Tenant member users no longer able to invite external guests to access SharePoint site resources using SharePoint Transfer Service

Kenny Carriel 0 Reputation points
2026-06-16T13:53:12.76+00:00

We understand Microsoft has or is in the process of retiring SharePoint's standalone external authentication engine (and thus the SharePoint One-Time Passcodes) and now forces all site sharing to go through Microsoft Entra B2B. We are using the Microsoft GCC High Tenant with a G5 license. This is posing several roadblocks and is forcing additional time consuming workflows just to invite and external user to access a SharePoint site resource link.

Additionally, even after configuring the Entra ID External Collaboration Settings, we have tested the user experience with an email to a non-Microsoft account user and it does not show the user the option for a one-time passcode, only the option to sign in to Microsoft. We have the Entra ID settings configured to allow for an email one-time passcode.

How do we move forward with our workflow to allow external users to collaborate by viewing/accessing SharePoint site resources without greatly increasing the administrative burden?

We committed to the Microsoft GCC High environment for our government business because of the security and centralized control of user experience while reducing the administrative burden. Eliminating the SPO OTP feature seems to be a big step back for companies that did not know they had to commit to higher amounts of administrative burdens.

Microsoft 365 and Office | SharePoint | Development
0 comments No comments

2 answers

Sort by: Most helpful
  1. Hin-V 16,405 Reputation points Microsoft External Staff Moderator
    2026-06-16T18:43:28.14+00:00

    Hi @Kenny Carriel

    Thank you for reaching out. 

    Currently, I have not found any supported way to revert to the previous lightweight OTP-based access model yet. 

    The practical path forward is to work within the Entra B2B model and ensure the experience is kept as streamlined as possible while remaining compliant. You could consider pre-provisioning guest users where appropriate and reviewing your current sharing and access settings to confirm they are not more restrictive than necessary, as this can help improve usability without impacting security. 

    As far as I know, this isn’t really a configuration issue, but more of a platform-level change. Microsoft is moving toward an identity-based access model to improve governance, auditing, and compliance, especially in environments like GCC High. Because of that, things are a bit more structured than before, so the onboarding process has more steps and the overall admin effort is higher compared to the old OTP-based approach. 

    Please note that this summary is based on my own findings and may not fully address your concerns. To help you reach your goal more effectively, I recommend engaging with [GitHub Community Forum] for a deeper technical dive or to connect with individuals who have relevant experience and expertise. Some approaches may behave differently or be restricted depending on your specific environment and configuration. These forums include many experienced developers and Microsoft specialists who can assist with troubleshooting and guidance.     

    Apologies for redirecting you to the relevant development team for further support. As a moderator, I can help clarify the scenario and point you in the right direction. However, for requests that require product-specific implementation guidance or more specialized expertise, the best next step is to continue the discussion in the appropriate forum, where subject matter experts can provide more in-depth assistance. 

    If you have any additional concerns, feel free to comment below. I would be more than happy to assist. 


    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.   

    Was this answer helpful?


  2. AI answer

    2026-06-16T13:53:50.2733333+00:00

    SharePoint Online one-time passcode (SPO OTP) as a standalone external authentication mechanism is being retired in favor of Microsoft Entra B2B for all tenants, including GCC High. External collaboration with SharePoint and OneDrive now relies on Microsoft Entra B2B as the centralized identity provider.

    Key points from the current behavior and roadmap

    1. SPO OTP is not being removed as an authentication method, but ownership of external authentication is moving from SharePoint to Microsoft Entra B2B:
      • Microsoft Entra B2B uses one-time passcode (OTP) as the default authentication method for guests who don’t have a work or school account or a Microsoft account.
      • This change applies to all tenants and cannot be opted out of.
      • The goal is a single, centralized identity provider across Microsoft 365 applications.
    2. SharePoint and OneDrive integration with Microsoft Entra B2B is becoming mandatory:
      • Starting May 2026, SharePoint and OneDrive integration with Microsoft Entra B2B is enabled for all tenants regardless of the EnableAzureB2BIntegration setting, and the ability to disable it is removed.
      • For tenants where integration is already enabled, external users are authenticated and managed via Microsoft Entra B2B Invitation Manager.
      • Enabling this integration does not change existing sharing settings (for example, sites with external sharing disabled remain disabled).
    3. Impact on existing and legacy invitations:
      • As of June 2024, invitations sent through the legacy SharePoint Invitation Manager no longer grant access; documents must be reshared to generate valid invitations.
      • After enabling Microsoft Entra B2B integration, external users attempting to use previously shared OTP-based links can see errors such as “This organization updated its guest access settings.” Resharing the files, folders, or sites is required to restore access.
    4. Guest user provisioning and Conditional Access:
      • With the newer sharing back-end, when a site, list, or library is shared with guests via the legacy path, a guest account might not be provisioned in Microsoft Entra ID, which can cause errors like “Selected user account does not exist in tenant …” when Conditional Access policies apply.
      • To avoid this and streamline guest access, Microsoft recommends enabling SharePoint integration with Microsoft Entra B2B so that guests are properly provisioned and subject to Entra policies (including MFA, terms of use, etc.).
    5. One-time passcode behavior under Microsoft Entra B2B:
      • Under Microsoft Entra B2B, OTP is still available and is the default for guests without a work/school or Microsoft account.
      • The OTP experience is now governed by Microsoft Entra External Identities and B2B policies rather than SharePoint’s legacy OTP engine.

    Practical guidance to move forward with external collaboration

    Within the constraints of the current platform direction:

    1. Ensure SharePoint and OneDrive are integrated with Microsoft Entra B2B:
      • Enable the SharePoint and OneDrive integration with Microsoft Entra B2B Invitation Manager if not already enabled. This ensures that all new external sharing uses Entra B2B and that guests receive B2B-based invitations.
    2. Use Microsoft Entra External Identities settings to control guest experience:
      • Configure External collaboration settings in Microsoft Entra ID (Guest user access, Guest invite settings, and Email one-time passcodes for guests) to align with organizational policies.
      • Ensure that guest invite settings allow the appropriate roles (for example, administrators and users in the Guest Inviter role) to invite external users, so that site owners or designated staff can manage invitations without central IT handling every request.
    3. Plan and streamline guest lifecycle and governance:
      • Use Microsoft Entra ID Governance (access reviews, Conditional Access, and access packages) to manage external users at scale rather than handling them manually per site.
      • Establish a process to review and remove external users who no longer need access, including both guest and member-type external accounts.
    4. Address legacy links and existing external users:
      • For content previously shared via SPO OTP or legacy SharePoint Invitation Manager, plan a campaign to reshare critical resources using the new B2B-based sharing model.
      • Where necessary, proactively create Microsoft Entra B2B guest accounts for external collaborators so they retain access to previously shared files.

    These changes are part of a broader move to centralize external identity and access control in Microsoft Entra B2B for Teams, SharePoint, and OneDrive, which allows consistent application of Conditional Access, MFA, and governance policies, but does require adjusting workflows away from the legacy SharePoint-specific OTP engine.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.