Microsoft is retiring SharePoint one-time passcode authentication between October 1 and October 31, 2026. Links sent to your external collaborators before the switch will stop working unless an Entra guest account exists. What to inventory and fix before the deadline.
A dated deadline: October 1, 2026
On July 17, 2026, Microsoft updated Microsoft 365 Message Center post MC1243549 with a firm schedule. Phase 1, which routes all new external sharing through Entra B2B, is fully rolled out in production. Phase 2, the retirement of SharePoint Online one-time passcode (SPO OTP) authentication, begins on October 1, 2026 and is expected to complete by October 31. GCC, GCCH and DoD environments are excluded for now.
In practice: starting in October, an external collaborator who opens a “specific people” link received before the switch will get an access denied message unless an Entra B2B guest account matching their address exists in your directory. No warning, no explanatory message. And it is not optional: the change applies to all tenants, and the option to disable it goes away.
SharePoint external sharing and Entra B2B: what changes, what doesn't
One-time passcode is not being dropped as an authentication method, Entra B2B uses it as the default for guests. What changes is the identity provider: external authentication moves from SharePoint to Entra, so that a single provider covers every Microsoft 365 application.
- What changes: invitations go through the Entra B2B Invitation Manager; the EnableAzureADB2BIntegration setting no longer controls external sharing behaviour as of May 2026; external authentication is logged in Entra audit logs rather than SPO OTP logs.
- What doesn't change: “Anyone” (anonymous) links are unaffected, and links already shared don't need to be reshared if a guest account already exists.
The risk isn't technical, it's relational
The whole risk sits with one population: external users who reached your files through one-time passcode without a guest account ever being created for them. The moment someone on your team has shared a document with a client, a supplier, an auditor or a consultant, you are in scope. For a municipality exchanging files with engineering firms, a professional practice sending documents to clients, or a manufacturer issuing quotes, the volume of historical links often runs into the hundreds. Nobody keeps an inventory of them, because until now nobody needed to.
The costly scenario: in early October, a client opens the link to the contract you sent in June. Access denied. They don't know why, you don't know why, and nobody connects it to a Microsoft notice they never read. Multiply that by your number of active external users and you get a month of help desk calls.
The fix itself is simple: an admin creates the guest account, or any authorized internal user reshares a single file, folder or site. That one action creates the account and instantly restores access to everything shared previously. The problem isn't the fix, it's discovering it under pressure, one file at a time.
The side effect few organizations have anticipated
After the retirement, all external users authenticate through Entra B2B and become fully subject to Conditional Access, Identity Protection and your guest governance policies.
If one of your policies requires a compliant device or strong authentication for “all users”, your guests now fall under it too, and you may unintentionally block external users who were working fine the week before. Conversely, if you rely on email one-time passcode on the Entra side, confirm it is not disabled in Entra External ID settings, otherwise your guests have no way to authenticate at all. This review belongs before October 1, not after the first ticket.
Five moves before October 1
- Inventory. The site-level external sharing report lists guests who arrived through one-time passcode and don't yet have an Entra B2B account. The “User E-mail” column gives you your work list.
- Create the guest accounts in advance for those addresses. No duplicate is created if the account already exists.
- Review Conditional Access and external sharing policies in the SharePoint and Entra admin centers, looking specifically at the effect on guests.
- Assign the Guest Inviter role to the people who share externally, so the reshare fix doesn't require the IT team.
- Brief your users. A one-paragraph internal note saves you most of the calls: “if an external contact says an old link no longer works, reshare a file with them and everything comes back”.
The upside, on the compliance side
Until now, an external user's access through SharePoint one-time passcode lived outside your identity management: no lifecycle, no access review, separate traceability. From October onward, every external access relies on a governed guest identity, and authentication events as well as guest lifecycle actions are logged in Entra. For an organization subject to Quebec's Law 25, that means a single source of truth to answer “who outside the organization accessed what, and when”. The trade-off: if your audit evidence points to SPO OTP logs today, it needs to be updated.
Conclusion
Between October 1 and October 31, 2026, older external sharing links without a matching guest account will stop working. Two moves are enough between now and then: inventory the external users without a guest account and create them in advance, then confirm your Conditional Access policies don't lock out your guests. Done in August, it's half a day to a few days depending on the size of your site estate. Done in October, it's crisis management with your clients on the phone. To run the inventory and frame the review with us, talk to an io4 expert.
Want to talk it through?
Let's spend 30 minutes on your situation.
A free assessment with an io4 architect. No commitment, no pressure.
Book my assessment
