Some day this month, with no warning of which day, the person at your payroll firm who opens your staff records with a code emailed to them is going to see "access denied". It is not a bug. Microsoft is retiring SharePoint Online one-time passcode authentication in commercial tenants during October 2026, and what stops opening are the "Specific people" links shared back then with anyone who does not today have a guest account in your directory. The "Anyone with the link" link, the one you have spent years trying to stop people using, is untouched.
It is worth saying up front that the change is a good one. Moving guest authentication from a SharePoint-specific mechanism to Microsoft Entra B2B means those people now exist in your directory, with a record, an audit trail and subject to your policies. It is better than what came before and we will defend it even if that costs us a headline. It is also worth clearing up the likeliest misunderstanding before going on: the emailed code is not going away. What is being retired is SharePoint Online's own mechanism; the Entra B2B one stands, and the documentation says so in the very first FAQ answer —"Microsoft Entra B2B email one-time passcode (OTP) authentication isn't being retired". If that person holds a guest record, they will keep getting in with a code. What is awkward is the road there.
It is the careful link that breaks, not the open one
SharePoint and OneDrive have three link types âthe report.s own Link Type column calls them Anonymous, Organization and Specific Peopleâ and two of them point outwards. They are not equivalent. The Specific people link is the one that makes you type the recipient's address: access is bound to that address and, if they forward it, the next person gets nothing. The Anyone with the link one is anonymous: it works for whoever holds it, it gets forwarded down an email chain and ends up on the phone of somebody you have never met.
The retirement hits the first. Microsoft's documentation answers it in one line: "Is there any impact on Anyone/Anonymous links? — No, SPO OTP retirement and use of Entra B2B for external sharing does not impact Anyone/Anonymous links". And on the other, just as clear: users without a matching guest account "receive access denied on previously shared Specific people links".
It is not an oversight: it is mechanics. The anonymous link authenticates nobody, so there is no identity to migrate anywhere. But the effect inside your company, for however many weeks it takes you to notice, is what it is: the organisation that shared by name ends up with broken access and the one handing out open links notices nothing. If somebody on your team draws the conclusion that sharing carefully causes trouble, that damage will outlast the incident.
You do not have a date: you have a month
Your room for manoeuvre is closed off by four answers in the documentation, two on the FAQ page and two in the questions section of the integration page. The FAQ rules out opting out —«Commercial tenants can't opt out of SharePoint OTP retirement or disable Microsoft Entra B2B integration for new external sharing»— and rules out picking the day: «Retirement rolls out to commercial tenants during October 2026. Tenants are selected automatically, and you can't choose a specific date». The integration page closes the other two escape routes: asked whether exceptions can be made, it answers «No. This update is part of Microsoft's ongoing efforts to enhance security», and asked whether it can be applied to one site, «the change applies at the tenant level and can't be scoped to individual sites».
From which follows the practical consequence that matters: the fact that it works today proves nothing. While the rollout lasts, "it still opens" and "it has not reached us yet" are the same sentence. The only check worth anything is the one against your list of recipients, not the one against whether the link opens.
The setting you are about to check no longer means anything
Almost everyone reading this will open the SharePoint Online shell and check the historic integration setting. It is the reasonable reflex and it leads to a false conclusion, because the earlier phase has already happened: "Between May and July 2026, Microsoft enabled SharePoint and OneDrive integration with Microsoft Entra B2B for new external sharing in commercial tenants. The EnableAzureADB2BIntegration setting no longer controls sharing behavior for these tenants, and the integration can't be disabled".
Connect-SPOService -Url https://<tuorganizacion>-admin.sharepoint.com
Get-SPOTenant | Select-Object EnableAzureADB2BIntegration
That command still returns True or False, and in a commercial tenant the value tells you neither whether the retirement has reached you nor whether your old guests will keep getting in. Microsoft's own answer closes it off: the integration is on "regardless of the EnableAzureADB2BIntegration value". What matters is no longer that setting, but how many outside people hold a record in your directory.
The report they point you to has a documented blind spot
Microsoft answers "how do I identify guests who do not have an account yet?" by sending you to the site's external sharing report, looking at the User E-mail column. It is good advice, and you need to read the whole technical page, because that is where the sentence that changes the plan sits: "The report doesn't include links that are emailed directly but aren't clicked, or Anyone links".
That sentence has to be read precisely, because the exclusion is narrower than it looks and still hurts. The same page explains that the report carries a row "for each signed-in user who uses the link or receives the link through the sharing dialog": if it was shared from SharePoint's own dialog, the recipient shows up even if they never clicked. What disappears is the other case, the everyday one: somebody copied the link, pasted it into their own Outlook message and sent it by hand. If that person filed the message and did not open it until they needed it, they are on no list at all, and they are precisely the one who will fail, because theirs is the link that has been asleep for years. On top of that, another line from the same page: "The report shows SharePoint groups, but not individual users inside them".
There is also a matter of scale. The report runs site by site —"You must be a site admin to run the report"— and in OneDrive each person runs it from their own settings: a company with forty sites and a hundred and twenty OneDrives does not have "a report", it has a hundred and sixty. And the file is saved inside the site itself, with a warning worth reading twice: "If you don't want site members to see the report, consider creating a folder with different permissions where only site owners can access the report". The list of everything a department shares outwards ends up, by default, where any site member can read it.
It should be said that Microsoft does not wash its hands of this: asked whether there is any way to report which links and users are affected, the integration page answers "Yes" and offers two further routes: audit logs, and the site sharing reports available through Microsoft Graph Data Connect. Both are real and both have the same problem for an SME. The audit log tells you what happened inside its retention window, and the link that will break your month has been asleep since 2023, well beyond any reasonable retention. And Graph Data Connect does solve the scale problem —it is tenant-wide, not site by site— but it requires an Azure subscription, organisation-level permissions and a data pipeline to build. It is the right tool if you already have it; if you have to stand it up for this, it costs more than the problem.
Turn it around: do not discover who you are locking out, decide who you want in
If the exhaustive inventory is expensive and incomplete by design, chasing it is the wrong strategy. The right one is the opposite, and it is cheaper: instead of reconstructing everyone you have ever granted access to, take the two lists you already hold outside SharePoint —the active customers and suppliers in your ERP or CRM, and the handful of addresses for your accountant, payroll firm, auditor and bank— and create those guest accounts in advance. Microsoft explicitly allows for this and clears away the fear of duplicates: "If a Microsoft Entra B2B guest account already exists for a collaborator outside your organization, a duplicate is not created".
Whatever is not on those lists, let it break. A four-year-old link to a person who no longer works at that company ought to stop opening; the fact that it still works is the problem, not the solution. Seen that way, this is not an outage: it is a clear-out of external access that nobody would ever have authorised on their own initiative, because it is frightening and no client asks for it.
The expensive mistake is the opposite one, and it is what plenty of shops will do this month: pull the report, see a list of two hundred external addresses and reshare in bulk so nobody complains. That turns two hundred emails of uncertain provenance into two hundred permanent records in your directory, which is exactly the hole we described in The directory holds more records than the company has employees. A guest account does not expire on its own.
The guest now comes in through Entra, under your rules
The good part of the change has small print too, and it is the same sentence: "Invited people outside your organization each get an account in the directory and are subject to Microsoft Entra ID access policies such as multifactor authentication". Read it twice. From now on, the outside people opening your documents are subject to your Conditional Access policies. If yours were written with employees only in mind —or if they are the ones that shipped by default and nobody reviewed— you will find guests blocked by a rule you had forgotten, or guests getting in under fewer requirements than you assumed. Both surprises are common and both are avoided by reading the policies beforehand, not afterwards: we went into it in The Conditional Access policies you never wrote are already in your tenant.
There is a second side effect that barely anyone mentions, and it can bite you quietly. If you kept a list of allowed or blocked domains for sharing in SharePoint, it needs revisiting. Microsoft writes this inside the enablement procedure —drafted for tenants where the setting still rules— but the warning holds just the same now that the integration is on everywhere: "Review any custom domain sharing restrictions in SharePoint and OneDrive and decide if they should be moved to the Microsoft Entra B2B Allow/Deny list", and warns you of the bill: "The Microsoft Entra ID Allow/Deny list also affects other Microsoft 365 services like Teams and Microsoft 365 Groups". Which means: move your domain restriction over to Entra as it stands and you end up applying it to Teams and Groups as well. That is not a call for whoever administers SharePoint to make.
In the Microsoft 365 tenants we administer, the order we do this in is not the one that looks logical. You read the Conditional Access policy first, and invite afterwards. We learned that the boring way: a policy written with employees in mind, carrying a location or compliant-device condition, locks out a guest who has just accepted the invitation, and then you have two problems instead of one: the broken access and a policy you are no longer sure you should touch. Looking at it first costs the same.
What this will not cost you (and what will)
Somebody will tell you that filling your directory with guests sends the bill through the roof. Let us be precise, and that includes not stopping at the most reassuring example. The External ID model bills on monthly active users: "the count of unique external users who authenticate to your tenants within a calendar month". The documentation walks through several scenarios, and you have to take the one that applies to you. The first —a consumer app in an external tenant with 10,000 users signing in with email or a social identity— ends in "No cost if MAU usage is within free limits", but that is not your case. Yours is the fourth: "An organization invites 2,000 external business partners as B2B collaboration guests in their workforce tenant", and there the result is no longer free but "Microsoft Entra External ID Basic MAU charges", plus the governance add-on if you use it. There is a free tier, but Microsoft publishes the figure on the pricing page rather than the technical one: if anybody quotes you an exact number, ask where it comes from and what date it carries.
Even so, for an SME with a few hundred external recipients the cost of this is not on the invoice: it is in the hours. That is the number to put on the table, and it is the one almost nobody works out.
The work order, in five steps
- 1Produce the short list before the long one. The external addresses that cannot fail: payroll firm, accountant, auditor, bank, the two or three clients who work inside your folders. It usually fits on one sheet.
- 2Create those guests in Entra now, using the exact address the item was shared with back then. If the record exists it will not be duplicated. It has to be the same address: not an alias, not another mailbox belonging to the same person.
- 3Run the report only on the sites that genuinely share. Usually four or five: sales, purchasing, projects, management. Save the CSV to a folder with owner-only permissions, not to the general library.
- 4Review your Conditional Access policies before inviting anyone. Look specifically at what you require from a guest-type user and from where. It is cheaper to fix with five guests than with two hundred.
- 5Brief whoever answers the phone. Through October, "I get access denied on the link you sent me" has a known cause and a two-minute fix: create the guest, or reshare a single item. If nobody on the service desk knows this, it gets logged as a SharePoint fault and takes two days.
The repair itself is cheap: "You don't need to reshare each item individually". Create the guest account, or share a single item with that person, and they get back everything they already had. It is cheap if you know who to repair. All the work lives in that condition.
What we are not going to tell you
- ✗That Microsoft is doing something to you. The change genuinely improves control over who opens your documents, and we would rather say so even though the alarmist headline performs better. What we question is the distribution: the benefit goes to the administrator, and the "access denied" lands on a third party who knows nothing about any of this.
- ✗That a complete inventory exists. It does not: the official report excludes, in writing, links pasted by hand into an email and never clicked. Anyone promising you the exact list of affected users has not read the report's own page.
If your company shares documents with people outside it —and every company does— this is work for this week, not for November. And if reading it made you realise you do not know how many external addresses have access to your folders right now, that is the diagnosis: October does not bring the problem, it uncovers it.
Sources (verified 11 Oct 2026): every quoted passage is verbatim from Microsoft Learn's official documentation. Timeline, phases, inability to disable, absence of exceptions and of per-site scoping, guests subject to Entra policies, the audit-log and Graph Data Connect route, and the domain-restriction note: Microsoft Entra B2B integration for SharePoint & OneDrive (ms.date 18 Sep 2026). Inability to opt out or pick a date, survival of Entra B2B email OTP, Anyone links, duplicates and resharing: FAQ on improvements to external sharing in OneDrive and SharePoint (ms.date 18 Sep 2026). Report mechanics, columns and exclusions: Report on file and folder sharing in a SharePoint site (ms.date 7 May 2026). Monthly-active-user billing model: External ID pricing (ms.date 22 Jun 2026). The "hundred and sixty reports" figure is ours, from a hypothetical estate of forty sites and a hundred and twenty OneDrives: substitute your own.
Do you know how many outside addresses can open your folders right now?
If the answer is "no idea", the short list takes one afternoon and saves you the week of phone calls. It is Microsoft 365 work —the tenant, the guests and the policies governing them— and what keeps it alive afterwards is compliance and continuity: the record of who accesses which document, reviewed every quarter rather than every time something breaks.
Talk to everyWAN