearly stale accounts. Any guest who has not signed in for 90 or more days and whose engagement has ended should be removed. The default position should be that access is removed unless there is a current, documented reason to keep it. Do not retain access "just in case."
Pass 2: Right-size active accounts. Some external users may have broader access than their role requires. A supplier with member-level access to an entire team site may only need read access to a single shared library. Reducing scope limits risk without disrupting legitimate collaboration.
Pass 3: Document and schedule the next review. Record the audit date, the sites reviewed, the accounts removed, and any accounts retained with justification. Quarterly is the right cadence for most organisations; it aligns with common compliance frameworks and matches the natural rhythm of project and contract cycles.
For the shared links side of external access, the same review cycle applies. The guide on SharePoint shared links and external permissions covers how to find and revoke anonymous links and organisation-wide links that may have been issued without visibility.
Frequently Asked Questions
How do I find all external users in SharePoint Online?
External users appear in the Microsoft 365 admin centre under Users then Guest users, in each site's sharing report (Settings, Site usage, Shared with external users), and via PnP PowerShell using Get-PnPUser on each site. ShareMaster's Security Matrix report expands every SharePoint group on a site to its members' login names, so filtering for #EXT# isolates the guests in one export.
Can external users browse SharePoint content beyond what was shared with them?
No. External users can only access content they have been explicitly granted access to through a direct permission assignment or a sharing link. If they were added as site members rather than given narrower, library-specific access, their reach may still be broader than intended, which is one reason a library-level permissions audit is more informative than a site-level count.
How do I remove an external user from SharePoint Online?
To remove a guest from a specific site: Site settings, then People and groups, locate the guest account, and delete the entry. To revoke tenant-wide access: Microsoft 365 admin centre, Users, Guest users, select the guest account, and delete it. Deleting the Entra ID B2B guest account removes their access to all SharePoint resources across your tenant.
Do SharePoint guest users count toward my Microsoft 365 licence limit?
No. Entra ID B2B guest accounts do not consume a Microsoft 365 user licence. Microsoft Entra External ID counts guests by monthly active users instead, with a free tier, and charges separately for premium add-ons such as ID Governance for guests, so the standard case is that guest accounts cost nothing.