No Guest? No Problem: Direct External Assignments in Microsoft Entra



Microsoft has introduced a significant enhancement to Entra ID Governance: Direct Admin Assignment for External Users Using Only an Email Address. This feature streamlines how organizations onboard external collaborators into governed access packages, removing long‑standing friction in B2B onboarding workflows.

A Shift in How External Access Is Granted

Historically, assigning external users to access packages required one of two steps:

  • The external user had to already exist as a Guest in the tenant, or
  • The external user had to request access through a connected organization or self‑service flow.

This created operational overhead for administrators who needed to onboard partners, contractors, or one‑off external identities quickly.

The new capability changes that model entirely.

What the New Feature Enables

Administrators can now:

  • Enter an external user’s email address directly during access package assignment.
  • Entra automatically:

This means external identities no longer need to pre-exist in the directory before being governed.

Why This Matters

This feature addresses several real-world challenges:

  • Faster partner onboarding Admins can assign access immediately without waiting for external users to initiate a request.
  • Reduced manual B2B invitation steps No more pre-inviting users or coordinating with partner IT teams.
  • Governance-first access External users are governed from the moment they enter the tenant- no gaps, no exceptions.
  • Support for organizations without Entra tenants Email-based onboarding works even when the external user authenticates through social or federated identity providers.

How It Works in Practice

  1. Admin selects an access package.
  2. Admin chooses Direct Assignment.
  3. Admin enters the external user’s email address.
  4. Entra creates the Guest user, sends the invitation, and assigns the access package with the governance policies built-in.

The user receives the invitation and signs in using their home identity provider. Once authenticated, they immediately receive the resources defined in the access package.

Security and Governance Implications

This feature aligns with Microsoft’s broader strategy of tightening external access governance:

  • Lifecycle automation ensures external users don’t linger in the tenant after their access expires.
  • Access reviews provide periodic validation of external access.
  • Conditional Access ensures external identities meet MFA, device compliance, or risk-based requirements.
  • Verified ID can be layered to require external users to present verifiable credentials before access is granted.

The result is a more secure, more controlled external access experience without sacrificing speed.

Use Cases

  • Vendor onboarding for short-term projects
  • Partner access to shared applications or Teams channels
  • Contractor access to internal portals
  • Cross-tenant collaboration where self-service is not desirable
  • Government and public-sector workflows requiring strict governance

Limitations and Considerations

  • Direct assignment still requires the access package to be configured for external users.
  • Organizations should ensure their B2B invitation policies allow email-based onboarding.
  • Governance policies should be reviewed to ensure they apply correctly to newly created external identities.

How to Use It

1. Open Entitlement Management

Microsoft Entra admin center -> Identity Governance -> Entitlement Management

2. Select the Access Package

Go to Access packages -> choose the package you want to assign.

3. Start a Direct Assignment

Access package -> Assignments -> Add assignments

4. Choose “For users not in your directory”

This is the new capability. You’ll see a field to enter email addresses of external users.

5. Enter the external user’s email

Example: partner.user@externalcompany.com

Entra will:

  • Validate the email format
  • Queue the B2B invitation
  • Create the Guest user object
  • Apply the access package assignment

6. Configure governance (optional but recommended)

Ensure your access package has:

  • Expiration policies
  • Access reviews
  • Lifecycle workflows
  • Conditional Access for external identities

These will automatically apply to the newly created guest.

7. External user receives the invitation

They authenticate using their home identity provider (Microsoft, Google, SAML, etc.) and immediately receive governed access.

Conclusion

Direct admin assignment using only an email address is a deceptively simple feature with major operational impact. It removes friction, accelerates collaboration, and ensures external users are governed from the moment they enter the tenant. For organizations with complex partner ecosystems or strict compliance requirements this is one of the most meaningful Entra Governance improvements in 2026.

Until next week admins! 

Comments

Popular posts from this blog

Using Custom Connectors and Microsoft Graph API's to Manage Licenses in Power Automate - Part One

Using Power Automate to Update Contact Information

Windows BYOD Is Awesome- Here's Why and How