Guests in Microsoft Loop (for tenants with Sensitivity Labels)

Organizations without Sensitivity Labels should have been able to invite guests to Loop Workspaces since March 2024. For organizations with Sensitivity Labels, inviting guests has not been possible until now.
Sensitivity Labels do not need to be actively used in the tenant; a single test label configuration in Microsoft Purview is sufficient, and Loop Workspaces does not allow invitations to guests.

After several delays, Microsoft enabled support for tenants with Sensitivity Labels in January and completed it in my tenant over the last two weeks. Note the requirements according to the documentation.

For guests in Loop, you should be aware of the following points:

  • The support for guests refers to content in the Loop Workspace at loop.cloud.microsoft and Loop components stored in other locations (like in OneDrive or SharePoint sites).
  • For Loop Workspaces, the guest account must already be available in the tenant. You cannot invite new guests. If the guest account does not yet exist in Entra ID, an administrator must invite the account.
  • Members of a workspace invite guests using their email addresses to the workspace. As a reminder, every licensed member is currently entitled to invite new members.
Invite guests to a workspace
Invite guests to a workspace
  • You should check whether internal users can share individual Loop components with guests. As Microsoft mentions in the documentation, the activation of Business-to-Business Invitation Manager is required for the sharing. You find a good description of B2B Invitation Manager at AdminDroid.
    In my tenant, sharing Loop components with guests was enabled during the last two weeks, although the B2B Invitation Manager has been active for a long time.
Loop components could not be shared with guests (now it works)
Loop components could not be shared with guests (now it works)
  • This meant that all Loop components in the workspace with a location outside the workspace could not be viewed by guests unless they were shared with them.

Permissions in Loop Workspaces, Loop components and the different storage locations can lead to frustration and dissatisfaction. It makes no difference for internal or external users.

With an example, I simulated the situation in a Loop Page with three components.

  • The first component was created in the workspace. A guest can collaborate if the external account is a member of the workspace. If only the Loop Page is shared with a guest, it does not work with the first component.
  • The second component was created in a Teams chat, which stores the component in OneDrive. A guest has no access to the component unless it has been explicitly shared with the guest.
  • The third component was created in a Teams channel, which stores it in the SharePoint site collection of the team. The component can be shared with the guest, or the guest account can be added as a team member.
Loop components for guests
Loop components for guests

I recommend reading the information about the Loop storage locations.

Loop Storage (February 2025)
Loop Storage (February 2025)
Share
Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with around ten years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Reply

Your email address will not be published. Required fields are marked *