Teams distinguishes a guest invited into an organization from an external person who joins a meeting or federated chat. Someone can also join anonymously where policies permit. Their display name is not reliable identity proof, and a meeting invite does not automatically grant access to every channel file or post-meeting recording. For a vendor or consultant, decide which collaboration mode is needed before inviting them, and verify the recipient through a known business channel.
Before you start
Get the person's expected work email and organization from an existing contract or known contact, not a fresh chat message. Define whether they only need a meeting, a one-to-one conversation or persistent team files. Ask an administrator for the organization's guest and external-access policy if the option is blocked.Do it step by step
- Confirm the email address by a separate trusted route. Inspect the domain and name carefully; a display name can be copied. Do not send a guest invitation based solely on an unsolicited request.
- For a single meeting, invite the exact address and set the lobby and presenter roles in Meeting options. Admit the expected person only after confirming their identity through an appropriate channel.
- For ongoing team collaboration, ask the team owner or admin whether guest access is appropriate. A guest account may need to redeem an invitation and switch organizations in Teams.
- For a simple external chat, check whether your organization permits External Access. This is a different mechanism from adding someone as a guest to the team and may not grant file or channel access.
- Share only the specific file or channel needed. Review file permissions rather than inferring them from meeting attendance. Test an approved external account's access before sending sensitive data.
- At project end, remove unneeded guest membership, chats or file grants through the owner or admin. Audit recordings and links that may outlive the meeting.