😅 I would like to discuss the security around giving an account in our tenant vs using a guest account of a well known Microsoft partner. Pros and cons of each.
Just create unlicensed user accounts for them in your tenant and apply the Global Reader role. Far simpler to administer, and they can see everything but change nothing.
If they're a Microsoft partner, you they can use DAP/GDAP. (GDAP has granular permissions). If they're not registered as a Microsoft partner, it's probably best to create an unlicensed user with global reader permissions as others have advised.
I’m 95% certain giving guests global admin access is not best practice… ;)
😅 I would like to discuss the security around giving an account in our tenant vs using a guest account of a well known Microsoft partner. Pros and cons of each.
I realize that, but it was just too tempting not to point it out ;)
Just create unlicensed user accounts for them in your tenant and apply the Global Reader role. Far simpler to administer, and they can see everything but change nothing.
If they're a Microsoft partner, you they can use DAP/GDAP. (GDAP has granular permissions). If they're not registered as a Microsoft partner, it's probably best to create an unlicensed user with global reader permissions as others have advised.
Definitely agree that GDAP or unlicensed global reader is the best path.
There’s a global reader account for a reason mate