Microsoft 365Detection & ResponseRetrospectives

Detecting Teams Guest Access Risk: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.

Guest accounts and broad Teams access can quietly expose sensitive data. These detections highlight risky guest activity and sharing.

Signals worth watching

  • Guests added to Teams or groups that contain sensitive data or carry Confidential labels.
  • Guests from personal email domains (gmail.com, outlook.com) added to internal Teams.
  • Guests downloading large numbers of files.
  • Guest accounts that haven't signed in for months but still have access.
  • Anonymous "Anyone" links created for files in sensitive sites.

Where the data lives

  • Entra ID audit logs: guest invitations and group membership changes.
  • Microsoft 365 audit log (OfficeActivity / CloudAppEvents): Teams membership, file access, sharing link creation.
  • Defender for Cloud Apps: policies for guest activity and mass downloads.

A starting query

Guests added to Teams:

OfficeActivity
| where Operation == "MemberAdded"
| mv-expand Member = Members
| extend UPN = tostring(Member.UPN)
| where UPN has "#EXT#"
| project TimeGenerated, UserId, TeamName, UPN

Correlate team names with your list of sensitive Teams or with sensitivity labels.

Response

  1. Confirm the business need with the Team owner.
  2. Remove guests who don't need access.
  3. Review files accessed by the guest.
  4. Apply sensitivity labels to restrict guest access for sensitive Teams going forward.
detect teams guest access riskCOVID remote work & Teams sprawl2020

More on this story