For orgs that allow Guests, the tenant-wide configurations that are required to secure controlled data are numerous and include creation of attribute based dynamic groups to enforce authentication strengths and other CAPs, as well as Teams, SPO/OneDrive, and Exchange hardening.