What happens to SharePoint one-time passcode sharing on 1 October 2026?
External users who open shared files with an emailed passcode lose access from 1 October 2026 unless they have a Microsoft Entra B2B guest account in your directory. Create those guest accounts and every existing link keeps working. Nothing needs resharing, and anonymous links are unaffected.
External users who open shared SharePoint content with a passcode emailed to them lose that access from 1 October 2026, even for files they have opened repeatedly for months or years. Microsoft is moving external authentication from SharePoint Online to Microsoft Entra B2B identity for all specific-people external sharing.
What Is SharePoint One-Time Passcode Authentication
When a SharePoint admin or document owner shares a file or folder with a specific external email address, SharePoint can authenticate that recipient in one of two ways: via the recipient's existing Microsoft account or work account, or by sending a numeric one-time passcode to their email and accepting that code as proof of identity. The second method, SPO OTP, has been the fallback for external users who do not have a Microsoft account.
OTP asks nothing of the recipient beyond access to their inbox. No account creation, no password, no MFA. Microsoft is removing this path because users authenticated by it exist entirely outside Microsoft Entra ID. They have no guest account, fall outside the scope of Conditional Access policies, and are invisible to guest lifecycle management. Maintaining a parallel authentication path that bypasses Entra ID controls is incompatible with the direction of Microsoft 365 security governance.
One-Time Passcodes Are Not Going Away
This change is widely described as the retirement of one-time passcodes, and Microsoft answers that directly in its own FAQ: passcodes are not being retired. Microsoft Entra B2B uses a one-time passcode as the default authentication method for guests, so an external user without a Microsoft account still receives a code by email and still signs in with it.
What changes is which system issues that code and what it leaves behind. Today SharePoint issues it and the recipient exists nowhere in your directory. After the transition Entra issues it and the recipient has a guest account, which is what brings them inside Conditional Access, guest lifecycle management and access reviews. The sign-in experience is close to unchanged; the governance position is completely different.
The Retirement Timeline (MC1243549)
- May 2026 (complete): New external sharing invitations use Microsoft Entra B2B automatically. SharePoint no longer issues its own passcode for newly created sharing links in tenants the rollout has reached. Newly invited external users authenticate with a Microsoft account, a work account, or a new Entra guest account.
- 1 October 2026: Phase 2 begins. The retirement extends to existing links. External users who have no Entra B2B guest account in your directory receive access denied on content already shared with them. Files are not deleted; only the SharePoint-issued authentication path is removed.
- 31 October 2026: Phase 2 is expected to complete across production environments.
These dates are the rescheduled ones. The original announcement set Phase 2 for August 2026, and the message centre entry was revised on 17 July 2026 to move it to October.
Which Organisations Are Most at Risk
Tenants that have already required a Microsoft account for all external sharing will see minimal disruption. Organisations most likely to have affected users are those where:
- External users routinely access shared content via OTP links, particularly contractors, clients, and partners who do not have Microsoft 365 licences.
- Sharing links have been active for months or years with no governance review.
- The tenant has never enforced Microsoft account requirements for external sharing at the tenant or site level.
If your organisation shares documents regularly with external parties using default SharePoint sharing settings, some of those links rely on OTP authentication. The retirement affects both SharePoint Online and OneDrive for Business sharing links of this type.
Steps Admins Should Take Before 1 October 2026
- List the guests who have no Entra B2B account yet. This is the step that decides who breaks, and Microsoft provides it directly: the site-level external sharing report returns the guests invited by SharePoint passcode who do not yet have a Microsoft Entra B2B guest account, in its User E-mail column. Run it per site and you have the exact population at risk rather than an estimate.
- Create those guest accounts in advance. Creating the Entra B2B guest account in your directory restores access to everything already shared with that person. Doing it before October turns a cut-off into a non-event, because the accounts are in place before the authentication path is removed.
- Review the sharing links themselves while you are in there. ShareMaster's Shared Links and Permissions feature gives administrators a browsable view of active sharing links across a site or library, which is how you see which specific-people links point at external recipients and how long they have been sitting open.
- Review Conditional Access policies for guests. Once external users authenticate through Entra B2B, any guest-scoped Conditional Access policy applies to them, including ones that were previously irrelevant because passcode users were never in the directory. Confirm those policies are scoped so legitimate external access is not blocked by MFA or device compliance requirements written for a different population.
- Clean up stale sharing links while reviewing. This transition is a useful prompt to audit all active external sharing, not just OTP links. Removing links to content that no longer needs external access reduces your sharing footprint. See the guide to auditing SharePoint shared links for a step-by-step approach.
For a reference on what each SharePoint external sharing setting permits, see the SharePoint external sharing settings reference.
Frequently Asked Questions
Is one-time passcode authentication being retired?
No, and Microsoft says so in its own FAQ. Entra B2B uses a one-time passcode as the default authentication method for guests, so codes by email continue. What retires is the SharePoint Online passcode path, which authenticated people who existed nowhere in your directory.
Do existing SharePoint sharing links need to be reshared?
No. Microsoft states that previously shared links do not need resharing. What matters is whether the recipient has a Microsoft Entra B2B guest account in your directory: if one is present, every link already shared with that person keeps working. An administrator can create the account in advance rather than waiting for the access failure and re-sharing afterwards.
Will existing SharePoint passcode links stop working on 1 October 2026?
For recipients with no Entra B2B guest account, yes. They receive an access-denied error on links that worked the day before. Files are not deleted and the link is not revoked, so creating the guest account restores access to the same link.
Are anonymous SharePoint sharing links affected by this retirement?
No. Anonymous links (anyone with the link) are not affected. This change applies to specific-people sharing links that used the SharePoint passcode as the authentication method. If your tenant policy permits anonymous links, those continue to work after October 2026.
Does the OTP retirement affect SharePoint site permissions?
No. External users who already have an Entra B2B guest account or a work or school account and were added to a SharePoint site directly are not affected. Only users who relied on email one-time passcodes to open sharing links will experience disruption.