Starting July 2026, Microsoft will require every external user accessing shared files in SharePoint Online and OneDrive to have a Microsoft Entra B2B guest account. Collaborators who relied on SharePoint’s native one-time passcode (OTP) system but never got a guest identity will suddenly see access denied. For IT administrators, the clock has already started ticking — this change is mandatory, automatic, and cannot be delayed.

The Change: SharePoint’s Own OTP Is Out, Entra B2B Is In

For years, SharePoint Online handled external authentication on its own. When someone without a Microsoft 365 account tried to open a shared link, SharePoint prompted them for a one-time passcode sent via email. That experience is being retired — not OTP itself, but the separate authentication pipeline that SharePoint ran in parallel to the rest of Microsoft 365.

From July 2026 onward, all external sharing authentication will flow through Microsoft Entra B2B, the company’s guest management platform. Entra B2B also supports email one-time passcodes, so the end-user experience can remain similar. The critical difference is that the external recipient must exist as a guest object in your organization’s Entra directory before the OTP flow can work.

Microsoft confirmed the rollout on its official FAQ page for the integration. Tenants are being selected automatically by Microsoft’s rollout systems. There is no opt-out and no way to pick an activation date. The only window of control is a manual enablement option available until the end of April 2026 — after that, the change comes for everyone.

What It Means for You

For IT Administrators

This is an identity-reconciliation project that cannot be punted. If an external recipient has been accessing shared documents via the old SharePoint OTP and does not have a corresponding Entra B2B guest account, that person will hit a wall in July 2026. The impact is not theoretical: law firms sharing case files with clients, manufacturers exchanging specs with suppliers, consultants collaborating on project sites — any workflow that depends on seamless external access could break.

The good news is that previously shared links do not need to be recreated. When the recipient has a valid guest account, the existing links continue working. The bad news is that identifying which external users are active, which ones have guest accounts, and which ones are missing is entirely the administrator’s responsibility.

For End Users and Business Owners

If you regularly send SharePoint or OneDrive links to people outside your organization, you need to know that come July 2026, some recipients may get an “access denied” message. This won’t affect everyone: anyone who already has a guest account in your company’s Entra directory — perhaps because they were formally invited to a Team, a group, or a site — will be fine. It’s the less formal, ad-hoc sharing with a one-time passcode that’s at risk.

Business owners should work with IT to identify their most important external collaborators. A salesperson who shares proposals with a prospect whose email never got registered as a guest could lose that deal. The earlier you flag these critical relationships, the smoother the transition.

How We Got Here

Microsoft has spent years consolidating identity management across its cloud services. When Entra ID (formerly Azure Active Directory) became the backbone for all Microsoft 365 workloads, SharePoint’s homegrown OTP system became an outlier. The company wants one centralized identity provider, and Entra B2B is that platform for guest users.

The timeline isn’t abrupt, but the communication has been quiet. Microsoft first signalled this direction in 2023 when it began nudging tenants toward Entra B2B for external sharing. The current FAQ page, published in early 2025, sets the hard deadline. Many admins likely haven’t noticed because the change was buried in SharePoint documentation rather than surfaced through the Message Center.

What to Do Now: A Phased Approach

A haphazard response — inviting thousands of dormant external email addresses or reissuing every shared link — creates more problems than it solves. A focused, four-step plan will protect vital collaboration without turning your directory into a mess.

Step 1: Take an Inventory of External Collaborators

Start with the external sharing report in the SharePoint admin center. Navigate to Reports and export the sharing report to CSV. The “User E-mail” column gives you the raw list of external addresses that have received shared content. This is not a to-do list of accounts to create. It’s a lead sheet for the real work of deciding who still matters.

Correlate these addresses with business context. Which ones belong to active customers, partners, legal counsel, or project teams? Which ones were one-off shares to a vendor whose contract ended? Focus on the active relationships first.

Step 2: Figure Out Who Already Has a Guest Account

In the Entra admin center, under Identity > Users > All users, search for each high-priority email address. When you find a match, verify it’s a genuine guest account — user type “Guest” — and not a stale object. Be precise: rely on the exact email address, not display names. An alias like [email protected] might map to a guest signing in as [email protected]; confirm with the content owner which address is current.

This matching step often reveals that many recipients are already covered. Document each confirmed guest so you know you can test later.

Step 3: Proactively Invite Missing Priority Guests

For collaborators without a guest account who you have confirmed need continued access, use the Entra B2B invitation workflow. Go to the same All users area, select New user > Invite external user, and enter the email and display name. The invitation should be sent by someone with permission under your external collaboration policy.

Creating the guest does not grant access to any files — it only establishes the identity. You still need to ensure the person has the correct sharing permissions on the specific SharePoint site or OneDrive item.

Step 4: Test with the Actual End User

This is the most neglected step. Have the external recipient accept the invitation, then open the exact resource they depend on — not a test file, but the real site, folder, or document. Confirm they can perform the expected actions: view, edit, upload. If access fails, record the error message, whether the invitation was redeemed, and any conditional access or cross-tenant policies that may block sign-in.

A successful test means the recipient could access the content with the right permissions. That’s the only signal that the transition worked.

What Not to Do

Don’t reissue every shared link. Microsoft says existing links continue to work when the recipient has a guest account. Blasting out new links en masse creates confusion and duplicates permissions. Also, don’t treat every address from the sharing report as a required guest. Dormant recipients who later need access can be handled on demand through targeted resharing after an access denial.

Outlook: A Unified External Identity World

After July 2026, all external sharing in Microsoft 365 will rely on Entra B2B. This simplifies identity management in the long run — one place to control guest settings, conditional access, and cross-tenant policies. Administrators can expect Microsoft to extend this pattern to other workloads that still have legacy external authentication methods.

In the short term, the key is to move now on the external collaborators your business can’t afford to lose. The change won’t be reversed, and the deadline is not negotiable. The IT teams that start auditing today will be the ones whose users notice nothing come July.