Microsoft 365How-To & HardeningRetrospectives

How to Govern Teams Creation, Guest Access and Expiration Policies

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.

Teams sprawl and forgotten guest access create real security risk. Here is how to put lightweight governance in place without slowing collaboration.

Step 1: Decide who can create Teams

Options range from everyone (default) to a specific group. Many organizations keep creation open but add guard rails below. If you restrict creation, provide a fast request process.

Step 2: Apply a naming policy

Use a Microsoft 365 group naming policy with prefixes or suffixes (for example, department or "EXT-" for external collaboration) and blocked words.

Step 3: Require ownership

Every Team should have at least two owners. Use SharePoint Advanced Management's site ownership policy or reports to find ownerless Teams and assign owners.

Step 4: Set expiration

Configure a Microsoft 365 group expiration policy (for example, 365 days). Active groups renew automatically; inactive ones prompt owners to renew or let them expire.

Step 5: Govern guest access

  • Restrict guest invitations to specific roles or approved domains if appropriate.
  • Use access reviews for guests in Teams (Entra ID Governance), quarterly.
  • Set guest expiration through entitlement management or cross-tenant access settings where appropriate.

Step 6: Apply sensitivity labels to Teams

Use container sensitivity labels to set privacy (private/public), guest access and sharing rules when a Team is created.

Step 7: Clean up the backlog

Archive or delete inactive Teams after confirming with owners. Remove guests who haven't signed in for 90 days.

Verify

Track: number of ownerless Teams, inactive Teams, guests without review. All three should decline quarter over quarter.

teams governance policiesCOVID remote work & Teams sprawl2020

More on this story