September 7, 2026
Nobody Offboards a Guest
When somebody resigns, a chain of events begins. HR files it, a ticket opens, accounts get disabled, the laptop comes back.

By Technijian
4 min read
When an outside collaborator stops working with you, nothing happens at all.
There is no last day, no exit interview, no HR record. The referring specialist simply stops replying. The billing consultant's engagement winds down. The project with the external counsel finishes and everyone moves on. And in Microsoft 365, every one of them is still a guest in the Teams channel where the work happened, still able to open the SharePoint folder it lived in.
For a medical practice this is a more specific problem than it sounds, because of who those guests tend to be and what the channels tend to contain.
The access was granted by someone who does not manage access
The structural issue is that guest invitations rarely come from IT.A practice manager adds a specialist to a Teams channel so a case can be discussed properly. A billing lead shares a folder with the outside coding company. Someone in operations invites the EHR vendor's implementation consultant. Every one of those decisions was reasonable, made by a competent person solving a real problem quickly.
But the person who granted the access does not own the access. They own the task. When the task ends, their relationship with the permission ends too โ in their mind, though not in the tenant.
That is why guest access accumulates in a way employee access does not. Internal accounts are created by a process and removed by a process. Guest accounts are created by whoever needed collaboration that afternoon, and removed by nobody in particular.
Why healthcare makes this sharper
Two things raise the stakes for a practice specifically.The first is what the collaboration channels contain. A Teams conversation about a patient case is not a project thread. It accumulates clinical detail, attachments, and images over months, and a guest added for one consultation in March can typically read all of it โ including the parts added long after their involvement ended.
The second is that many of these guests are business associates in the formal sense: billing companies, transcription services, external specialists, IT and EHR vendors. The relationship is governed by agreements that say something about access, and those agreements usually contemplate access ending when the engagement does. A guest account that outlives the contract is a gap between what was signed and what is technically true โ and that gap is exactly the sort of thing an assessment surfaces, usually at an inconvenient moment.
None of that requires a breach to become a problem. It only requires someone to ask for the current list.
Producing the list is the hard part
Most practices cannot answer "who has guest access, and why" without a project.The information exists, but it is scattered across the places access was granted rather than collected anywhere central. Guests appear in Teams membership, in SharePoint site permissions, in individual sharing links, and in the directory itself โ and those views do not agree with each other. Someone removed from a Team may still hold a working link to a file.
A first pass does not need to be sophisticated. Pull every guest identity in the tenant and record, for each one: which organization they belong to, who invited them, what they can currently reach, and when they last signed in.
Last sign-in is the column that does most of the work. Guests who have not authenticated in ninety days are, in the overwhelming majority of cases, people whose involvement ended and nobody noticed. That single field usually turns an intimidating list into a short one worth actually discussing.
Ask the person who invited them, not a manager
The review itself should route differently from an internal access review.There is no manager to attest to an external person, and asking IT to decide is asking the wrong party โ IT can see the permission but not whether the clinical or business relationship is still live. The only person who reliably knows is whoever requested the access in the first place.
So the question goes to them, and it is narrow: is this collaboration still active, and does it still need the access it has? One line back, either way. Where the answer is no, removal is straightforward. Where nobody can be found who owns the relationship at all, that is itself the finding โ and the safe default is removal, because an access nobody will vouch for is not one anyone is monitoring either.
Handled as part of ordinary security operations, this is a short recurring exercise. Handled as a project every few years, it is an archaeology dig.
Close the loop that created it
Reviewing is remediation. It does not stop the next accumulation, and the accumulation is the actual problem.
Three changes prevent most of it, and none require new tooling:Expiry by default. Guest access granted for a project should carry an end date at the moment it is granted. Most collaborations have a knowable horizon, and a date that arrives too early is a two-minute renewal โ far cheaper than an account nobody reviews for three years.
- A record of why. When a guest is invited, capture the sponsor and the reason. Without it, next year's review has no one to ask, which is what makes these lists so slow to work through.
- Sharing rules that match the sensitivity. Anonymous links and organization-wide sharing defaults deserve a deliberate decision in a practice environment rather than whatever the tenant shipped with.
These are small operating habits rather than a control framework. They belong with whoever runs the tenant day to day โ internal IT or an outside managed IT partner โ and they matter most in clinical environments, where the collaboration is genuinely necessary and the content is genuinely sensitive.
The point of the exerciseThe goal is not to make external collaboration harder. Practices work with specialists, billing partners, and vendors because that is how care and operations actually run, and locking it down would cost more than it saved.
The goal is that the list of people outside your organization who can read patient information is a list somebody has looked at recently, and can explain.
Right now, in most practices, that list is longer than anyone would guess โ not because of a decision, but because leaving was never an event.
Technijian works with Orange County and Southern California healthcare practices on Microsoft 365, security, compliance support, and managed IT. Talk to the team here.
Listen to the related Technijian podcast episode: