Every tenant collects Guests that External User Manager never created. Some appear when somebody shares a file or folder with an address outside the company, and Microsoft creates the account automatically. Others were added by hand, or joined before you installed EUM. None of them go through your Onboarding Procedures or fall under your Governance Policies.
Unmanaged Guests gives you a complete list of these accounts, the tools to bring them under External User Manager or remove them in bulk, and an optional clean-up that removes inactive ones on its own.
Unmanaged Guests are visible to administrators only, and only administrators can import or remove them.
Let's go through the list, the actions you can take on it, and the settings behind it.
👥 Finding Unmanaged Guests
Navigate to the Users tab and switch the Guests card to the Unmanaged Guests tab. The tab next to it, Managed Guests & Requests, holds everyone with a Request in External User Manager.
Each row gives you what you need to decide what should happen to a Guest:
Filesharing-Guest? - whether Microsoft created the account because somebody shared a file or folder. It reads Unknown for guests created more than seven days before External User Manager started tracking them, since the directory audit only reaches back seven days. Tracking starts when you install External User Manager, or on 29 September 2026 if you installed it before then.
Related teams/groups - the teams and groups the guest is a member of, if any.
Sponsor - the person recorded in Microsoft Entra ID as responsible for the guest. For a filesharing guest, that's usually the person who shared a file with them for the first time.
Last sign-in - the guest's most recent sign-in, or Never signed in when the sign-in log confirms there has been none. It can take up to three days for a new sign-in to show up here.
Automatic removal - where the guest stands if automatic removal is on: how many days are left, whether a warning has gone out, or why the guest is exempt.
You can narrow the list with the Filter panel, by Created, Filesharing, Sponsor, Import, and Type, or search for a Guest by typing at least three characters.
The details behind each Guest are collected once a day, and Microsoft can take up to 48 hours to index new accounts and their activity. That's what the Data may not be up to date label next to the tabs refers to.
✅ Importing Guests via the Unmanaged Bot
Importing a Guest creates a Request from your Unmanaged Bot for the account that already exists on your tenant. What happens next depends on your Import settings: with Auto approve on, the Request is approved straight away, and with it off, it waits for an Approver. Skip Onboarding decides whether approved Guests go through your Onboarding Procedures.
Select the Guests you'd like to import. Selecting the checkbox in the header picks every Guest in the list, or every Guest matching your filter, not just the ones on the current page.
Click Start import in the bar above the list.
Review the dialog. It tells you how many Guests will be imported and how many cannot be imported, and why.
Check the settings listed under Import runs with. Click Change in Settings if you'd like to adjust them first.
Click Import via unmanaged bot.
Once the import is under way, a summary shows how many Requests were created, and which Guests couldn't be imported, with the reason for each. You can Export result for your records.
Imported Guests leave the list as soon as their Request exists, and from that moment automatic removal no longer applies to them. You can follow their Requests under Approvals. If a Request is denied, the Guest returns to the list, unless Auto remove user is on under Settings > Approval, in which case the account is deleted.
Only one import can run on your tenant at a time, and a single import can include up to 500 guests.
When a Guest cannot be imported, the dialog names the setting that changes that:
In no team or group - turn on Allow requesters to create Non-Team specific invitations. This requires an Enterprise licence.
Only in Entra security groups - turn on Enable EUM for Entra Security Groups. This requires an Enterprise licence.
Only in Microsoft 365 groups - turn on Enable EUM for M365 Groups that aren't Teams.
Only in blocked teams - the guest's teams are excluded from External User Manager, so they can't be imported.
No mail address - a request needs an address, so these accounts can't be imported.
All three switches are under Settings > Expert mode > Request.
📝 Creating a Request Instead
Importing isn't the only way to bring a Guest under External User Manager. The ⋯ menu at the end of each row offers Import via unmanaged bot and Remove from tenant for that single Guest, and a third option that works differently: Create new request.
Create new request opens the regular request form for that Guest, with you as the requester. The Request goes through your normal approval and onboarding process, and the Import settings don't apply to it. It works for every Guest, including ones that can't be imported.
🗑️ Removing Guests
Some of these accounts shouldn't be on your tenant at all. Remove from tenant deletes the selected Guest accounts from Microsoft Entra ID, and every file access and team or group membership ends with them.
Select the Guests you'd like to remove.
Click Remove from tenant in the bar above the list.
Check the dialog. If any of the selected Guests belong to a team or group, it tells you how many, since a Guest in a team might still be in use.
Tick I understand these accounts are deleted permanently., then confirm the removal.
External User Manager can't undo a removal. Microsoft Entra ID keeps deleted accounts under Deleted users for 30 days, where an administrator can restore them. A single removal can include up to 500 Guests. Suspended accounts are skipped, and so are accounts without a mail address or sign-in name.
⚙️ Configuring Unmanaged Externals
Navigate to Settings, switch to Expert mode, and open Unmanaged externals under Automation.
Import settings:
Bot Name - the name of the bot that sends the import requests. It defaults to Unmanaged Bot.
Auto approve - approves imported requests automatically. With it off, each request waits for an Approver.
Skip Onboarding - lets approved guests skip the onboarding process. It's only available while the onboarding process is active.
Automatic import:
Import automatically - searches for unmanaged guests at a fixed interval and imports every guest it finds via the Unmanaged Bot, so you don't have to start the import yourself.
Check interval - the number of days between two automatic runs, from 1 to 999. It defaults to 30.
💎 Import automatically is accessible exclusively to enterprise customers. If you'd like to request an upgrade, feel free to contact your sales manager or send us an email at [email protected]
At the bottom of the page, Import history lists every import run, whether it was started by hand or automatically.
⏳ Automatic Removal after Inactivity
Filesharing Guests pile up quietly, and most are never used again. Automatic removal after inactivity removes unmanaged Guests who haven't signed in for a set number of days, and can warn the right people first.
Setting Breakdown:
Enable automatic removal - turns the feature on. Since doing nothing means a guest is removed, you're asked to confirm when you switch it on.
Scope - Filesharing guests only (recommended) removes only guests confirmed as filesharing guests. All unmanaged guests also includes accounts an administrator created by hand.
Inactivity period - the number of days without a sign-in before a guest is removed, from 14 days upwards. It defaults to 180, and every sign-in starts the full period again.
Include guests with a team or group membership - off by default, since a guest in a team is usually a guest in use.
Send a pre-warning - sends a warning card in Microsoft Teams before a guest is removed. With it off, guests are removed without warning.
Warning lead time - how many days before the removal the card goes out. It defaults to 14, and it must be shorter than the inactivity period.
Recipients of the pre-warning - who receives the card: the guest's Sponsor, your Approvers, your Administrators, or any combination of them.
Backup Group for Sponsor - who receives the card instead when a guest has no sponsor to warn: Admins only or Admins + Approvers.
The sentence at the bottom of the section shows what your settings mean in practice, for example when a Guest who signs in today would be removed. When you switch the feature on or widen it, a confirmation explains the effect before anything is saved. Today counts as day 0, so no Guest is removed sooner than the inactivity period you've set.
Automatic removal runs once a day, and it works independently of the Auto remove user setting. It never removes a Guest who has a Request, a Guest whose sign-in data couldn't be determined, a suspended account, or an account without a mail address. If sign-in data can't be read for any Guest on your tenant, a notice appears above the list and nothing is removed until it can.
🤖 The Removal Warning Card
When the pre-warning is on, each recipient gets a card from the External User Manager bot in Microsoft Teams, as soon as a guest's removal is within the warning lead time.
The card shows the Guest, whether they're a filesharing Guest, their last sign-in, the earliest removal date, and their sponsor. Recipients can act on it right away:
Allow another X days - gives the guest a new, full inactivity period, counted from the moment somebody clicks it.
Request as a full guest - opens the request form, already filled in for this guest. Nothing is created until the form is submitted. Once the request exists, the guest leaves the list and automatic removal no longer applies.
The card updates itself as things change, for example when the Guest signs in, a Request is created, or the account is removed, so recipients always see where things stand.
👣 Next Steps
Now that you know how to handle Guests who came in outside External User Manager, take a look at how their Requests are approved.
We recommend starting here:
⛑️ Need more help?
Get further assistance with External User Manager through our support chat widget within the app, or reach out to us at [email protected]









