When an external guest tries to open a file shared in Microsoft Teams, they may see an Access Denied error even though the file appears in the chat or channel. This usually happens because the file’s sharing permissions do not include the guest’s email domain, or because the guest is signed in with a personal Microsoft account instead of the work account. The Microsoft 365 admin or the file owner must adjust sharing settings at the tenant, site, or file level. This article explains the root causes and gives step-by-step fixes for each scenario.
Key Takeaways: Fixing Access Denied for External Guests in Teams
- SharePoint admin center > Sharing > External sharing: Set the default sharing link type to Anyone or Specific people to allow guest access.
- Teams admin center > Users > External access: Ensure external collaboration is not blocked at the tenant level.
- File link sharing dialog: Change the link type to People with existing access or Specific people and add the guest email.
Why Teams Files Show Access Denied for External Guests
The Access Denied error appears when the guest does not have the necessary permissions to view or edit the file. Even if the guest can see the file in Teams, the underlying SharePoint or OneDrive file permissions may not include the guest’s account. The most common causes are:
- The SharePoint site or OneDrive sharing settings are set to Only people in your organization.
- The default sharing link type is set to People with existing access, and the guest has not been explicitly added.
- The guest is signed in with a personal Microsoft account instead of the work account that was invited.
- The file owner has restricted sharing to specific people and forgot to add the guest.
- The tenant’s external sharing policy blocks sharing with guests from certain domains.
Each of these issues requires a different fix. The steps below cover the most common scenarios, starting with the simplest and moving to the most complex.
Steps to Fix Access Denied for an External Guest in Teams
Method 1: Change the File Sharing Link Permissions
- Open the file in Teams
In the Teams chat or channel, click the file to open it. The file will open in the Teams file viewer. - Click Share
At the top right of the file viewer, click the Share button. This opens the sharing dialog. - Select the link type
In the sharing dialog, click the current link type (for example, People with existing access). From the dropdown, choose Specific people or People with existing access. - Add the guest email
In the address field, type the guest’s full email address. If the guest is not listed, click Enter. The guest will receive an email with a link to the file. - Set permissions
Choose Can edit or Can view based on the level of access you want to grant. Click Send to finalize the sharing invitation.
If the guest still sees Access Denied after this step, proceed to Method 2.
Method 2: Verify the Guest Account Type
- Ask the guest to check the sign-in account
The guest must sign in with the email address that received the Teams invitation. If they are using a personal Microsoft account or a different work account, they will see Access Denied. - Sign out of all accounts
In the guest’s browser, click the profile icon in the top right and sign out. Then sign in using the invited email address. - Clear browser cache and cookies
After signing out, clear the browser cache and cookies, then restart the browser and try the file again.
Method 3: Adjust SharePoint Site Sharing Settings
- Open the SharePoint site
In Teams, click the Files tab, then click Open in SharePoint at the top of the file list. The site opens in a new browser tab. - Access site permissions
Click the gear icon in the top right, then select Site permissions. - Change external sharing settings
Click Sharing settings. Under External sharing, select Anyone with the link or New and existing guests. If you choose Anyone, the link will work for anyone who has it, but this is less secure. - Save the changes
Click Save, then ask the guest to try the file again.
Method 4: Check Tenant-Level External Sharing Policies
- Go to the SharePoint admin center
Sign in to admin.microsoft.com with an administrator account. In the admin center, select Show all, then SharePoint. - Open the Sharing settings
In the SharePoint admin center, select Policies, then Sharing. Under External sharing, ensure the slider is set to Anyone or New and existing guests. - Check domain restrictions
Scroll to the bottom and click More external sharing settings. If there are domain restrictions, remove the domain that blocks the guest’s email domain. - Save and wait
Click Save. Policy changes can take up to 24 hours to fully propagate, but usually apply within a few minutes.
If Teams Still Shows Access Denied After the Main Fix
Guest Sees Access Denied in the Teams Mobile App
The mobile app may cache old permissions. Ask the guest to close the app completely, then reopen it and sign in again. If the issue persists, the guest should open the file in a browser by clicking the file name and selecting Open in SharePoint.
Guest Receives a Sign-in Prompt That Loops
This often happens when the guest’s identity is not recognized. The guest should use a private or incognito window, sign in with the invited account, and then open the file link. If the loop continues, the admin must verify that the guest user exists in Azure AD under External Identities.
File Owner Cannot Share Because of a Policy
If the file owner sees a message that sharing is disabled, the tenant policy may block external sharing for that site. The admin must adjust the site’s sharing settings as described in Method 3, or grant the owner the ability to share externally.
Teams File Access Denied: Guest vs Internal User Comparison
| Item | External Guest | Internal User |
|---|---|---|
| Sharing permission needed | Explicit link or guest added to site | Automatic if user is a site member |
| Sign-in account | Must use the invited work or school email | Uses the organization account |
| Tenant policy impact | External sharing settings can block access | Internal policies rarely block file access |
| Link type default | Often set to People with existing access | Often set to Organization-wide |
Now you can fix Access Denied errors for external guests by adjusting sharing links, verifying the guest’s sign-in account, and updating SharePoint site or tenant policies. Start with the file-level sharing dialog, then move to site and tenant settings if needed. For recurring issues, review your tenant’s external sharing defaults and consider setting the default link type to Specific people to balance security and convenience.