MICROSOFT 365ILLUSTRATIVE
SCOUTz product evidence supporting Guest Accounts Now Outnumber Employees Two to One
How many SaaS accounts are guest accounts?

Kaseya's 2026 SaaS Security Report found that 69 percent of 6.26 million monitored SaaS accounts were guests, more than two guests for every licensed user.

ACCOUNT COMPOSITION

Guest identities are the larger side of the tenant.

Kaseya 2026 SaaS Security Report · 6.26M monitored accounts · calendar 2025
SCOUTz raccoon mascot peering at an evidence panel

Short answer: In Kaseya's 2026 SaaS Security Report, 69 percent of the 6.26 million SaaS accounts monitored across more than 50,000 small businesses were guest accounts rather than licensed employees, and the guest count grew by more than 1.9 million in a year. Guests are created for a contractor, a supplier or a shared project and rarely removed. Each one that outlives its purpose is a sign-in path into company data that nobody is watching.

How a tenant ends up with more outsiders than staff

Nobody sets out to build a guest list. A project manager shares a folder with an outside designer. Sales invites a customer into a chat channel. The accountant gets access for tax season. Each invitation creates an account in the tenant, and the tenant does not forget when the project ends.

Kaseya counted 4.3 million guest accounts against 1.96 million licensed users in its 2025 dataset. For a thirty-person company, the same ratio means sixty or seventy outside identities with some level of access, most of them created by someone other than the IT provider.

Why forgotten guests matter

A guest account is an account. If it has a weak password and no MFA, it can be guessed or sprayed like any other. Kaseya notes that many guests end up with the same permissions as internal staff, sometimes including privileged access, and that attackers now use automated tools to find active guest accounts in a tenant and test them quickly.

A contractor account that has sat untouched for a year and a half is as useful to an attacker as a freshly phished employee password, and it is less likely to be noticed because nobody expects it to be in use.

What a guest cleanup looks like

Kaseya's recommendations are the right starting list. Put guests on a lifecycle with expiration, review and removal. Alert on unusual guest growth, inactive guests and permission changes. When nobody can say whether a guest is still needed, block sign-in rather than leave it open; blocking is reversible and deletion is not. Hold external users to least privilege.

For an MSP, that becomes a clear first project. Export the guest list with last sign-in dates. Walk it with the owner, who usually recognizes about half the names. Block the stale ones, remove what nobody claims after thirty days, and set an expiration policy so the list does not rebuild itself.

The sales conversation

Guest sprawl is a strong opener because the owner can check it themselves and because the number is almost always higher than they expect. "You have twelve employees and forty-one guests, and nineteen of those guests have not signed in this year" is a sentence that does not need a slide. It is also a finding without blame: the client did not do anything wrong, they collaborated, and the tenant kept score.

Frequently asked questions

What is a guest account in Microsoft 365?

An account created in a company's tenant for someone outside the organization, such as a contractor, vendor or client, so they can access shared files, teams or apps. Guests are sometimes called external or B2B users.

How many SaaS accounts are guest accounts?

In Kaseya's 2026 SaaS Security Report, 69 percent of 6.26 million monitored accounts were guests, more than two guests for every licensed user, up over 1.9 million from the prior year.

Why are inactive guest accounts a security risk?

They are working sign-in paths that no one monitors. Kaseya reports many guests hold staff-level or privileged permissions, and attackers use automated tools to find and test dormant guest accounts.

Should inactive guest accounts be deleted or blocked?

Block sign-in first when ownership is unclear, confirm with the business owner, then remove what nobody claims. Kaseya's guidance is to block rather than leave an uncertain account open.

How often should an MSP review guest accounts?

Set an expiration policy so guests lapse automatically, and review the list with the client at least quarterly, flagging any guest with no recent sign-in.

How SCOUTz gets you there

SCOUTz is prospect intelligence for MSPs. With a prospect's read-only Microsoft 365 consent, it reads the tenant's identity configuration and puts the account picture on one page: employees versus outside identities, sign-in recency and MFA state, with no access to mail or files. The finding arrives in a branded report in your MSP's name, with a cleanup plan the owner can approve on the spot. Point it at any client and walk out with a deal. The open beta is free for thirty days at scoutzsecurity.io.