Previous
<p>Updated June 17, 2026: Phase 1, which enables Entra B2B for new external sharing, is now fully rolled out for Production environments. To ensure a smooth transition, Phase 2, the retirement of SharePoint Online OTP, has been rescheduled to begin on October 1 and is expected to complete by October 31 for Production environments.</p><p><br></p><p>Both Phase 1 and Phase 2 roll outs exclude GCC, GCCH & DoD. New dates for these environments will be communicated via Message center when we are ready to proceed. Thank you for your patience.</p><p><strong>[Introduction]</strong></p><p>We are<strong> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</strong> in <em>OneDrive</em> and <em>SharePoint</em> starting <strong>October 2026</strong>. Beginning in <strong>May 2026</strong>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p><p><strong>[When this will happen]</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>May & June 2026: </strong>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>October 2026: </strong>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>Retirement is expected to complete by October 31, 2026.</strong></li></ol><p><strong>[How this affects your organization]</strong></p><p><em>Who is affected</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All Microsoft 365 tenants (commercial, government, sovereign).</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ol><p><em>What will happen</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The <em>EnableAzureADB2BIntegration </em>setting will no longer control external sharing behavior beginning May 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>SPO OTP authentication will retire beginning October 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The option to disable Entra B2B integration will be removed.</li></ol><p><em>Impact on external users</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users who already have an Entra B2B guest account in your directory:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>No change in behavior.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users without a B2B guest account:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">shared </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">after changes rolled out to your tenant: A guest account will be automatically created via the Entra B2B Invitation Manager and authentication will use Entra B2B. The email one-time passcode feature is now turned on by default for all new tenants and for any existing tenants where you haven’t explicitly turned it off. Please refer to this article to </span><a href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fentra%2Fexternal-id%2Fone-time-passcode&data=05%7C02%7Cv-honoggle%40microsoft.com%7C9da8d02d31eb4e1b23ab08dee446b63c%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639199189543428490%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=dJn0RquzFkRF7PHL98iaVNIIon5Mc7277nr0pB%2BAzS4%3D&reserved=0" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">learn more.</a></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links shared </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">before </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">changes rolled out to your tenant: SPO OTP authentication continues until October 2026. After October 2026, these users will receive </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">access denied</strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);"> until a matching B2B guest account exists.</span></li></ol><p><strong>Restoring access after retirement</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Admins can manually create a guest account for the external user at any time. Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li></ol><p><strong>[What you need to do to prepare]</strong></p><p>To ensure a smooth transition:</p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Ensure that Microsoft Entra is configured to allow guest invitations for the appropriate users. For example, assign the <strong>Guest Inviter</strong> role to users who need external sharing or are responsible for creating guest accounts.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Inform users that, beginning in October 2026, some external collaborators may see an access denied message when opening older links that were previously authenticated with SharePoint Online OTP. This can occur if a matching B2B guest account was not created for the email address used with the original sharing link.</li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>To restore access, users can share or reshare at least one file with the external collaborator. This creates the required B2B guest account, after which the collaborator can continue accessing previously shared links.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>If your organization relies on email OTP authentication via Entra, ensure it is <strong>not disabled</strong> in <em>Entra External ID settings</em>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">Email OTP for B2B guests</a>.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">create guest accounts</a> to retain access.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Update internal documentation.</li></ol><p><strong>Learn more:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" rel="noopener noreferrer" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive & SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" rel="noopener noreferrer" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" rel="noopener noreferrer" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" rel="noopener noreferrer" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/external-collaboration-settings-configure" rel="noopener noreferrer" target="_blank">Configure external collaboration - Microsoft Entra External ID | Microsoft Learn</a></li></ol><p><strong>[Compliance considerations]</strong></p><table><tbody><tr><td data-row="row-mrpg2tc1-51"><strong>Compliance Question</strong></td><td data-row="row-mrpg2tc1-51"><strong>Answer</strong></td></tr><tr><td data-row="row-mrpg2tc1-52"><strong>Does the change alter how existing customer data is accessed, processed, or stored?</strong></td><td data-row="row-mrpg2tc1-52"><strong>Yes. </strong>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td data-row="row-mrpg2tc1-53"><strong>Does the change modify Conditional Access policies or enforcement?</strong></td><td data-row="row-mrpg2tc1-53"><strong>Yes. </strong>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td data-row="row-mrpg2tc1-54"><strong>Does the change provide a new way of communicating between users, tenants, or subscriptions?</strong></td><td data-row="row-mrpg2tc1-54"><strong>Yes. </strong>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td data-row="row-mrpg2tc1-55"><strong>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</strong></td><td data-row="row-mrpg2tc1-55"><strong>Yes. </strong>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
New
<p>Updated July 17, 2026: Phase 1, which enables Entra B2B for new external sharing, is now fully rolled out for Production environments. To ensure a smooth transition, Phase 2, the retirement of SharePoint Online OTP, has been rescheduled to begin on October 1 and is expected to complete by October 31 for Production environments.</p><p><br></p><p>Both Phase 1 and Phase 2 roll outs exclude GCC, GCCH & DoD. New dates for these environments will be communicated via Message center when we are ready to proceed. Thank you for your patience.</p><p><strong>[Introduction]</strong></p><p>We are<strong> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</strong> in <em>OneDrive</em> and <em>SharePoint</em> starting <strong>October 2026</strong>. Beginning in <strong>May 2026</strong>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p><p><strong>[When this will happen]</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>May & June 2026: </strong>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>October 2026: </strong>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>Retirement is expected to complete by October 31, 2026.</strong></li></ol><p><strong>[How this affects your organization]</strong></p><p><em>Who is affected</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All Microsoft 365 tenants (commercial, government, sovereign).</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ol><p><em>What will happen</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The <em>EnableAzureADB2BIntegration </em>setting will no longer control external sharing behavior beginning May 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>SPO OTP authentication will retire beginning October 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The option to disable Entra B2B integration will be removed.</li></ol><p><em>Impact on external users</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users who already have an Entra B2B guest account in your directory:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>No change in behavior.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users without a B2B guest account:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">shared </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">after changes rolled out to your tenant: A guest account will be automatically created via the Entra B2B Invitation Manager and authentication will use Entra B2B. The email one-time passcode feature is now turned on by default for all new tenants and for any existing tenants where you haven’t explicitly turned it off. Please refer to this article to </span><a href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fentra%2Fexternal-id%2Fone-time-passcode&data=05%7C02%7Cv-honoggle%40microsoft.com%7C9da8d02d31eb4e1b23ab08dee446b63c%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639199189543428490%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=dJn0RquzFkRF7PHL98iaVNIIon5Mc7277nr0pB%2BAzS4%3D&reserved=0" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">learn more.</a></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links shared </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">before </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">changes rolled out to your tenant: SPO OTP authentication continues until October 2026. After October 2026, these users will receive </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">access denied</strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);"> until a matching B2B guest account exists.</span></li></ol><p><strong>Restoring access after retirement</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Admins can manually create a guest account for the external user at any time. Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li></ol><p><strong>[What you need to do to prepare]</strong></p><p>To ensure a smooth transition:</p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Ensure that Microsoft Entra is configured to allow guest invitations for the appropriate users. For example, assign the <strong>Guest Inviter</strong> role to users who need external sharing or are responsible for creating guest accounts.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Inform users that, beginning in October 2026, some external collaborators may see an access denied message when opening older links that were previously authenticated with SharePoint Online OTP. This can occur if a matching B2B guest account was not created for the email address used with the original sharing link.</li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>To restore access, users can share or reshare at least one file with the external collaborator. This creates the required B2B guest account, after which the collaborator can continue accessing previously shared links.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>If your organization relies on email OTP authentication via Entra, ensure it is <strong>not disabled</strong> in <em>Entra External ID settings</em>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">Email OTP for B2B guests</a>.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">create guest accounts</a> to retain access.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Update internal documentation.</li></ol><p><strong>Learn more:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" rel="noopener noreferrer" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive & SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" rel="noopener noreferrer" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" rel="noopener noreferrer" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" rel="noopener noreferrer" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/external-collaboration-settings-configure" rel="noopener noreferrer" target="_blank">Configure external collaboration - Microsoft Entra External ID | Microsoft Learn</a></li></ol><p><strong>[Compliance considerations]</strong></p><table><tbody><tr><td data-row="row-mrpg2tc1-51"><strong>Compliance Question</strong></td><td data-row="row-mrpg2tc1-51"><strong>Answer</strong></td></tr><tr><td data-row="row-mrpg2tc1-52"><strong>Does the change alter how existing customer data is accessed, processed, or stored?</strong></td><td data-row="row-mrpg2tc1-52"><strong>Yes. </strong>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td data-row="row-mrpg2tc1-53"><strong>Does the change modify Conditional Access policies or enforcement?</strong></td><td data-row="row-mrpg2tc1-53"><strong>Yes. </strong>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td data-row="row-mrpg2tc1-54"><strong>Does the change provide a new way of communicating between users, tenants, or subscriptions?</strong></td><td data-row="row-mrpg2tc1-54"><strong>Yes. </strong>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td data-row="row-mrpg2tc1-55"><strong>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</strong></td><td data-row="row-mrpg2tc1-55"><strong>Yes. </strong>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>