Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

(Updated) Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B

Message ID
MC1243549
View in Message Center
Services
SharePoint OnlineMicrosoft OneDrive
Category
Plan for Change
Tags
Major Change User impactAdmin impactRetirement
Rollout
May 2026June 2026October 2026

Summary

SharePoint One-Time Passcode (SPO OTP) authentication retires in October 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New external sharing uses Entra B2B from May 2026. External users need guest accounts for access; admins should prepare by updating policies and managing guest accounts accordingly.

Details

Updated July 17, 2026: Phase 1, which enables Entra B2B for new external sharing, is now fully rolled out for Production environments. To ensure a smooth transition, Phase 2, the retirement of SharePoint Online OTP, has been rescheduled to begin on October 1 and is expected to complete by October 31 for Production environments.


Both Phase 1 and Phase 2 roll outs exclude GCC, GCCH & DoD. New dates for these environments will be communicated via Message center when we are ready to proceed. Thank you for your patience.

[Introduction]

We are retiring SharePoint One‑Time Passcode (SPO OTP) authentication in OneDrive and SharePoint starting October 2026. Beginning in May 2026, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.

[When this will happen]

  1. May & June 2026: Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.
  2. October 2026: Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.
  3. Retirement is expected to complete by October 31, 2026.

[How this affects your organization]

Who is affected

  1. All Microsoft 365 tenants (commercial, government, sovereign).
  2. All external users who access OneDrive or SharePoint files, folders, or sites.

What will happen

  1. The EnableAzureADB2BIntegration setting will no longer control external sharing behavior beginning May 2026.
  2. SPO OTP authentication will retire beginning October 2026.
  3. The option to disable Entra B2B integration will be removed.

Impact on external users

  1. External users who already have an Entra B2B guest account in your directory:
  2. No change in behavior.
  3. External users without a B2B guest account:
  4. Specific people links shared after changes rolled out to your tenant: A guest account will be automatically created via the Entra B2B Invitation Manager and authentication will use Entra B2B. The email one-time passcode feature is now turned on by default for all new tenants and for any existing tenants where you haven’t explicitly turned it off. Please refer to this article to learn more.
  5. Specific people links shared before changes rolled out to your tenant: SPO OTP authentication continues until October 2026. After October 2026, these users will receive access denied until a matching B2B guest account exists.

Restoring access after retirement

  1. Admins can manually create a guest account for the external user at any time. Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.

[What you need to do to prepare]

To ensure a smooth transition:

  1. Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.
  2. Ensure that Microsoft Entra is configured to allow guest invitations for the appropriate users. For example, assign the Guest Inviter role to users who need external sharing or are responsible for creating guest accounts.
  3. Inform users that, beginning in October 2026, some external collaborators may see an access denied message when opening older links that were previously authenticated with SharePoint Online OTP. This can occur if a matching B2B guest account was not created for the email address used with the original sharing link.
  4. To restore access, users can share or reshare at least one file with the external collaborator. This creates the required B2B guest account, after which the collaborator can continue accessing previously shared links.
  5. If your organization relies on email OTP authentication via Entra, ensure it is not disabled in Entra External ID settings. See Email OTP for B2B guests.
  6. Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively create guest accounts to retain access.
  7. Update internal documentation.

Learn more:

  1. Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn
  2. Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn
  3. Frequently Asked Questions: Improvements to external sharing in OneDrive & SharePoint | SharePoint in Microsoft 365 | Microsoft Learn
  4. Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn
  5. Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn
  6. SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn
  7. Configure external collaboration - Microsoft Entra External ID | Microsoft Learn

[Compliance considerations]

Compliance QuestionAnswer
Does the change alter how existing customer data is accessed, processed, or stored?Yes. This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.
Does the change modify Conditional Access policies or enforcement?Yes. After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.
Does the change provide a new way of communicating between users, tenants, or subscriptions?Yes. External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.
Does the change alter how admins monitor, report on, or demonstrate compliance activities?Yes. Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.

Change History

Show
July 18, 2026 at 2:30 AM Updated
Last Updated Date
Previous
2026-07-17T21:27:30.267Z
New
2026-07-17T22:35:30.057Z
Body Content
Previous
<p>Updated June 17, 2026: Phase 1, which enables Entra B2B for new external sharing, is now fully rolled out for Production environments. To ensure a smooth transition, Phase 2, the retirement of SharePoint Online OTP, has been rescheduled to begin on October 1 and is expected to complete by October 31 for Production environments.</p><p><br></p><p>Both Phase 1 and Phase 2 roll outs exclude GCC, GCCH &amp; DoD. New dates for these environments will be communicated via Message center when we are ready to proceed. Thank you for your patience.</p><p><strong>[Introduction]</strong></p><p>We are<strong> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</strong> in <em>OneDrive</em> and <em>SharePoint</em> starting <strong>October 2026</strong>. Beginning in <strong>May 2026</strong>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p><p><strong>[When this will happen]</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>May &amp; June 2026: </strong>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>October 2026: </strong>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>Retirement is expected to complete by October 31, 2026.</strong></li></ol><p><strong>[How this affects your organization]</strong></p><p><em>Who is affected</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All Microsoft 365 tenants (commercial, government, sovereign).</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ol><p><em>What will happen</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The <em>EnableAzureADB2BIntegration </em>setting will no longer control external sharing behavior beginning May 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>SPO OTP authentication will retire beginning October 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The option to disable Entra B2B integration will be removed.</li></ol><p><em>Impact on external users</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users who already have an Entra B2B guest account in your directory:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>No change in behavior.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users without a B2B guest account:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">shared </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">after changes rolled out to your tenant: A guest account will be automatically created via the Entra B2B Invitation Manager and authentication will use Entra B2B. The email one-time passcode feature is now turned on by default for all new tenants and for any existing tenants where you haven’t explicitly turned it off. Please refer to this article to </span><a href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fentra%2Fexternal-id%2Fone-time-passcode&amp;data=05%7C02%7Cv-honoggle%40microsoft.com%7C9da8d02d31eb4e1b23ab08dee446b63c%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639199189543428490%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=dJn0RquzFkRF7PHL98iaVNIIon5Mc7277nr0pB%2BAzS4%3D&amp;reserved=0" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">learn more.</a></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links shared </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">before </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">changes rolled out to your tenant: SPO OTP authentication continues until October 2026. After October 2026, these users will receive </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">access denied</strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);"> until a matching B2B guest account exists.</span></li></ol><p><strong>Restoring access after retirement</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Admins can manually create a guest account for the external user at any time. Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li></ol><p><strong>[What you need to do to prepare]</strong></p><p>To ensure a smooth transition:</p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Ensure that Microsoft Entra is configured to allow guest invitations for the appropriate users. For example, assign the <strong>Guest Inviter</strong> role to users who need external sharing or are responsible for creating guest accounts.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Inform users that, beginning in October 2026, some external collaborators may see an access denied message when opening older links that were previously authenticated with SharePoint Online OTP. This can occur if a matching B2B guest account was not created for the email address used with the original sharing link.</li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>To restore access, users can share or reshare at least one file with the external collaborator. This creates the required B2B guest account, after which the collaborator can continue accessing previously shared links.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>If your organization relies on email OTP authentication via Entra, ensure it is <strong>not disabled</strong> in <em>Entra External ID settings</em>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">Email OTP for B2B guests</a>.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">create guest accounts</a> to retain access.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Update internal documentation.</li></ol><p><strong>Learn more:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" rel="noopener noreferrer" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" rel="noopener noreferrer" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" rel="noopener noreferrer" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" rel="noopener noreferrer" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/external-collaboration-settings-configure" rel="noopener noreferrer" target="_blank">Configure external collaboration - Microsoft Entra External ID | Microsoft Learn</a></li></ol><p><strong>[Compliance considerations]</strong></p><table><tbody><tr><td data-row="row-mrpg2tc1-51"><strong>Compliance Question</strong></td><td data-row="row-mrpg2tc1-51"><strong>Answer</strong></td></tr><tr><td data-row="row-mrpg2tc1-52"><strong>Does the change alter how existing customer data is accessed, processed, or stored?</strong></td><td data-row="row-mrpg2tc1-52"><strong>Yes. </strong>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td data-row="row-mrpg2tc1-53"><strong>Does the change modify Conditional Access policies or enforcement?</strong></td><td data-row="row-mrpg2tc1-53"><strong>Yes. </strong>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td data-row="row-mrpg2tc1-54"><strong>Does the change provide a new way of communicating between users, tenants, or subscriptions?</strong></td><td data-row="row-mrpg2tc1-54"><strong>Yes. </strong>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td data-row="row-mrpg2tc1-55"><strong>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</strong></td><td data-row="row-mrpg2tc1-55"><strong>Yes. </strong>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
New
<p>Updated July 17, 2026: Phase 1, which enables Entra B2B for new external sharing, is now fully rolled out for Production environments. To ensure a smooth transition, Phase 2, the retirement of SharePoint Online OTP, has been rescheduled to begin on October 1 and is expected to complete by October 31 for Production environments.</p><p><br></p><p>Both Phase 1 and Phase 2 roll outs exclude GCC, GCCH &amp; DoD. New dates for these environments will be communicated via Message center when we are ready to proceed. Thank you for your patience.</p><p><strong>[Introduction]</strong></p><p>We are<strong> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</strong> in <em>OneDrive</em> and <em>SharePoint</em> starting <strong>October 2026</strong>. Beginning in <strong>May 2026</strong>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p><p><strong>[When this will happen]</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>May &amp; June 2026: </strong>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>October 2026: </strong>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>Retirement is expected to complete by October 31, 2026.</strong></li></ol><p><strong>[How this affects your organization]</strong></p><p><em>Who is affected</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All Microsoft 365 tenants (commercial, government, sovereign).</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ol><p><em>What will happen</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The <em>EnableAzureADB2BIntegration </em>setting will no longer control external sharing behavior beginning May 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>SPO OTP authentication will retire beginning October 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The option to disable Entra B2B integration will be removed.</li></ol><p><em>Impact on external users</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users who already have an Entra B2B guest account in your directory:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>No change in behavior.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users without a B2B guest account:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">shared </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">after changes rolled out to your tenant: A guest account will be automatically created via the Entra B2B Invitation Manager and authentication will use Entra B2B. The email one-time passcode feature is now turned on by default for all new tenants and for any existing tenants where you haven’t explicitly turned it off. Please refer to this article to </span><a href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fentra%2Fexternal-id%2Fone-time-passcode&amp;data=05%7C02%7Cv-honoggle%40microsoft.com%7C9da8d02d31eb4e1b23ab08dee446b63c%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639199189543428490%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=dJn0RquzFkRF7PHL98iaVNIIon5Mc7277nr0pB%2BAzS4%3D&amp;reserved=0" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">learn more.</a></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links shared </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">before </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">changes rolled out to your tenant: SPO OTP authentication continues until October 2026. After October 2026, these users will receive </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">access denied</strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);"> until a matching B2B guest account exists.</span></li></ol><p><strong>Restoring access after retirement</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Admins can manually create a guest account for the external user at any time. Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li></ol><p><strong>[What you need to do to prepare]</strong></p><p>To ensure a smooth transition:</p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Ensure that Microsoft Entra is configured to allow guest invitations for the appropriate users. For example, assign the <strong>Guest Inviter</strong> role to users who need external sharing or are responsible for creating guest accounts.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Inform users that, beginning in October 2026, some external collaborators may see an access denied message when opening older links that were previously authenticated with SharePoint Online OTP. This can occur if a matching B2B guest account was not created for the email address used with the original sharing link.</li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>To restore access, users can share or reshare at least one file with the external collaborator. This creates the required B2B guest account, after which the collaborator can continue accessing previously shared links.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>If your organization relies on email OTP authentication via Entra, ensure it is <strong>not disabled</strong> in <em>Entra External ID settings</em>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">Email OTP for B2B guests</a>.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">create guest accounts</a> to retain access.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Update internal documentation.</li></ol><p><strong>Learn more:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" rel="noopener noreferrer" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" rel="noopener noreferrer" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" rel="noopener noreferrer" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" rel="noopener noreferrer" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/external-collaboration-settings-configure" rel="noopener noreferrer" target="_blank">Configure external collaboration - Microsoft Entra External ID | Microsoft Learn</a></li></ol><p><strong>[Compliance considerations]</strong></p><table><tbody><tr><td data-row="row-mrpg2tc1-51"><strong>Compliance Question</strong></td><td data-row="row-mrpg2tc1-51"><strong>Answer</strong></td></tr><tr><td data-row="row-mrpg2tc1-52"><strong>Does the change alter how existing customer data is accessed, processed, or stored?</strong></td><td data-row="row-mrpg2tc1-52"><strong>Yes. </strong>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td data-row="row-mrpg2tc1-53"><strong>Does the change modify Conditional Access policies or enforcement?</strong></td><td data-row="row-mrpg2tc1-53"><strong>Yes. </strong>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td data-row="row-mrpg2tc1-54"><strong>Does the change provide a new way of communicating between users, tenants, or subscriptions?</strong></td><td data-row="row-mrpg2tc1-54"><strong>Yes. </strong>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td data-row="row-mrpg2tc1-55"><strong>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</strong></td><td data-row="row-mrpg2tc1-55"><strong>Yes. </strong>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
July 17, 2026 at 10:31 PM Updated
Summary
Previous
SharePoint One-Time Passcode (SPO OTP) authentication will retire by October 31, 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New sharing uses Entra B2B from May 2026. External users without guest accounts will lose access unless a guest account is created or content is reshared. Organizations must update policies and prepare for this change.
New
SharePoint One-Time Passcode (SPO OTP) authentication retires in October 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New external sharing uses Entra B2B from May 2026. External users need guest accounts for access; admins should prepare by updating policies and managing guest accounts accordingly.
Last Updated Date
Previous
2026-07-16T21:41:00.817Z
New
2026-07-17T21:27:30.267Z
Body Content
Previous
<p>Updated June 16, 2026: We have decided to pause roll out to all non-commercial clouds. We will communicate via Message center when we are ready to proceed. Thank you for your patience.&nbsp;</p><p>Phase 1, which enables Entra B2B for net new external sharing, is now fully rolled out. To ensure a smooth transition, Phase 2, the retirement of SharePoint Online OTP, has been rescheduled to begin on October 1 and is expected to complete by October 31.</p><p><b>[Introduction]</b></p><p>We are<b> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</b> in <i>OneDrive</i> and <i>SharePoint</i> starting <b>October 2026</b>. Beginning in <b>May 2026</b>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p> <p><b>[When this will happen]</b></p><ul><li><b>May &amp; June 2026: </b>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li><b>October 2026: </b>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li><b>Retirement is expected to complete by October 31, 2026.</b></li><li><b>GCCH: </b>We will communicate via Message center when we are ready to proceed.</li></ul> <p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft 365 tenants (commercial, government, sovereign).</li><li>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ul><p><i>What will happen</i></p><ul><li>The <i>EnableAzureADB2BIntegration </i>setting will no longer control external sharing behavior beginning May 2026.</li><li>SPO OTP authentication will retire beginning October 2026.</li><li>The option to disable Entra B2B integration will be removed.</li></ul><p><i>Impact on external users</i></p><ul><li><b>External users who already have an Entra B2B guest account in your directory:</b><ul><li>No change in behavior.</li></ul></li><li><b>External users without a B2B guest account:</b><ul style=""><li style="">Specific people links <b>shared </b>after changes rolled out to your tenant:<ul style=""><li style="">A guest account will be automatically created via the Entra B2B Invitation Manager.</li><li style="">Authentication will use Entra B2B (email OTP available if enabled).</li></ul></li><li style="">Specific people links shared <b>before </b>changes rolled out to your tenant:<ul style=""><li style="">SPO OTP authentication continues until October 2026.</li><li style="">After October 2026, these users will receive <b>access denied</b> until a matching B2B guest account exists.</li></ul></li></ul></li></ul><p><i>Restoring access after retirement</i></p><ul><li>Admins can manually create a guest account for the external user at any time.</li><li>Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li> </ul> <p><b>[What you need to do to prepare]</b></p> <p>To ensure a smooth transition:</p> <ul> <li>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li><li>Ensure that Microsoft Entra is configured to allow guest invitations for the appropriate users. For example, assign the <b>Guest Inviter</b> role to users who need external sharing or are responsible for creating guest accounts.</li><li>Inform users that, beginning in October 2026, some external collaborators may see an access denied message when opening older links that were previously authenticated with SharePoint Online OTP. This can occur if a matching B2B guest account was not created for the email address used with the original sharing link.<ul><li>To restore access, users can share or reshare at least one file with the external collaborator. This creates the required B2B guest account, after which the collaborator can continue accessing previously shared links.</li></ul></li><li>If your organization relies on email OTP authentication via Entra, ensure it is <b>not disabled</b> in <i>Entra External ID settings</i>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">Email OTP for B2B guests</a>.</li> <li>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">create guest accounts</a> to retain access.</li> <li>Update internal documentation.</li> </ul> <p><b>Learn more:</b> </p><ul><li><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/external-collaboration-settings-configure" target="_blank">Configure external collaboration - Microsoft Entra External ID | Microsoft Learn</a></li></ul><p><b>[Compliance considerations]</b></p><table class="table table-bordered"><tbody><tr><td><b>Compliance Question</b></td><td><b>Answer</b></td></tr><tr><td><b>Does the change alter how existing customer data is accessed, processed, or stored?</b></td><td><b>Yes. </b>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td><b>Does the change modify Conditional Access policies or enforcement?</b></td><td><b>Yes. </b>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td><b>Does the change provide a new way of communicating between users, tenants, or subscriptions?</b></td><td><b>Yes. </b>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td><b>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</b></td><td><b>Yes. </b>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
New
<p>Updated June 17, 2026: Phase 1, which enables Entra B2B for new external sharing, is now fully rolled out for Production environments. To ensure a smooth transition, Phase 2, the retirement of SharePoint Online OTP, has been rescheduled to begin on October 1 and is expected to complete by October 31 for Production environments.</p><p><br></p><p>Both Phase 1 and Phase 2 roll outs exclude GCC, GCCH &amp; DoD. New dates for these environments will be communicated via Message center when we are ready to proceed. Thank you for your patience.</p><p><strong>[Introduction]</strong></p><p>We are<strong> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</strong> in <em>OneDrive</em> and <em>SharePoint</em> starting <strong>October 2026</strong>. Beginning in <strong>May 2026</strong>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p><p><strong>[When this will happen]</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>May &amp; June 2026: </strong>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>October 2026: </strong>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>Retirement is expected to complete by October 31, 2026.</strong></li></ol><p><strong>[How this affects your organization]</strong></p><p><em>Who is affected</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All Microsoft 365 tenants (commercial, government, sovereign).</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ol><p><em>What will happen</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The <em>EnableAzureADB2BIntegration </em>setting will no longer control external sharing behavior beginning May 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>SPO OTP authentication will retire beginning October 2026.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>The option to disable Entra B2B integration will be removed.</li></ol><p><em>Impact on external users</em></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users who already have an Entra B2B guest account in your directory:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>No change in behavior.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><strong>External users without a B2B guest account:</strong></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">shared </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">after changes rolled out to your tenant: A guest account will be automatically created via the Entra B2B Invitation Manager and authentication will use Entra B2B. The email one-time passcode feature is now turned on by default for all new tenants and for any existing tenants where you haven’t explicitly turned it off. Please refer to this article to </span><a href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fentra%2Fexternal-id%2Fone-time-passcode&amp;data=05%7C02%7Cv-honoggle%40microsoft.com%7C9da8d02d31eb4e1b23ab08dee446b63c%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639199189543428490%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=dJn0RquzFkRF7PHL98iaVNIIon5Mc7277nr0pB%2BAzS4%3D&amp;reserved=0" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">learn more.</a></li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">Specific people links shared </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">before </strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">changes rolled out to your tenant: SPO OTP authentication continues until October 2026. After October 2026, these users will receive </span><strong style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);">access denied</strong><span style="background-color: rgb(255, 255, 255); color: rgb(36, 36, 36);"> until a matching B2B guest account exists.</span></li></ol><p><strong>Restoring access after retirement</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Admins can manually create a guest account for the external user at any time. Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li></ol><p><strong>[What you need to do to prepare]</strong></p><p>To ensure a smooth transition:</p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Ensure that Microsoft Entra is configured to allow guest invitations for the appropriate users. For example, assign the <strong>Guest Inviter</strong> role to users who need external sharing or are responsible for creating guest accounts.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Inform users that, beginning in October 2026, some external collaborators may see an access denied message when opening older links that were previously authenticated with SharePoint Online OTP. This can occur if a matching B2B guest account was not created for the email address used with the original sharing link.</li><li data-list="bullet" class="ql-indent-1"><span class="ql-ui" contenteditable="false"></span>To restore access, users can share or reshare at least one file with the external collaborator. This creates the required B2B guest account, after which the collaborator can continue accessing previously shared links.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>If your organization relies on email OTP authentication via Entra, ensure it is <strong>not disabled</strong> in <em>Entra External ID settings</em>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">Email OTP for B2B guests</a>.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank" style="background-color: rgb(255, 255, 255);">create guest accounts</a> to retain access.</li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span>Update internal documentation.</li></ol><p><strong>Learn more:</strong></p><ol><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" rel="noopener noreferrer" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" rel="noopener noreferrer" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" rel="noopener noreferrer" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" rel="noopener noreferrer" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" rel="noopener noreferrer" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" rel="noopener noreferrer" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li data-list="bullet"><span class="ql-ui" contenteditable="false"></span><a href="https://learn.microsoft.com/entra/external-id/external-collaboration-settings-configure" rel="noopener noreferrer" target="_blank">Configure external collaboration - Microsoft Entra External ID | Microsoft Learn</a></li></ol><p><strong>[Compliance considerations]</strong></p><table><tbody><tr><td data-row="row-mrpg2tc1-51"><strong>Compliance Question</strong></td><td data-row="row-mrpg2tc1-51"><strong>Answer</strong></td></tr><tr><td data-row="row-mrpg2tc1-52"><strong>Does the change alter how existing customer data is accessed, processed, or stored?</strong></td><td data-row="row-mrpg2tc1-52"><strong>Yes. </strong>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td data-row="row-mrpg2tc1-53"><strong>Does the change modify Conditional Access policies or enforcement?</strong></td><td data-row="row-mrpg2tc1-53"><strong>Yes. </strong>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td data-row="row-mrpg2tc1-54"><strong>Does the change provide a new way of communicating between users, tenants, or subscriptions?</strong></td><td data-row="row-mrpg2tc1-54"><strong>Yes. </strong>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td data-row="row-mrpg2tc1-55"><strong>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</strong></td><td data-row="row-mrpg2tc1-55"><strong>Yes. </strong>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
July 16, 2026 at 10:30 PM Updated
Summary
Previous
SharePoint One-Time Passcode (SPO OTP) authentication will retire starting July 2026, transitioning external sharing and authentication in OneDrive and SharePoint to Microsoft Entra B2B. New external sharing invitations begin using Entra B2B in May 2026. External users without guest accounts will lose access unless a guest account is created or content is re-shared. No admin action is required, but organizations should inform users and review sharing policies. The change affects all Microsoft 365 tenants and enhances compliance, governance, and conditional access.
New
SharePoint One-Time Passcode (SPO OTP) authentication will retire by October 31, 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New sharing uses Entra B2B from May 2026. External users without guest accounts will lose access unless a guest account is created or content is reshared. Organizations must update policies and prepare for this change.
Last Updated Date
Previous
2026-06-16T17:25:57.370Z
New
2026-07-16T21:41:00.817Z
Body Content
Previous
<p>Updated June 16, 2026: We have decided to pause GCCH release at this time. We will communicate via Message center when we are ready to proceed. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p><p>We are<b> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</b> in <i>OneDrive</i> and <i>SharePoint</i> starting <b>July 2026</b>. Beginning in <b>May 2026</b>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p> <p><b>[When this will happen]</b></p><ul><li><b>May &amp; June 2026: </b>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li><b>July 2026: </b>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li><b>Retirement is expected to complete by August 31, 2026.</b></li><li><b>GCCH: </b>We will communicate via Message center when we are ready to proceed.</li></ul> <p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft 365 tenants (commercial, government, sovereign).</li><li>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ul><p><i>What will happen</i></p><ul><li>The <i>EnableAzureADB2BIntegration </i>setting will no longer control external sharing behavior beginning May 2026.</li><li>SPO OTP authentication will retire beginning July 2026.</li><li>The option to disable Entra B2B integration will be removed.</li></ul><p><i>Impact on external users</i></p><ul><li><b>External users who already have an Entra B2B guest account in your directory:</b><ul><li>No change in behavior.</li></ul></li><li><b>External users without a B2B guest account:</b><ul style=""><li style="">Specific people links <b>shared </b>after changes rolled out to your tenant:<ul style=""><li style="">A guest account will be automatically created via the Entra B2B Invitation Manager.</li><li style="">Authentication will use Entra B2B (email OTP available if enabled).</li></ul></li><li style="">Specific people links shared <b>before </b>changes rolled out to your tenant:<ul style=""><li style="">SPO OTP authentication continues until July 2026.</li><li style="">After July 2026, these users will receive <b>access denied</b> until a matching B2B guest account exists.</li></ul></li></ul></li></ul><p><i>Restoring access after retirement</i></p><ul><li>Admins can manually create a guest account for the external user at any time.</li><li>Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li> </ul> <p><b>[What you need to do to prepare]</b></p> <p>No admin action is required. However, to ensure a smooth transition:</p> <ul> <li>Inform users that some external collaborators may see <b>access denied </b>beginning July 2026 for older links authenticated via SPO OTP.</li><li>If your organization relies on email OTP authentication via Entra, ensure it is <b>not disabled</b> in <i>Entra External ID settings</i>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">Email OTP for B2B guests</a>.</li> <li>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li> <li>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator">create guest accounts</a> to retain access.</li> <li>Update internal documentation.</li> </ul> <p><b>Learn more:</b> </p><ul><li><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li></ul><p><b>[Compliance considerations]</b></p><table class="table table-bordered"><tbody><tr><td><b>Compliance Question</b></td><td><b>Answer</b></td></tr><tr><td><b>Does the change alter how existing customer data is accessed, processed, or stored?</b></td><td><b>Yes. </b>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td><b>Does the change modify Conditional Access policies or enforcement?</b></td><td><b>Yes. </b>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td><b>Does the change provide a new way of communicating between users, tenants, or subscriptions?</b></td><td><b>Yes. </b>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td><b>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</b></td><td><b>Yes. </b>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
New
<p>Updated June 16, 2026: We have decided to pause roll out to all non-commercial clouds. We will communicate via Message center when we are ready to proceed. Thank you for your patience.&nbsp;</p><p>Phase 1, which enables Entra B2B for net new external sharing, is now fully rolled out. To ensure a smooth transition, Phase 2, the retirement of SharePoint Online OTP, has been rescheduled to begin on October 1 and is expected to complete by October 31.</p><p><b>[Introduction]</b></p><p>We are<b> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</b> in <i>OneDrive</i> and <i>SharePoint</i> starting <b>October 2026</b>. Beginning in <b>May 2026</b>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p> <p><b>[When this will happen]</b></p><ul><li><b>May &amp; June 2026: </b>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li><b>October 2026: </b>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li><b>Retirement is expected to complete by October 31, 2026.</b></li><li><b>GCCH: </b>We will communicate via Message center when we are ready to proceed.</li></ul> <p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft 365 tenants (commercial, government, sovereign).</li><li>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ul><p><i>What will happen</i></p><ul><li>The <i>EnableAzureADB2BIntegration </i>setting will no longer control external sharing behavior beginning May 2026.</li><li>SPO OTP authentication will retire beginning October 2026.</li><li>The option to disable Entra B2B integration will be removed.</li></ul><p><i>Impact on external users</i></p><ul><li><b>External users who already have an Entra B2B guest account in your directory:</b><ul><li>No change in behavior.</li></ul></li><li><b>External users without a B2B guest account:</b><ul style=""><li style="">Specific people links <b>shared </b>after changes rolled out to your tenant:<ul style=""><li style="">A guest account will be automatically created via the Entra B2B Invitation Manager.</li><li style="">Authentication will use Entra B2B (email OTP available if enabled).</li></ul></li><li style="">Specific people links shared <b>before </b>changes rolled out to your tenant:<ul style=""><li style="">SPO OTP authentication continues until October 2026.</li><li style="">After October 2026, these users will receive <b>access denied</b> until a matching B2B guest account exists.</li></ul></li></ul></li></ul><p><i>Restoring access after retirement</i></p><ul><li>Admins can manually create a guest account for the external user at any time.</li><li>Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li> </ul> <p><b>[What you need to do to prepare]</b></p> <p>To ensure a smooth transition:</p> <ul> <li>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li><li>Ensure that Microsoft Entra is configured to allow guest invitations for the appropriate users. For example, assign the <b>Guest Inviter</b> role to users who need external sharing or are responsible for creating guest accounts.</li><li>Inform users that, beginning in October 2026, some external collaborators may see an access denied message when opening older links that were previously authenticated with SharePoint Online OTP. This can occur if a matching B2B guest account was not created for the email address used with the original sharing link.<ul><li>To restore access, users can share or reshare at least one file with the external collaborator. This creates the required B2B guest account, after which the collaborator can continue accessing previously shared links.</li></ul></li><li>If your organization relies on email OTP authentication via Entra, ensure it is <b>not disabled</b> in <i>Entra External ID settings</i>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">Email OTP for B2B guests</a>.</li> <li>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">create guest accounts</a> to retain access.</li> <li>Update internal documentation.</li> </ul> <p><b>Learn more:</b> </p><ul><li><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/external-collaboration-settings-configure" target="_blank">Configure external collaboration - Microsoft Entra External ID | Microsoft Learn</a></li></ul><p><b>[Compliance considerations]</b></p><table class="table table-bordered"><tbody><tr><td><b>Compliance Question</b></td><td><b>Answer</b></td></tr><tr><td><b>Does the change alter how existing customer data is accessed, processed, or stored?</b></td><td><b>Yes. </b>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td><b>Does the change modify Conditional Access policies or enforcement?</b></td><td><b>Yes. </b>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td><b>Does the change provide a new way of communicating between users, tenants, or subscriptions?</b></td><td><b>Yes. </b>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td><b>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</b></td><td><b>Yes. </b>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
June 16, 2026 at 6:30 PM Updated
Summary
Previous
SharePoint One-Time Passcode (SPO OTP) authentication will retire by August 31, 2026, transitioning external sharing and authentication in OneDrive and SharePoint to Microsoft Entra B2B starting May 2026. External users must have Entra B2B guest accounts for access, enabling unified guest management and Conditional Access enforcement.
New
SharePoint One-Time Passcode (SPO OTP) authentication will retire starting July 2026, transitioning external sharing and authentication in OneDrive and SharePoint to Microsoft Entra B2B. New external sharing invitations begin using Entra B2B in May 2026. External users without guest accounts will lose access unless a guest account is created or content is re-shared. No admin action is required, but organizations should inform users and review sharing policies. The change affects all Microsoft 365 tenants and enhances compliance, governance, and conditional access.
Last Updated Date
Previous
2026-05-07T19:44:32.743Z
New
2026-06-16T17:25:57.370Z
Body Content
Previous
<p>Updated May 7, 2026: We have updated the content. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p><p>We are<b> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</b> in <i>OneDrive</i> and <i>SharePoint</i> starting <b>July 2026</b>. Beginning in <b>May 2026</b>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p> <p><b>[When this will happen]</b></p><ul><li><b>May &amp; June 2026: </b>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li><b>July 2026: </b>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li><b>Retirement is expected to complete by August 31, 2026.</b></li></ul> <p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft 365 tenants (commercial, government, sovereign).</li><li>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ul><p><i>What will happen</i></p><ul><li>The <i>EnableAzureADB2BIntegration </i>setting will no longer control external sharing behavior beginning May 2026.</li><li>SPO OTP authentication will retire beginning July 2026.</li><li>The option to disable Entra B2B integration will be removed.</li></ul><p><i>Impact on external users</i></p><ul><li><b>External users who already have an Entra B2B guest account in your directory:</b><ul><li>No change in behavior.</li></ul></li><li><b>External users without a B2B guest account:</b><ul style=""><li style="">Specific people links <b>shared </b>after changes rolled out to your tenant:<ul style=""><li style="">A guest account will be automatically created via the Entra B2B Invitation Manager.</li><li style="">Authentication will use Entra B2B (email OTP available if enabled).</li></ul></li><li style="">Specific people links shared <b>before </b>changes rolled out to your tenant:<ul style=""><li style="">SPO OTP authentication continues until July 2026.</li><li style="">After July 2026, these users will receive <b>access denied</b> until a matching B2B guest account exists.</li></ul></li></ul></li></ul><p><i>Restoring access after retirement</i></p><ul><li>Admins can manually create a guest account for the external user at any time.</li><li>Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li> </ul> <p><b>[What you need to do to prepare]</b></p> <p>No admin action is required. However, to ensure a smooth transition:</p> <ul> <li>Inform users that some external collaborators may see <b>access denied </b>beginning July 2026 for older links authenticated via SPO OTP.</li><li>If your organization relies on email OTP authentication via Entra, ensure it is <b>not disabled</b> in <i>Entra External ID settings</i>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">Email OTP for B2B guests</a>.</li> <li>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li> <li>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator">create guest accounts</a> to retain access.</li> <li>Update internal documentation.</li> </ul> <p><b>Learn more:</b> </p><ul><li><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li></ul><p><b>[Compliance considerations]</b></p><table class="table table-bordered"><tbody><tr><td><b>Compliance Question</b></td><td><b>Answer</b></td></tr><tr><td><b>Does the change alter how existing customer data is accessed, processed, or stored?</b></td><td><b>Yes. </b>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td><b>Does the change modify Conditional Access policies or enforcement?</b></td><td><b>Yes. </b>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td><b>Does the change provide a new way of communicating between users, tenants, or subscriptions?</b></td><td><b>Yes. </b>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td><b>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</b></td><td><b>Yes. </b>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
New
<p>Updated June 16, 2026: We have decided to pause GCCH release at this time. We will communicate via Message center when we are ready to proceed. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p><p>We are<b> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</b> in <i>OneDrive</i> and <i>SharePoint</i> starting <b>July 2026</b>. Beginning in <b>May 2026</b>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p> <p><b>[When this will happen]</b></p><ul><li><b>May &amp; June 2026: </b>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li><b>July 2026: </b>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li><b>Retirement is expected to complete by August 31, 2026.</b></li><li><b>GCCH: </b>We will communicate via Message center when we are ready to proceed.</li></ul> <p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft 365 tenants (commercial, government, sovereign).</li><li>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ul><p><i>What will happen</i></p><ul><li>The <i>EnableAzureADB2BIntegration </i>setting will no longer control external sharing behavior beginning May 2026.</li><li>SPO OTP authentication will retire beginning July 2026.</li><li>The option to disable Entra B2B integration will be removed.</li></ul><p><i>Impact on external users</i></p><ul><li><b>External users who already have an Entra B2B guest account in your directory:</b><ul><li>No change in behavior.</li></ul></li><li><b>External users without a B2B guest account:</b><ul style=""><li style="">Specific people links <b>shared </b>after changes rolled out to your tenant:<ul style=""><li style="">A guest account will be automatically created via the Entra B2B Invitation Manager.</li><li style="">Authentication will use Entra B2B (email OTP available if enabled).</li></ul></li><li style="">Specific people links shared <b>before </b>changes rolled out to your tenant:<ul style=""><li style="">SPO OTP authentication continues until July 2026.</li><li style="">After July 2026, these users will receive <b>access denied</b> until a matching B2B guest account exists.</li></ul></li></ul></li></ul><p><i>Restoring access after retirement</i></p><ul><li>Admins can manually create a guest account for the external user at any time.</li><li>Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li> </ul> <p><b>[What you need to do to prepare]</b></p> <p>No admin action is required. However, to ensure a smooth transition:</p> <ul> <li>Inform users that some external collaborators may see <b>access denied </b>beginning July 2026 for older links authenticated via SPO OTP.</li><li>If your organization relies on email OTP authentication via Entra, ensure it is <b>not disabled</b> in <i>Entra External ID settings</i>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">Email OTP for B2B guests</a>.</li> <li>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li> <li>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator">create guest accounts</a> to retain access.</li> <li>Update internal documentation.</li> </ul> <p><b>Learn more:</b> </p><ul><li><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li></ul><p><b>[Compliance considerations]</b></p><table class="table table-bordered"><tbody><tr><td><b>Compliance Question</b></td><td><b>Answer</b></td></tr><tr><td><b>Does the change alter how existing customer data is accessed, processed, or stored?</b></td><td><b>Yes. </b>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td><b>Does the change modify Conditional Access policies or enforcement?</b></td><td><b>Yes. </b>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td><b>Does the change provide a new way of communicating between users, tenants, or subscriptions?</b></td><td><b>Yes. </b>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td><b>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</b></td><td><b>Yes. </b>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
May 7, 2026 at 10:30 PM Updated
Summary
Previous
SharePoint One-Time Passcode (SPO OTP) authentication will retire by August 31, 2026, transitioning external sharing and authentication in OneDrive and SharePoint to Microsoft Entra B2B starting May 2026. External users must have Entra B2B guest accounts for access, enabling consistent governance and Conditional Access across Microsoft 365.
New
SharePoint One-Time Passcode (SPO OTP) authentication will retire by August 31, 2026, transitioning external sharing and authentication in OneDrive and SharePoint to Microsoft Entra B2B starting May 2026. External users must have Entra B2B guest accounts for access, enabling unified guest management and Conditional Access enforcement.
Last Updated Date
Previous
2026-03-04T18:27:32.183Z
New
2026-05-07T19:44:32.743Z
Body Content
Previous
<p>Updated March 4, 2026: We have updated the content. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p><p>We are<b> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</b> in <i>OneDrive</i> and <i>SharePoint</i> starting <b>July 2026</b>. Beginning in <b>May 2026</b>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p> <p><b>[When this will happen]</b></p><ul><li><b>May 2026: </b>Invitation and authentication for new external sharing begins transitioning to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li><b>July 2026: </b>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li><b>Retirement is expected to complete by August 31, 2026.</b></li></ul> <p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft 365 tenants (commercial, government, sovereign).</li><li>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ul><p><i>What will happen</i></p><ul><li>The <i>EnableAzureADB2BIntegration </i>setting will no longer control external sharing behavior beginning May 2026.</li><li>SPO OTP authentication will retire beginning July 2026.</li><li>The option to disable Entra B2B integration will be removed.</li></ul><p><i>Impact on external users</i></p><ul><li><b>External users who already have an Entra B2B guest account in your directory:</b><ul><li>No change in behavior.</li></ul></li><li><b>External users without a B2B guest account:</b><ul style=""><li style="">Specific people links <b>shared </b>after changes rolled out to your tenant:<ul style=""><li style="">A guest account will be automatically created via the Entra B2B Invitation Manager.</li><li style="">Authentication will use Entra B2B (email OTP available if enabled).</li></ul></li><li style="">Specific people links shared <b>before </b>changes rolled out to your tenant:<ul style=""><li style="">SPO OTP authentication continues until July 2026.</li><li style="">After July 2026, these users will receive <b>access denied</b> until a matching B2B guest account exists.</li></ul></li></ul></li></ul><p><i>Restoring access after retirement</i></p><ul><li>Admins can manually create a guest account for the external user at any time.</li><li>Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li> </ul> <p><b>[What you need to do to prepare]</b></p> <p>No admin action is required. However, to ensure a smooth transition:</p> <ul> <li>Inform users that some external collaborators may see <b>access denied </b>beginning July 2026 for older links authenticated via SPO OTP.</li><li>If your organization relies on email OTP authentication via Entra, ensure it is <b>not disabled</b> in <i>Entra External ID settings</i>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">Email OTP for B2B guests</a>.</li> <li>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li> <li>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator">create guest accounts</a> to retain access.</li> <li>Update internal documentation.</li> </ul> <p><b>Learn more:</b> </p><ul><li><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li></ul><p><b>[Compliance considerations]</b></p><table class="table table-bordered"><tbody><tr><td><b>Compliance Question</b></td><td><b>Answer</b></td></tr><tr><td><b>Does the change alter how existing customer data is accessed, processed, or stored?</b></td><td><b>Yes. </b>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td><b>Does the change modify Conditional Access policies or enforcement?</b></td><td><b>Yes. </b>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td><b>Does the change provide a new way of communicating between users, tenants, or subscriptions?</b></td><td><b>Yes. </b>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td><b>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</b></td><td><b>Yes. </b>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
New
<p>Updated May 7, 2026: We have updated the content. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p><p>We are<b> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</b> in <i>OneDrive</i> and <i>SharePoint</i> starting <b>July 2026</b>. Beginning in <b>May 2026</b>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p> <p><b>[When this will happen]</b></p><ul><li><b>May &amp; June 2026: </b>Invitation and authentication for new external sharing transitions to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li><b>July 2026: </b>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li><b>Retirement is expected to complete by August 31, 2026.</b></li></ul> <p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft 365 tenants (commercial, government, sovereign).</li><li>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ul><p><i>What will happen</i></p><ul><li>The <i>EnableAzureADB2BIntegration </i>setting will no longer control external sharing behavior beginning May 2026.</li><li>SPO OTP authentication will retire beginning July 2026.</li><li>The option to disable Entra B2B integration will be removed.</li></ul><p><i>Impact on external users</i></p><ul><li><b>External users who already have an Entra B2B guest account in your directory:</b><ul><li>No change in behavior.</li></ul></li><li><b>External users without a B2B guest account:</b><ul style=""><li style="">Specific people links <b>shared </b>after changes rolled out to your tenant:<ul style=""><li style="">A guest account will be automatically created via the Entra B2B Invitation Manager.</li><li style="">Authentication will use Entra B2B (email OTP available if enabled).</li></ul></li><li style="">Specific people links shared <b>before </b>changes rolled out to your tenant:<ul style=""><li style="">SPO OTP authentication continues until July 2026.</li><li style="">After July 2026, these users will receive <b>access denied</b> until a matching B2B guest account exists.</li></ul></li></ul></li></ul><p><i>Restoring access after retirement</i></p><ul><li>Admins can manually create a guest account for the external user at any time.</li><li>Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li> </ul> <p><b>[What you need to do to prepare]</b></p> <p>No admin action is required. However, to ensure a smooth transition:</p> <ul> <li>Inform users that some external collaborators may see <b>access denied </b>beginning July 2026 for older links authenticated via SPO OTP.</li><li>If your organization relies on email OTP authentication via Entra, ensure it is <b>not disabled</b> in <i>Entra External ID settings</i>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">Email OTP for B2B guests</a>.</li> <li>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li> <li>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator">create guest accounts</a> to retain access.</li> <li>Update internal documentation.</li> </ul> <p><b>Learn more:</b> </p><ul><li><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li></ul><p><b>[Compliance considerations]</b></p><table class="table table-bordered"><tbody><tr><td><b>Compliance Question</b></td><td><b>Answer</b></td></tr><tr><td><b>Does the change alter how existing customer data is accessed, processed, or stored?</b></td><td><b>Yes. </b>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td><b>Does the change modify Conditional Access policies or enforcement?</b></td><td><b>Yes. </b>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td><b>Does the change provide a new way of communicating between users, tenants, or subscriptions?</b></td><td><b>Yes. </b>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td><b>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</b></td><td><b>Yes. </b>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
March 4, 2026 at 10:31 PM Updated
Title
Previous
Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B guest accounts
New
(Updated) Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B
Summary
Previous
SharePoint One-Time Passcode (SPO OTP) authentication will retire by August 2026, transitioning external sharing and authentication in OneDrive and SharePoint to Microsoft Entra B2B guest accounts. This change enhances security, governance, and conditional access, requiring guest accounts for external user access after July 2026.
New
SharePoint One-Time Passcode (SPO OTP) authentication will retire by August 31, 2026, transitioning external sharing and authentication in OneDrive and SharePoint to Microsoft Entra B2B starting May 2026. External users must have Entra B2B guest accounts for access, enabling consistent governance and Conditional Access across Microsoft 365.
Last Updated Date
Previous
2026-03-04T01:21:58.000Z
New
2026-03-04T18:27:32.183Z
Tags
Previous
User impact,Admin impact,Retirement
New
Updated message,User impact,Admin impact,Retirement
Body Content
Previous
<p><b>[Introduction]</b></p><p>We are<b> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</b> in <i>OneDrive</i> and <i>SharePoint</i> starting <b>July 2026</b>. Beginning in <b>May 2026</b>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p> <p><b>[When this will happen]</b></p><ul><li><b>May 2026: </b>Invitation and authentication for new external sharing begins transitioning to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li><b>July 2026: </b>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li><b>Retirement is expected to complete by August 31, 2026.</b></li></ul> <p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft 365 tenants (commercial, government, sovereign).</li><li>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ul><p><i>What will happen</i></p><ul><li>The <i>EnableAzureB2BIntegration </i>setting will no longer control external sharing behavior beginning May 2026.</li><li>SPO OTP authentication will retire beginning July 2026.</li><li>The option to disable Entra B2B integration will be removed.</li></ul><p><i>Impact on external users</i></p><ul><li><b>External users who already have an Entra B2B guest account in your directory:</b><ul><li>No change in behavior.</li></ul></li><li><b>External users without a B2B guest account:</b><ul style=""><li style="">Specific people links <b>shared </b>after changes rolled out to your tenant:<ul style=""><li style="">A guest account will be automatically created via the Entra B2B Invitation Manager.</li><li style="">Authentication will use Entra B2B (email OTP available if enabled).</li></ul></li><li style="">Specific people links shared <b>before </b>changes rolled out to your tenant:<ul style=""><li style="">SPO OTP authentication continues until July 2026.</li><li style="">After July 2026, these users will receive <b>access denied</b> until a matching B2B guest account exists.</li></ul></li></ul></li></ul><p><i>Restoring access after retirement</i></p><ul><li>Admins can manually create a guest account for the external user at any time.</li><li>Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li> </ul> <p><b>[What you need to do to prepare]</b></p> <p>No admin action is required. However, to ensure a smooth transition:</p> <ul> <li>Inform users that some external collaborators may see <b>access denied </b>beginning July 2026 for older links authenticated via SPO OTP.</li><li>If your organization relies on email OTP authentication via Entra, ensure it is <b>not disabled</b> in <i>Entra External ID settings</i>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">Email OTP for B2B guests</a>.</li> <li>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li> <li>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator">create guest accounts</a> to retain access.</li> <li>Update internal documentation.</li> </ul> <p><b>Learn more:</b> </p><ul><li><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li></ul><p><b>[Compliance considerations]</b></p><table class="table table-bordered"><tbody><tr><td><b>Compliance Question</b></td><td><b>Answer</b></td></tr><tr><td><b>Does the change alter how existing customer data is accessed, processed, or stored?</b></td><td><b>Yes. </b>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td><b>Does the change modify Conditional Access policies or enforcement?</b></td><td><b>Yes. </b>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td><b>Does the change provide a new way of communicating between users, tenants, or subscriptions?</b></td><td><b>Yes. </b>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td><b>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</b></td><td><b>Yes. </b>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>
New
<p>Updated March 4, 2026: We have updated the content. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p><p>We are<b> retiring SharePoint One‑Time Passcode (SPO OTP) authentication</b> in <i>OneDrive</i> and <i>SharePoint</i> starting <b>July 2026</b>. Beginning in <b>May 2026</b>, new external sharing invitations and authentication will start using Microsoft Entra B2B instead of SPO OTP. This transition simplifies external collaboration, aligns authentication with Microsoft identity standards, and enables consistent guest lifecycle management, governance, and Conditional Access coverage across Microsoft 365.</p> <p><b>[When this will happen]</b></p><ul><li><b>May 2026: </b>Invitation and authentication for new external sharing begins transitioning to Microsoft Entra B2B. Users who previously authenticated via SPO OTP will continue to have access to specific people links even without a B2B guest account yet.</li><li><b>July 2026: </b>Retirement of SPO OTP authentication begins. External users without a guest account get access denied on previously shared specific people links. To restore access, a guest account must be created in Entra B2B, or an allowed user must share/re-share at least one file/folder/site.</li><li><b>Retirement is expected to complete by August 31, 2026.</b></li></ul> <p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>All Microsoft 365 tenants (commercial, government, sovereign).</li><li>All external users who access OneDrive or SharePoint files, folders, or sites.</li></ul><p><i>What will happen</i></p><ul><li>The <i>EnableAzureADB2BIntegration </i>setting will no longer control external sharing behavior beginning May 2026.</li><li>SPO OTP authentication will retire beginning July 2026.</li><li>The option to disable Entra B2B integration will be removed.</li></ul><p><i>Impact on external users</i></p><ul><li><b>External users who already have an Entra B2B guest account in your directory:</b><ul><li>No change in behavior.</li></ul></li><li><b>External users without a B2B guest account:</b><ul style=""><li style="">Specific people links <b>shared </b>after changes rolled out to your tenant:<ul style=""><li style="">A guest account will be automatically created via the Entra B2B Invitation Manager.</li><li style="">Authentication will use Entra B2B (email OTP available if enabled).</li></ul></li><li style="">Specific people links shared <b>before </b>changes rolled out to your tenant:<ul style=""><li style="">SPO OTP authentication continues until July 2026.</li><li style="">After July 2026, these users will receive <b>access denied</b> until a matching B2B guest account exists.</li></ul></li></ul></li></ul><p><i>Restoring access after retirement</i></p><ul><li>Admins can manually create a guest account for the external user at any time.</li><li>Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.</li> </ul> <p><b>[What you need to do to prepare]</b></p> <p>No admin action is required. However, to ensure a smooth transition:</p> <ul> <li>Inform users that some external collaborators may see <b>access denied </b>beginning July 2026 for older links authenticated via SPO OTP.</li><li>If your organization relies on email OTP authentication via Entra, ensure it is <b>not disabled</b> in <i>Entra External ID settings</i>. See <a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" style="background-color: rgb(255, 255, 255); font-family: sans-serif; font-weight: 400;">Email OTP for B2B guests</a>.</li> <li>Review external sharing policies and conditional access settings for guests in SharePoint and Entra admin centers.</li> <li>Optionally, identify external collaborators without guest accounts via external sharing reports. Proactively <a href="https://learn.microsoft.com/entra/external-id/add-users-administrator">create guest accounts</a> to retain access.</li> <li>Update internal documentation.</li> </ul> <p><b>Learn more:</b> </p><ul><li><a href="https://learn.microsoft.com/entra/external-id/add-users-administrator" target="_blank">Add and manage B2B collaboration users in the Microsoft Entra admin center | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/one-time-passcode" target="_blank">Email one-time passcode authentication for B2B guest users | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/faqs-odspintegrationwithentrab2b" target="_blank">Frequently Asked Questions: Improvements to external sharing in OneDrive &amp; SharePoint | SharePoint in Microsoft 365 | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/what-is-b2b" target="_blank">Overview: B2B collaboration with external guests for your workforce | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/entra/external-id/b2b-quickstart-add-guest-users-portal" target="_blank">Quickstart: Add a guest user and send an invitation | External ID | Microsoft Entra | Microsoft Learn</a></li><li><a href="https://learn.microsoft.com/sharepoint/sharepoint-azureb2b-integration" target="_blank">SharePoint and OneDrive integration with Microsoft Entra B2B | SharePoint in Microsoft 365 | Microsoft Learn</a></li></ul><p><b>[Compliance considerations]</b></p><table class="table table-bordered"><tbody><tr><td><b>Compliance Question</b></td><td><b>Answer</b></td></tr><tr><td><b>Does the change alter how existing customer data is accessed, processed, or stored?</b></td><td><b>Yes. </b>This change retires SPO OTP authentication and requires all external users to authenticate using Microsoft Entra B2B guest accounts, which alters the authentication method used to access existing SharePoint and OneDrive content.</td></tr><tr><td><b>Does the change modify Conditional Access policies or enforcement?</b></td><td><b>Yes. </b>After retirement, all external users will authenticate through Entra B2B and become fully subject to Microsoft Entra Conditional Access, Identity Protection, and guest governance policies.</td></tr><tr><td><b>Does the change provide a new way of communicating between users, tenants, or subscriptions?</b></td><td><b>Yes. </b>External sharing invitations will be routed through Microsoft Entra B2B Invitation Manager instead of SharePoint’s OTP invitation flow.</td></tr><tr><td><b>Does the change alter how admins monitor, report on, or demonstrate compliance activities?</b></td><td><b>Yes. </b>Authentication events and guest lifecycle actions will be logged through Entra audit logs rather than SPO OTP logs, changing where admins review authentication and guest access activity.</td></tr></tbody></table>

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.