Microsoft is moving ahead with the retirement of SharePoint One-Time Passcode (SPO OTP) authentication, with the next phase scheduled to begin in mid-October 2026 and expected to finish by the end of November for Production environments.
The change affects external users accessing files, folders and sites through SharePoint Online and OneDrive. Instead of relying on SharePoint’s legacy OTP authentication flow, external collaboration will increasingly use Microsoft Entra B2B guest accounts, bringing those users into Microsoft’s broader identity, governance and Conditional Access framework.
Microsoft’s latest update, dated October 1, 2026, confirms that Phase 1—the rollout enabling Entra B2B for new external sharing—is fully deployed in Production. Phase 2, the actual retirement of SPO OTP, has been rescheduled to start in mid-October.
For Microsoft 365 administrators, the timeline matters because some external collaborators could lose access to older shared links if the appropriate Entra B2B guest account does not exist.
What Is Changing in SharePoint and OneDrive?
Historically, SharePoint could allow certain external users to authenticate using a one-time passcode sent to their email address.
The upcoming change moves that authentication experience into Microsoft Entra B2B, Microsoft’s identity and guest-collaboration framework. External users will be represented as guest accounts in the organization’s directory, allowing administrators to apply identity and access controls more consistently.
The transition is being implemented in two major phases:
- Phase 1: New external sharing invitations and authentication move to Entra B2B.
- Phase 2: SharePoint Online OTP authentication is retired.
- Production completion: Expected by the end of November 2026.
- GCC, GCCH and DoD: These environments are excluded from the current rollout, with separate dates to be communicated through Microsoft’s Message Center.
The change applies broadly across Microsoft 365 environments, although rollout timing differs for the government environments excluded from the current Production schedule.
The Important October 2026 Deadline
The most significant date for organizations is mid-October 2026, when Microsoft begins retiring SPO OTP authentication.
The change does not necessarily mean every external collaborator will immediately experience a disruption.
External users who already have a matching Microsoft Entra B2B guest account should see no change in their normal access.
The potential problem is with external users who still depend on older SharePoint-specific sharing links and do not have a corresponding B2B guest account.
Once SPO OTP retirement reaches a tenant, those users can encounter an access denied message when attempting to open previously shared specific-people links.
Why Older Sharing Links Matter
The distinction between old and new sharing links is particularly important for administrators.
For sharing invitations created after the Entra B2B changes reached a tenant, Microsoft can automatically create a guest account through the Entra B2B Invitation Manager.
Older invitations are different.
An external collaborator who accessed content through SPO OTP before the transition may not yet have a matching guest account. That account becomes important once the legacy authentication method disappears.
In practical terms, organizations may have external users who have been accessing SharePoint content successfully for months or years but whose authentication arrangements need to be updated before the retirement reaches their tenant.
What Happens When an External User Loses Access?
Microsoft provides two primary ways to restore access.
An administrator can manually create the external user’s guest account in Microsoft Entra.
Alternatively, an internal user with appropriate permissions can share or re-share at least one file, folder or site with the external collaborator. That sharing action can create the required B2B guest account.
Once the matching guest account exists, the user can continue accessing previously shared content.
This makes external-sharing inventories particularly relevant as the October rollout approaches.
Who Needs to Pay Attention?
The change potentially affects organizations across Microsoft 365 that use SharePoint or OneDrive for external collaboration.
Key groups include:
- Microsoft 365 administrators
- SharePoint administrators
- Security and identity teams
- Compliance teams
- Organizations working with contractors or partners
- Businesses that routinely share documents with customers
- Teams managing large numbers of external collaborators
The practical risk is not simply whether external sharing is enabled. It is whether external collaborators have the appropriate Entra B2B identity when SPO OTP is no longer available.
Conditional Access Becomes More Central
One of the broader consequences of the transition is the increased integration between SharePoint external collaboration and Microsoft’s identity controls.
With external users represented through Entra B2B, organizations can apply relevant Microsoft Entra Conditional Access, Identity Protection and guest governance policies to those users.
That creates a more centralized approach to controlling external access.
For security teams, this also means reviewing existing policies before the transition rather than treating the change as a SharePoint-only authentication update.
Organizations should verify that their guest access policies work as intended and that appropriate users have permission to invite external collaborators.
What Microsoft 365 Admins Should Do Now
Organizations approaching the October retirement can use the remaining transition period to identify potential access problems.
A practical preparation checklist includes:
- Review external-sharing policies in SharePoint and Microsoft Entra.
- Check Conditional Access policies that apply to guest users.
- Verify guest invitation permissions for administrators and users responsible for external collaboration.
- Review external-sharing reports to identify collaborators who may not have guest accounts.
- Create guest accounts proactively where continued access is important.
- Confirm Entra email OTP is enabled if the organization relies on that authentication option for B2B guests.
- Update internal documentation covering external sharing and guest onboarding.
- Notify users that some older external links may require the collaborator to be provisioned as an Entra B2B guest.
Microsoft specifically highlights the Guest Inviter role as one way to give appropriate users the ability to invite external collaborators.
What About Email One-Time Passcodes?
There is an important distinction between SPO OTP and the email one-time passcode capability available through Microsoft Entra External ID.
Microsoft’s change retires the SharePoint-specific OTP authentication flow. Entra B2B can still use email OTP for eligible guest authentication, provided that capability has not been disabled in the organization’s Entra External ID settings.
That means organizations should not automatically interpret “SPO OTP retirement” as meaning all email-based one-time passcode authentication is disappearing.
Instead, the identity flow is moving from a SharePoint-specific mechanism toward Microsoft’s Entra-based guest identity model.
Compliance and Audit Implications
The migration also has implications beyond user convenience.
Microsoft’s documentation identifies several compliance-related changes associated with the transition.
| Area | Expected change |
|---|---|
| Authentication | External users move from SPO OTP to Entra B2B authentication |
| Conditional Access | External users can be governed through Microsoft Entra controls |
| Guest lifecycle | Guest identities can be managed through Entra |
| Invitations | External sharing uses the Entra B2B Invitation Manager |
| Monitoring | Relevant authentication and guest lifecycle activity can be reviewed through Entra audit capabilities |
For compliance teams, the important issue is where authentication and guest-access activity is recorded and governed after the transition.
Organizations with established audit procedures should review whether their documentation, monitoring processes and evidence collection still point to the correct identity systems.
A Change to the Administration Model
The retirement is also removing some of the separation between SharePoint external sharing and Microsoft’s identity platform.
The EnableAzureADB2BIntegration setting will no longer control external sharing behavior beginning with the 2026 changes, and the option to disable Entra B2B integration is being removed.
That means organizations should plan around Entra B2B as the standard identity model for SharePoint and OneDrive external collaboration rather than treating it as an optional integration.
For IT teams, this shifts the focus from maintaining separate SharePoint authentication behavior to managing guest identities and policies through the Microsoft Entra ecosystem.
What Organizations Should Watch in October and November
The next two months will be particularly important for organizations with extensive external sharing.
The main warning sign will be external collaborators reporting that previously working SharePoint or OneDrive links now return an access-denied message.
When that happens, administrators should first determine whether the user has a corresponding Entra B2B guest account and whether the guest identity matches the email address associated with the original sharing relationship.
If no matching account exists, creating the guest account—or having an authorized internal user share or re-share content—can restore the required identity relationship.
Microsoft expects the Production retirement to complete by the end of November 2026. Government environments covered by GCC, GCCH and DoD are following a separate timeline.
What Comes Next
The retirement of SPO OTP marks a broader move toward making Microsoft Entra B2B the identity foundation for external SharePoint and OneDrive collaboration.
For users, the change may be almost invisible when the correct guest account already exists. For organizations with years of accumulated external sharing, however, the transition provides a reason to examine who has access, how those identities are managed and which security policies apply to them.
The immediate priority is therefore less about changing how employees share files and more about identifying external collaborators who could be left behind by the retirement of the legacy authentication path.
As Microsoft’s October rollout begins, organizations that proactively review guest identities and external-sharing relationships will have a clearer picture of where access could be affected before the final November deadline.






