SharePoint’s one-time passcode sharing retires on 1 October 2026

Share on facebook
Share on twitter
Share on linkedin
Share on email

If you share files out of SharePoint or OneDrive with people outside your organisation, the way they get in has already changed. Older links start dying in October.

This is for the person who has just had a client phone up and say: it’s asking me to create an account and I don’t know what to do.

The short version

  • Since May–June 2026, a new “specific people” share creates a guest account for the recipient in your Microsoft Entra directory. That part is already live.
  • From 1 October 2026, SharePoint’s own one-time passcode (SPO OTP) retires. Recipients on older links who have no guest account start getting access denied. Microsoft expects that done by 31 October.
  • You do not have to re-share everything. You need a guest account for that person. Create one, or share one file with them. That restores the old links too.
  • “Anyone with the link” shares are not affected.
  • You cannot turn this off. The old setting is gone.

Source of truth: Microsoft 365 Message Center MC1243549, published 4 March 2026, last revised 17 July 2026. Microsoft’s public FAQ still says July. Trust the Message Center, and check your own tenant.

If you send one-off files to clients — completion statements, SAR bundles, counsel papers — and you need proof of delivery, SharePoint is no longer built for that job. Skip to  where safedrop fits, or read on for what actually changes.

Everyday “Send link” overlay — what staff actually click

What Microsoft is actually doing

For years there were two ways an external person opened a file you shared with them by name.

The old way: SharePoint sent a code. They typed the code. No account anywhere. About as simple as secure sharing gets.

The new way: Microsoft Entra B2B. They become a guest in your directory. They sign in with a work account, a personal Microsoft account, or an Entra email passcode.

Microsoft’s reason is governance, and it is a fair one. SPO OTP sat outside Entra. No Conditional Access. No guest lifecycle. A thinner audit trail. If you run a large tenant, you want every external identity in one place.

The trade-off is simple. The easiest recipient experience is gone. The cost lands on whoever sent the file.

Two phases

Phase 1 — already done. May and June 2026. New named shares go through Entra. A guest object is created automatically. If your recipients have been confused since summer, this is why.

Phase 2 — 1 to 31 October 2026. Old SPO OTP links die for anyone without a guest account. Originally July/August. Slipped to October in the 17 July revision.

GCC, GCC High and DoD are excluded for now.

One warning: Microsoft Learn’s FAQ was last usefully aligned in May and still says access denied “starting July 2026.” Where FAQ and Message Center disagree, use Message Center.

What your recipients see now

They do not get a simple code prompt. They get an invitation to become a guest in your organisation.

Depending on the address and your tenant, they are asked to use a work account, a personal Microsoft account, or an Entra email passcode. That last option is the closest to the old experience. Check it is still enabled. Even then they are consenting to an invitation, not just typing a code.

To a client it reads the same way: this firm wants me to set up an account to read one document.

SharePoint OTP access denied — how to restore access

From 1 October, old SharePoint OTP links return access denied unless a guest account exists. Two ways to restore access.

You do not need to go back through every send. Microsoft is explicit: previously shared links keep working if a guest account exists for that person.

  1. An admin creates the guest account. Once. No duplicate if they already exist.
  2. Someone inside shares or re-shares one file, folder or site with that person. That creates the guest. One share restores the rest.

Microsoft points admins at the site-level external sharing report. Look at the “User E-mail” column for people invited via SPO OTP who still have no Entra guest. Create the ones that matter before October.

The second fix is what your staff will actually do. Sit with that for a second. Client cannot open the June bundle. Supported answer: create an identity for them inside your directory.

Fine for a stable set of partners. Ugly for a conveyancing team sending completion statements to several hundred one-off clients a year.

Three things this is not

It is not the end of passcodes. Entra email OTP remains. Default on for new tenants and for old ones that have not switched it off. What dies is SharePoint’s separate passcode flow. The difference is not the code. It is the guest object that now exists either way.

It does not touch anonymous links. Anyone-with-the-link works as before. No guest. If someone tells you all SharePoint sharing now needs an account, they are wrong.

It is not optional, and you cannot pick a date. No opt-out. Tenants are selected by Microsoft’s rollout. The window to switch the integration on early closed at the end of April 2026.

anonymous links are not affected

And it is not the new sharing dialog

Separate change. Message Center MC1454378, roadmap 492622. One reusable “hero link” per file or folder. Rolling mid-September to late October 2026. This one does include GCC / GCC High / DoD.

Default hero link: “Only people added to the file.” The link itself grants access to nobody. Microsoft still calls adding people directly “the simplest way to share.” That path is the named path. That path creates guests.

Two changes in the same window. Both push the same way.

Admins can set the default hero-link audience per site collection or OneDrive with DefaultMainLinkScope in SharePoint PowerShell (OnlyPeopleAdded or Organization). No tenant-wide switch. Existing links keep working under “Other links.”

Audit and proof of delivery

This is the bit that matters if you have to show a document was sent and received.

After retirement, authentication and guest lifecycle live in Entra audit logs, not SPO OTP logs. Everyone external authenticates through Entra B2B. Conditional Access, Identity Protection, guest policies all apply.

For a big identity team: better. One place, one policy set.

For a small firm that needs evidence a specific client got a specific bundle on a specific date:

  • The evidence moved.
  • It is identity-centric, not document-centric. Reconstructing one file means correlating logs.
  • The person who needs it — legal secretary, practice manager — usually cannot see the Entra admin centre.

SharePoint is not a bad system. If delivery evidence is part of the job, check you can still produce it. Do that now, not the week you are asked.

The guest you will never see again

Every named external share now leaves a persistent object in your directory. Somebody reviews it. Somebody removes it.

Partners: manageable. One-off clients: you are collecting identities for people you will not share with again, in the same directory that governs your internal systems. That is data minimisation and offboarding in the same sentence. There is no neat answer inside Microsoft 365.

Four options

Do nothing and manage the guests. Works if external sharing is real collaboration with a known set of firms. Better governance. Worse experience for the occasional recipient. You own the lifecycle.

Pre-create guest accounts before October. Right move for a short list of people whose links must not break. Does not scale to hundreds of one-offs.

Use anonymous links for outbound sends. Sidesteps the change. Simplest for the recipient. Anyone holding the link can open it. Your record of who opened it is weaker. Fine for low-sensitivity material. Poor when you may need to prove receipt.

Keep SharePoint for collaboration. Use something else for one-off outbound. Split the problem on the line where it already splits. Partners stay in the tenant, under Entra. Client bundles and counterparties go through a tool built for a send, not a guest.

Where safedrop fits

We build the fourth option. Treat this as what it is.

safedrop is a UK-owned secure file transfer product. It is not a SharePoint replacement. Do not run it as one. It is the second tool, for the send that leaves the building.

Three things that matter for this change:

No account for the recipient. Link, authenticate to the file, collect it. Nothing lands in your directory. No invitation to accept. No “what do I sign in with?” call.

A delivery record on the send itself. Sent, opened, downloaded. Who, when. Document-centric, which is the shape you want when someone claims they never got the bundle. One of our customers had a solicitor deny receipt. The safedrop record went to court. Costs against them. Many of our clients legal teams use the open tracking before hearings.

Zero-knowledge encryption. Keys stay on the client. We do not hold a master key to hand over, or to lose. That is a claim about key custody, not about which country the disks sit in.

If you send from conveyancing@ or admin@, you will feel this change first.

Free to try. Teams get a two-week trial. No card.

If you want a walkthrough for IT or compliance, book a call.

FAQ

Is SharePoint one-time passcode (SPO OTP) being retired?
Yes. SharePoint’s own passcode flow retires from 1 October 2026. Entra email one-time passcode is not retiring. Different product, same-looking code.

When does it happen?
New named shares have used Entra B2B since May–June 2026. Old SPO OTP links start failing from 1 October and Microsoft expects that done by 31 October. GCC, GCC High and DoD are later. Check your own Message Center. Microsoft’s public FAQ still says July. It is wrong.

Do I have to re-share every old link?
No. Create a guest account for that person, or share one file with them. That restores access to what you already shared. The guest is the thing that matters, not the age of the link.

Are “Anyone with the link” shares affected?
No. Anonymous links do not create a guest and do not use SPO OTP. This change is named, specific-people sharing only.

Can I opt out or pick a date?
No. The setting that used to control it is gone. The early-enable window closed at the end of April 2026.

Will recipients need a Microsoft account?
Not always. They may sign in with a work account, a personal Microsoft account, or an Entra email passcode if you have that enabled. They will always become a guest in your directory.

Does this affect proof of delivery?
Yes, in practice. Auth events move to Entra logs. Reconstructing one file means correlating identity events, and most practice managers cannot see the Entra admin centre. If you have to prove a specific bundle arrived, check that path now.

Is the new “hero link” the same change?
No. Hero link is a separate rollout (MC1454378, mid-September to late October). Default is “Only people added to the file,” which is the path that creates guests. Related. Not the same thing.

What should we do if we send one-off files to clients?
Keep SharePoint for collaboration with known partners. For outbound bundles where the recipient should not join your directory, use a send tool that does not create a guest and writes a delivery record on the file.

Sources

  • Microsoft 365 Message Center, MC1243549 — Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B. Published 4 March 2026, last updated 17 July 2026.
  • Microsoft 365 Message Center, MC1454378 — The Next Generation of File & Folder Sharing. Published 13 August 2026, last updated 26 August 2026. Roadmap ID 492622.
  • Microsoft Learn — FAQs: Improvements to external sharing in OneDrive & SharePoint (last useful update 9 May 2026; still cites July).
  • Microsoft Learn — Email one-time passcode authentication (Entra External ID).
  • Microsoft Learn — Microsoft Entra B2B integration for SharePoint & OneDrive.
  • Microsoft 365 Community Hub — “Simple, Smart, and Secure: The next step in sharing files in Microsoft 365.”

Dates checked 7 September 2026. Microsoft has already moved both of these once. Rollout varies by tenant. Read your own Message Center.