Published on August 25, 2026
SharePoint OTP Retirement: Migrate to Entra B2B by Oct 2026
BCC
Microsoft Is Forcing the Switch. Is Your Organization Ready?
Microsoft is discontinuing SharePoint One-Time Passcode (OTP) authentication for all external sharing. Every Microsoft 365 tenant, Business, Government, and Sovereign, will migrate to Microsoft Entra B2B guest accounts by October 31, 2026. There is no opt-out.
If your organization shares SharePoint files or folders with external users, this change directly affects you. Here is everything you need to know, and what to do before your external collaborators start hitting "Access Denied" errors.
What Is SharePoint OTP and Why Is Microsoft Retiring It?
SharePoint OTP (also known as SPO OTP) is an authentication method that lets external users access shared SharePoint or OneDrive content by entering a one-time passcode sent to their email. No Microsoft account or guest account in your directory is required.
While convenient, this approach has significant security drawbacks:
- OTP users have no persistent identity in your Microsoft Entra ID directory
- They cannot be covered by Conditional Access policies or MFA enforcement
- There is no lifecycle management. Accounts never expire automatically.
- Admins have limited visibility into who is accessing what content
Microsoft's decision to retire SharePoint OTP is part of a broader initiative to bring all external access under the governance umbrella of Microsoft Entra ID (formerly Azure Active Directory). The move is a clear signal: unmanaged external identities are no longer acceptable in modern M365 environments.
SharePoint OTP Retirement Timeline: Key Dates
- May – June 2026: New external sharing invitations automatically use Entra B2B instead of OTP
- October 1, 2026: SharePoint OTP retirement begins; users still relying on legacy OTP authentication receive "Access Denied" errors
- October 31, 2026: Full retirement complete. All non-B2B guest users permanently lose access
Note: Government Cloud (GCCH) environments follow a separate timeline that Microsoft has not yet announced.
Who Is Affected? How to Identify Legacy OTP Users in Your Tenant
External users who access SharePoint via OTP can be identified by their login format: urn:spo:guest#emailaddress. These users will lose access once retirement is complete. Users who already have formal Entra B2B guest accounts (login format: emailaddress#ext#@tenant.onmicrosoft.com) are not affected.
Many organizations have a mixed population of both types, especially if your tenant has had the EnableAzureADB2BIntegration setting disabled at any point in the past. Some legacy OTP accounts may date back to 2019, making a thorough audit critical.
Three ways to identify affected users:
- Query the
IsEmailAuthenticationGuestUserproperty via the SharePoint REST API - Search Microsoft Purview audit logs for the event type
EmailAuthOTPAuthenticationSucceeded(up to 180-day lookback) - Review site collection sharing reports in the SharePoint admin center
How to Migrate: From SharePoint OTP to Entra B2B
The migration path is straightforward, but only if you start early. Invite affected users as proper Entra B2B guests using their existing email addresses. Once they accept the invitation, their access to previously shared SharePoint content is automatically restored. No need to re-share individual files or folders.
Microsoft's B2B invitation workflow handles the account linkage automatically. The guest receives a new account in your directory with the login format emailaddress#ext#@tenant.onmicrosoft.com, and existing permissions carry over.
The Bigger Picture: Why Guest Governance Now Matters More Than Ever
Here is what most technical migration guides miss: this change does not require only a one-time migration task. It fundamentally changes how external users are created and managed in your tenant going forward.
Under the old OTP model, external sharing was largely invisible to your directory. Under the new Entra B2B model, every external file share automatically creates a guest account in Microsoft Entra ID. This is good for security, but it also means:
- Your guest account count will grow rapidly with every new external share
- Without governance controls, you risk accumulating "shadow guests" with no defined lifecycle or expiration
- Compliance frameworks such as GDPR, ISO 27001, and NIS2 require you to manage and document these access relationships
Organizations that treat this as a one-time cleanup task will find themselves with a larger, less-controlled guest population within months.
Action Plan: What Your Organization Should Do Now
- Audit your current external users: Identify which users rely on OTP authentication and which already have B2B guest accounts. Do not wait until October.
- Prioritize early migration: Users who lose access unexpectedly create helpdesk burden and business disruption. Give yourself a runway of several months.
- Communicate proactively: Notify external collaborators about the change before they encounter an "Access Denied" error. This protects your business relationships.
- Establish guest lifecycle governance: Define expiration policies, access reviews, and approval workflows for guest accounts before the new wave of B2B guests arrives.
- Brief your helpdesk and IT teams: Make sure support staff understands the change and can handle re-sharing requests efficiently.
How BCC Affirmatic Simplifies the Transition
Our Affirmatic solution is built precisely for this challenge. Affirmatic provides a structured, automated framework for managing Microsoft 365 guest users, covering the full lifecycle from invitation through to offboarding.
With Affirmatic, your organization can:
- Control the invitation process: Replace ad-hoc SharePoint sharing with a structured, approval-based guest onboarding workflow
- Enforce lifecycle management: Define automatic expiration periods for guest accounts and set up renewal workflows to prevent "zombie guests"
- Gain full visibility: See all guest accounts in your tenant, their access scope, and their activity history in one place
- Support compliance requirements: Maintain audit trails and access documentation for GDPR, ISO 27001, and NIS2
- Reduce admin overhead: Automate the identification and reclaiming of inactive or unmanaged guest accounts
The SharePoint OTP retirement is not a threat to organizations that already have proper guest governance in place. Affirmatic ensures yours is one of them.
Get Started Before the October 2026 Deadline
The retirement timeline is set and there is no opt-out. Start your OTP user audit now, plan your migration, and put guest governance controls in place before the wave of new Entra B2B guest accounts arrives.
Want to learn more about how Affirmatic helps your organization manage Microsoft 365 guest users at scale?
Get in touch with the BCC team. We are happy to walk you through a demo and help you assess your current guest user posture.
View upcoming events
See all industry events that BCC will be attending in the near future.
View eventsBevorstehende Veranstaltungen ansehen
Sehen Sie alle Branchenveranstaltungen, an denen BCC in naher Zukunft teilnehmen wird.
Veranstaltungen ansehen
