Sep 25, 2026

SharePoint One-Time Passcode Sharing Retires October 2026: Fix External Access Before Links Break

5 min readBeginner

External users who access shared SharePoint and OneDrive content today by entering a one-time passcode emailed to them are about to lose that access, unless they already have a Microsoft Entra B2B guest account. Microsoft’s retirement of SharePoint One-Time Passcode (SPO OTP) authentication, tracked as message center post MC1243549, has its Phase 2 cutover scheduled to begin October 1, 2026 and complete by October 31 for production environments. If your organization shares files or sites with external partners, clients, or contractors who are not set up as formal Entra guest accounts, this is worth checking this week, not after someone emails asking why their access link suddenly stopped working.

External guests about to lose access? Fix it before October.

What is actually changing

SharePoint Online OTP has been a convenient, low-friction way to share content externally: send a link, the recipient enters an email-delivered passcode, and they get access without any formal account provisioning. Microsoft is retiring that mechanism in favor of requiring Microsoft Entra B2B guest accounts for all external access. The rollout has happened in two phases. Phase 1, which began in May 2026, changed the default so new external sharing invitations and authentication already use Entra B2B rather than OTP. Phase 2, the actual retirement of OTP for existing links and any remaining fallback paths, is what starts October 1 and is expected to complete by the end of that month. GCC, GCC High, and DoD environments are explicitly excluded from both phases for now, with their own timeline to be announced separately through the Message Center.

What breaks for external users, and the two fixes

Once Phase 2 takes effect, an external user relying on an OTP-based link that has not already been converted to B2B guest access will find that link stops working. There is no silent fallback, the recipient hits an authentication wall. There are exactly two ways to restore their access, and both require action from your side, not theirs:

  • Create the B2B guest account directly. An administrator manually provisions a Microsoft Entra B2B guest account for the affected external user, using the same email address the original OTP-based sharing link went to. Once the guest account exists and has the appropriate permissions, the person can access the content again.
  • Re-share the content. The internal file, folder, or site owner opens the standard Share dialog and re-shares with that same external email address. This triggers the current, Entra B2B-based sharing flow rather than the retired OTP path, and effectively re-establishes access through the supported mechanism.

Neither of these happens automatically. If nobody notices a given external relationship depended on OTP until after October 1, that person is locked out until an admin or content owner takes one of these two actions.

Preparing before the cutover instead of reacting after

The practical move is auditing external sharing before the retirement completes rather than waiting for support tickets. Review active external shares across your SharePoint sites and OneDrive accounts and identify recipients who do not already have an Entra guest account associated with their email address, those are the relationships that will break. For anyone you can identify in advance, proactively create the guest account or re-share the content now, while it is a routine administrative task rather than an urgent fix during a live access failure. For ongoing external collaboration patterns your organization relies on regularly, this is also a reasonable moment to review your Entra B2B guest access policies and expiration settings, since guest accounts you create in response to this retirement will be subject to whatever guest governance policy is already in place.

Frequently asked questions

Do internal users lose any access because of this change?
No. This retirement is specific to external sharing authentication, how people outside your organization prove who they are to access shared content. Internal users authenticating through your organization’s own Entra ID are not affected.

Is there a way to keep using OTP past October 2026?
Based on Microsoft’s published retirement timeline, no general opt-out is available for commercial tenants, Phase 2 is expected to complete by the end of October 2026. GCC, GCC High, and DoD environments are currently excluded with their own timeline still to be announced, so check the Message Center for updates specific to those environments if they apply to you.

What happens if I do nothing before October 1?
Existing OTP-based external sharing links that have not transitioned to Entra B2B will stop working once Phase 2 takes effect for your tenant. The external recipient will need an admin to create a B2B guest account for them or a content owner to re-share the content before they can regain access, doing this proactively avoids the resulting support interruption.