When you start a new chat in Teams, you may expect to see the encryption option in the message box. That option is missing for a guest conversation. The encryption feature is available only for internal users in your organization. Guests cannot use end-to-end encryption because their identity is not fully managed by your tenant. This article explains why the option disappears and how to verify or adjust the conditions that control it.
You will learn the exact policy settings and account types that make encryption visible or hidden. You will also see what to do when a guest still cannot see the option after your checks. The steps work for both the Teams desktop app and Teams on the web.
Key Takeaways: Restore Encryption Visibility in Guest Chats
- Teams admin center > Messaging policies > End-to-end encryption: Controls whether encryption is available for any user in your tenant.
- Teams admin center > Users > External access: Determines whether guests from other tenants can be added to encrypted chats.
- Teams admin center > Guest access settings: Enables or disables guest chat capabilities, including the encryption option.
Why Teams Hides Encryption for Guest Conversations
End-to-end encryption in Teams is designed for one-to-one chats between users who belong to the same organization. The encryption key is tied to the user identity that Microsoft 365 manages for your tenant. A guest account is hosted in a different tenant. That tenant does not share the same key management infrastructure with your organization. As a result, Teams does not show the encryption toggle in a chat that includes a guest.
The encryption option is also controlled by a messaging policy. The policy setting named End-to-end encryption must be set to Enabled for the user who starts the chat. Even if the policy is correct, the presence of a guest in the conversation automatically disables the feature. Teams does not allow encryption when any participant is from outside your tenant.
Guest Identity and Encryption Keys
When you add a guest, Teams creates a guest account in your Azure Active Directory. However, the guest’s actual credentials remain in their home tenant. The encryption service cannot issue a key that both tenants trust. Microsoft designed this restriction to prevent cross-tenant key access. Therefore, the encryption option disappears as soon as the guest is part of the chat.
Steps to Diagnose and Fix the Missing Encryption Option
Follow these steps in order. Each step checks a different condition that can hide the encryption option.
- Confirm the chat is one-to-one and not a group chat
Open the chat that shows no encryption option. Click the chat title at the top of the conversation. Check that only two participants are listed. If the chat contains more than two people, encryption is not available. Start a new chat with only the guest to test again. - Check the messaging policy for the user who starts the chat
Open the Teams admin center. Go to Messaging policies. Select the policy assigned to the user who initiates the chat. Scroll to the section named End-to-end encryption. Set it to Enabled. Save the policy and wait up to 24 hours for it to apply. - Verify the guest is actually an external user
In the Teams admin center, go to Users. Search for the guest account. Check the User type column. If it shows Guest, the account is external. If it shows Member, the account is internal and encryption should appear. If the user type is wrong, contact your identity administrator to correct it. - Ensure guest access is enabled in your tenant
In the Teams admin center, go to Org-wide settings > Guest access. Confirm the toggle for Allow guest access in Microsoft Teams is set to On. Also confirm that the option for Guests can make outgoing calls is set to On if you want calls to work. Save any changes. - Check the external access settings for your domain
In the Teams admin center, go to External access. Look for the list of allowed domains. Verify that the guest’s domain is not blocked. If the domain is blocked, remove it from the blocked list. Save the change. - Restart Teams and sign in again
Close Teams completely. Right-click the Teams icon in the system tray and choose Quit. Open Teams again and sign in. Then start a new chat with the guest. The encryption option will still be missing because guests cannot use encryption, but this step clears any stale policy cache.
If Teams Still Hides Encryption After All Checks
If you have completed every step and the option is still missing, the cause is the guest account type itself. No policy change can enable encryption for a conversation that contains a guest. The only way to get encryption is to remove the guest from the chat and use a different communication method.
Teams Shows Encryption for an Internal User but Not for a Guest
This is expected behavior. Encryption is available only for users who are members of your own tenant. Guests are members of another tenant. Teams intentionally disables the encryption toggle when a guest is present. To verify this, start a new chat with an internal colleague. The encryption option should appear. If it does, your policy settings are correct.
Teams Shows the Encryption Option but the Send Button Is Grayed Out
This happens when the chat contains more than two participants or when the recipient is a guest. The encryption toggle may appear, but Teams prevents sending an encrypted message. Check the participant list. Remove any extra members. If the recipient is a guest, the message cannot be encrypted. Use a regular message instead.
Encryption Option Disappears After a Guest Accepts the Invitation
Before the guest accepts the invitation, the chat may appear as a one-to-one internal chat. After acceptance, Teams recognizes the user as external and hides encryption. This is a normal change. You cannot prevent it. The only workaround is to use a different app that supports cross-tenant encryption, such as a secure file-sharing service.
Teams Encryption Options: Guest vs Internal User
| Item | Internal User | Guest User |
|---|---|---|
| Encryption option visible | Yes, when policy allows | No |
| Encryption key management | Managed by your tenant | Managed by home tenant |
| Supported chat types | One-to-one and group | One-to-one only |
| Policy control | End-to-end encryption policy | Guest access settings |
| Workaround for secure communication | Use encryption directly | Use a separate secure channel |
The table shows the core difference. Guests cannot use Teams encryption at all. Your policy checks confirm that your tenant is configured correctly, but the guest limitation remains.
Now you know that the missing encryption option is a built-in restriction for guest conversations. You can verify your messaging policy, guest access settings, and external access rules. For truly secure communication with a guest, use a third-party encryption tool that supports cross-tenant identities. Remember that Teams encryption works only between internal users in the same tenant.