{"id":5106,"date":"2019-04-12T15:42:09","date_gmt":"2019-04-12T20:42:09","guid":{"rendered":"http:\/\/lisa.rushworth.us\/?p=5106"},"modified":"2019-04-12T15:42:09","modified_gmt":"2019-04-12T20:42:09","slug":"spo-guest-access-stops-working","status":"publish","type":"post","link":"https:\/\/www.rushworth.us\/lisa\/?p=5106","title":{"rendered":"SPO Guest Access Stops Working"},"content":{"rendered":"<p>I ran across an interesting issue today &#8212; Windstream&#8217;s got a really awesome SPO site for SD Project Management \u2013 tracking orders, equipment orders, 3<sup>rd<\/sup> party cabling installations, etc. The cool part about the site being hosted in SharePoint <em>Online<\/em> is that a <em>customer<\/em> can get set up as a federated partner and be granted access to see equipment readiness and installation scheduling within our system.<\/p>\n<p>Guest access is an interesting concept \u2013 while I have an account in our tenant that is linked to my Active Directory account in our domain, you can also create links to accounts in <em>other<\/em> company\u2019s directories. The guest account can then be set up to access our Azure resources \u2013 added to Azure groups, added to SharePoint Online groups, <a href=\"http:\/\/lisa.rushworth.us\/?p=5086\" target=\"_blank\" rel=\"noopener noreferrer\">invited to join Teams<\/a>.<\/p>\n<p>A guest user had her computer replaced and could no longer access the site \u2013 SPO insisted that she was not a valid user. Looking in Azure AD, the account existed; the audit log even showed successful authentication events. I\u2019m not sure if the computer replacement was a coincidence, the new computer had a different configuration, or if your browser stashes some information that allowed her to avoid authentication failures, but her guest account in our tenant was no longer working.<\/p>\n<p>For companies that don&#8217;t have Azure AD, when an individual accepts guest account access &#8230; the guest account link in our tenant lists &#8220;Microsoft Account&#8221; as the source.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1234\" height=\"138\" class=\"wp-image-5107\" src=\"http:\/\/lisa.rushworth.us\/wp-content\/uploads\/2019\/04\/word-image-32.png\" srcset=\"https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2019\/04\/word-image-32.png 1234w, https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2019\/04\/word-image-32-300x34.png 300w, https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2019\/04\/word-image-32-768x86.png 768w, https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2019\/04\/word-image-32-1024x115.png 1024w\" sizes=\"auto, (max-width: 1234px) 100vw, 1234px\" \/><\/p>\n<p>But when the company sets up Azure, the auth framework seems to get confused by the Azure AD account. Easy enough solution \u2013 we\u2019ve got to delete the guest account that&#8217;s linked to their MS Account from Azure AD. Bonus step specific to SPO, a site administrator needs to use &lt;site&gt;\/_layouts\/15\/people.aspx?MembershipGroupId=0 to delete the guest account from the SPO site.<\/p>\n<p>&nbsp;<\/p>\n<p>Once the \u201cMicrosoft Account\u201d guest account has been removed, the guest can be re-invited. They&#8217;ll step through the registration process again <em>but <\/em>the guest account will be linked up to their Azure AD account.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1266\" height=\"165\" class=\"wp-image-5108\" src=\"http:\/\/lisa.rushworth.us\/wp-content\/uploads\/2019\/04\/word-image-33.png\" srcset=\"https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2019\/04\/word-image-33.png 1266w, https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2019\/04\/word-image-33-300x39.png 300w, https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2019\/04\/word-image-33-768x100.png 768w, https:\/\/www.rushworth.us\/lisa\/wp-content\/uploads\/2019\/04\/word-image-33-1024x133.png 1024w\" sizes=\"auto, (max-width: 1266px) 100vw, 1266px\" \/> \u00a0Re-add the new guest account to whatever they were using &amp; their access will be restored.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I ran across an interesting issue today &#8212; Windstream&#8217;s got a really awesome SPO site for SD Project Management \u2013 tracking orders, equipment orders, 3rd party cabling installations, etc. The cool part about the site being hosted in SharePoint Online is that a customer can get set up as a federated partner and be granted &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[677,30],"tags":[663,415,747,748],"class_list":["post-5106","post","type-post","status-publish","format-standard","hentry","category-office-365","category-system-administration","tag-azure-ad","tag-sharepoint","tag-sharepoint-online","tag-spo"],"_links":{"self":[{"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/posts\/5106","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5106"}],"version-history":[{"count":1,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/posts\/5106\/revisions"}],"predecessor-version":[{"id":5109,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=\/wp\/v2\/posts\/5106\/revisions\/5109"}],"wp:attachment":[{"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5106"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5106"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rushworth.us\/lisa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5106"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}