How to Manage Microsoft Teams External Access
This article explains how external access in Microsoft Teams allows us to seamlessly find, call, chat, and set up meetings with people outside our organization. It simplifies cross-company collaboration without switching accounts, requiring no guest management while keeping our internal data secure and controlled.
Most businesses today need to have chat conversations with people outside their organization, like clients and vendors. Microsoft Teams uses a feature called External Access (formerly called Federation) to make this happen. As spam messages move from email inboxes into Teams chats, managing these settings has become essential. By setting up External Access properly, IT admins can easily block unknown contacts and keep company chats safe.
External Access allows users in our organization to search for, chat with, call, and set up meetings with people outside our company using Microsoft Teams or personal Microsoft accounts.
External Access vs. Guest Access:
- External Access (Federation): It is like making a phone call or sending an email across companies. We can chat and call, but the outside user cannot see our internal team channels, view company files on SharePoint, or access internal apps.
- Guest Access: It is like giving someone a temporary badge to enter our physical office. A guest is added directly to our tenant. They get access to team channels, shared documents, group chats, and integrated apps.
When we open the Microsoft Teams Admin Center and navigate to External collaboration settings → External access, we will find several toggles and policy control. It’s illustrated below what each options mean:
Manage external domains for this organization:
- On: Enables external communication rules and lets us configure specific domain policies.
- Off: Instantly shuts down all external communication capabilities across our entire tenant.
Allow or block external domains:
This dropdown determines which external corporate domains our employees are allowed to talk to. It offers four distinct modes:
- Allow all external domains (Default): Our organization is completely open. Our users can look up and chat with anyone from any company that uses Teams provided that company hasn't blocked us.
- Allow only specific external domains: This sets up a strict "Allowlist" (or whitelist). Users can only communicate with domains we explicitly enter into the system (e.g., trusted partners or key vendors). Communication with every other domain in the world is blocked.
- Block only specific external domains: This sets up a "Blocklist" (or blacklist). Communication is allowed with everyone globally, except for the specific competitor or high-risk domains we explicitly ban.
- Block all external domains: This locks down external communications entirely, prohibiting any domain-to-domain interaction regardless of the master toggle state.
People in my org can chat and have meetings with external users who have unmanaged Microsoft accounts
An "unmanaged account" refers to a personal Microsoft account—like someone using a personal Outlook.com, Hotmail, or personal Teams account rather than a work/school account assigned by a company.
- Turning this On allows our staff to message and meet with individual clients, who use personal Microsoft accounts.
- Turning this Off restricts our users to communicating exclusively with corporate/work Microsoft accounts.
People in my organization can communicate with accounts in trial Teams tenant
When a company sets up a brand-new Microsoft 365 environment or uses temporary trial licenses, their tenant is flagged as a trial tenant.
- Turning this On lets our employees talk to users operating inside these trial tenants.
- Turning this Off prevents communication with trial accounts, which can help protect our company from phishing scams or spam accounts created using free trial setups.
Block specific users from communicating with people in my organization
While domain blocking applies to an entire company (e.g., blocking abc.com), this feature lets us block individual external email addresses or account IDs without having to block their whole company domain.
It is useful if we need to restrict contact with specific ex-employees, spammers, or compromised accounts while keeping communication open with the rest of that external company.
People in my organization can communicate with users who are using custom applications built with Azure Communication Services
Some businesses build custom mobile or web applications using Azure Communication Services (ACS)—for example, a healthcare app that lets patients video-call their doctor, or a customer support platform on a retail site.
- Turning this On allows your internal Teams users to join calls or exchange chats directly with external users who are connecting through these custom-built apps.
Allow my security team to manage blocked domains and blocked users
Normally, managing external domain rules requires Teams Administrator privileges.
- Turning this On integrates Teams security controls with Defender for Office 365. This gives our Security Operations team permission to quickly add suspicious domains or phishing accounts to our blocklists directly through the Microsoft Defender portal, without needing full admin access to the Teams Admin Center.
