No Guest? No Problem: Direct External Assignments in Microsoft Entra
Microsoft has introduced a significant enhancement to Entra
ID Governance: Direct Admin Assignment for External Users Using Only an
Email Address. This feature streamlines how organizations onboard external
collaborators into governed access packages, removing long‑standing friction in
B2B onboarding workflows.
A Shift in How External Access Is Granted
Historically, assigning external users to access packages
required one of two steps:
- The
external user had to already exist as a Guest in the tenant, or
- The
external user had to request access through a connected
organization or self‑service flow.
This created operational overhead for administrators who
needed to onboard partners, contractors, or one‑off external identities
quickly.
The new capability changes that model entirely.
What the New Feature Enables
Administrators can now:
- Enter
an external user’s email address directly during access package
assignment.
- Entra
automatically:
This means external identities no longer need to pre-exist
in the directory before being governed.
Why This Matters
This feature addresses several real-world challenges:
- Faster
partner onboarding Admins can assign access immediately without
waiting for external users to initiate a request.
- Reduced
manual B2B invitation steps No more pre-inviting users or coordinating
with partner IT teams.
- Governance-first
access External users are governed from the moment they enter the
tenant- no gaps, no exceptions.
- Support
for organizations without Entra tenants Email-based onboarding works
even when the external user authenticates through social or federated
identity providers.
How It Works in Practice
- Admin
selects an access package.
- Admin
chooses Direct Assignment.
- Admin
enters the external user’s email address.
- Entra
creates the Guest user, sends the invitation, and assigns the access
package with the governance policies built-in.
The user receives the invitation and signs in using their
home identity provider. Once authenticated, they immediately receive the
resources defined in the access package.
Security and Governance Implications
This feature aligns with Microsoft’s broader strategy of
tightening external access governance:
- Lifecycle
automation ensures external users don’t linger in the tenant after
their access expires.
- Access
reviews provide periodic validation of external access.
- Conditional
Access ensures external identities meet MFA, device compliance, or
risk-based requirements.
- Verified
ID can be layered to require external users to present verifiable
credentials before access is granted.
The result is a more secure, more controlled external access
experience without sacrificing speed.
Use Cases
- Vendor
onboarding for short-term projects
- Partner
access to shared applications or Teams channels
- Contractor
access to internal portals
- Cross-tenant
collaboration where self-service is not desirable
- Government
and public-sector workflows requiring strict governance
Limitations and Considerations
- Direct
assignment still requires the access package to be configured for external
users.
- Organizations
should ensure their B2B invitation policies allow email-based
onboarding.
- Governance
policies should be reviewed to ensure they apply correctly to newly
created external identities.
How to Use It
1. Open Entitlement Management
Microsoft Entra admin center -> Identity Governance
-> Entitlement Management
2. Select the Access Package
Go to Access packages -> choose the package you
want to assign.
3. Start a Direct Assignment
Access package -> Assignments -> Add
assignments
4. Choose “For users not in your directory”
This is the new capability. You’ll see a field to enter email
addresses of external users.
5. Enter the external user’s email
Example: partner.user@externalcompany.com
Entra will:
- Validate
the email format
- Queue
the B2B invitation
- Create
the Guest user object
- Apply
the access package assignment
6. Configure governance (optional but recommended)
Ensure your access package has:
- Expiration
policies
- Access
reviews
- Lifecycle
workflows
- Conditional
Access for external identities
These will automatically apply to the newly created guest.
7. External user receives the invitation
They authenticate using their home identity provider
(Microsoft, Google, SAML, etc.) and immediately receive governed access.
Conclusion
Direct admin assignment using only an email address is a
deceptively simple feature with major operational impact. It removes friction,
accelerates collaboration, and ensures external users are governed from the
moment they enter the tenant. For organizations with complex partner ecosystems
or strict compliance requirements this is one of the most meaningful Entra
Governance improvements in 2026.
Until next week admins!

Comments