Numentis

The Hidden SaaS Security Risk: Why Guest Accounts Deserve Your Attention

Modern businesses rely on SaaS applications like Microsoft 365, Teams, SharePoint, and countless third-party cloud tools to stay productive. But according to Kaseya’s 2026 SaaS Security Report, many organizations may be overlooking one of the biggest security risks hiding in plain sight: guest accounts. The report found that 69% of monitored SaaS accounts were guest accounts, significantly outnumbering licensed users.

For small and mid-sized businesses, this should be a wake-up call.

The Growing Trust Gap in SaaS Security

As organizations collaborate with vendors, contractors, partners, and clients, guest access has become a necessity. However, every guest account represents a potential entry point into business systems.

Kaseya’s research, which analyzed more than 27.6 billion SaaS security events across over 50,000 SMB environments, found that unmanaged guest accounts, third-party integrations, and external file sharing are expanding the attack surface for businesses.

Cybercriminals have also changed their tactics. Instead of focusing solely on traditional perimeter defenses, attackers increasingly target identities, access permissions, and trusted relationships within cloud environments.

In other words, the greatest threat may not be someone breaking in—it could be someone logging in with permissions that were never properly reviewed.

Why Guest Accounts Create Risk

Guest accounts often remain active long after a project ends or a partnership concludes. Over time, organizations lose visibility into:

  • Who has access
  • What data they can view
  • Which applications they’re connected to
  • Whether their accounts are protected with MFA

The report found that 56% of accounts lacked active multi-factor authentication (MFA), while only 27% of SMBs enforced MFA organization-wide.

Without proper governance, dormant guest accounts become easy targets for attackers looking to gain access to sensitive information.

Microsoft 365: A Common Source of Exposure

For organizations using Microsoft 365, collaboration tools make external sharing fast and convenient. However, convenience can come at a cost.

Kaseya reported that 45% of Microsoft 365 shared files were sent outside the organization.

While external sharing is often necessary, businesses need visibility and control over who has access to files, folders, Teams channels, and SharePoint sites.

Without continuous monitoring, it becomes difficult to identify excessive permissions, risky sharing behaviors, or compromised accounts before they lead to a security incident.

How NUMENTIS Helps Reduce SaaS Security Risk

At NUMENTIS, we help businesses secure and manage their modern workplace environments through a combination of cybersecurity expertise, managed IT services, and Microsoft cloud solutions.

Our services help organizations:

Identity & Access Management

We help implement and manage:

  • Multi-Factor Authentication (MFA)
  • Conditional Access Policies
  • Microsoft Entra ID (formerly Azure AD)
  • Guest user governance
  • Privileged access controls

By ensuring the right people have the right access at the right time, businesses can dramatically reduce identity-related risks.

Microsoft 365 Security Assessments

Our team conducts comprehensive reviews of:

  • Microsoft 365 tenant configuration
  • SharePoint and Teams permissions
  • External sharing settings
  • Guest user access
  • Security and compliance policies

These assessments provide clear recommendations for reducing exposure and strengthening security.

Managed Cybersecurity Services

Cyber threats don’t operate on a schedule—and neither should your monitoring.

Numentis delivers ongoing security monitoring, threat detection, security posture management, and proactive remediation to help identify suspicious activity before it becomes a breach.

Managed IT Services

As a trusted Managed Service Provider (MSP), we help businesses maintain secure, compliant, and efficient IT environments while reducing the burden on internal teams.

Our proactive approach ensures that security isn’t treated as a one-time project but as an ongoing business priority.

Security Starts with Visibility

The Kaseya report highlights an important reality: businesses often have more external users accessing their SaaS environments than they realize.

To stay secure, organizations need more than passwords and firewalls. They need visibility into identities, access permissions, external sharing, and cloud activity across their entire environment.

By combining strong governance, continuous monitoring, and modern security controls, businesses can significantly reduce risk while continuing to collaborate effectively.

Ready to Assess Your SaaS Security Posture?

If you’re unsure how many guest accounts exist in your Microsoft 365 environment—or whether your security controls are keeping up with today’s threats—NUMENTIS can help.

Book a Microsoft 365 Security Assessment with NUMENTIS today. Our experts will evaluate your cloud environment, identify security gaps, and provide actionable recommendations to strengthen your security posture.

Contact NUMENTIS today to schedule a consultation and take control of your SaaS security.