Microsoft has been moving external access to shared SharePoint and OneDrive content away from SharePoint Online’s One-Time Passcode (SPO OTP) authentication and toward Microsoft Entra B2B. The transition is already changing how external recipients are identified and managed when they access shared files.

Under the previous model, someone outside the organization could open a shared link and verify their identity with a temporary one-time passcode. With Microsoft Entra B2B, external collaborators are represented as guest accounts in the organization's Microsoft Entra directory.

For the person sharing a file, the process may look much the same. An employee still selects a file in SharePoint or OneDrive, shares it with an external recipient and sends a link. Depending on the organisation’s Entra configuration, external recipients may encounter additional steps, such as accepting an invitation, verifying their identity, or meeting access policies before they can open shared files. The bigger change happens behind the scenes: access is now tied to a guest account that the organization needs to manage.

Where friction and extra work may emerge

The practical impact becomes clearer when existing links and external recipients need to be checked against the new model.

Microsoft's guidance indicates that organizations do not necessarily need to re-share content that has already been shared. However, external recipients who do not have an Entra guest account need one to retain access. In some cases, previously shared links may stop working as the transition takes effect, meaning the recipient or the organization may need to take action to restore access.

For example, an employee may have shared a folder with an external legal advisor several months ago. If that advisor does not have the guest identity required under the new model, the old link may no longer be enough. Someone may need to create the guest account or share the content again to get the access to work.

There is also a less visible change for IT teams. When external recipients are brought into the Entra B2B model, they become guest accounts that need to be managed. For an organization working with hundreds or thousands of customers, suppliers, partners, contractors and advisors, those accounts can quickly add up.

IT may need to keep track of who these guests are, what they can access, whether they still need access and when their access should be removed. A single guest account may not sound like much work. Managing thousands of them is a different story.

External sharing isn't always the same as teamwork

This is where the difference between internal and external collaboration becomes important.

For employees, identity-based access makes sense. Everyone already has an account, a role, an onboarding process and a reason to remain in the company's systems.

External users are different. A customer may need to receive a confidential contract. A supplier may need to send pricing documents. A lawyer may need access to a handful of files for a particular case. An advisor may need information for a few weeks. A project partner may need access to a shared workspace for six months.

These scenarios all involve external people, but they have very different requirements.

For a long-term project team, creating guest accounts and managing ongoing access can be perfectly reasonable. Everyone needs regular access, the relationship is established, and there is value in having a more structured way to manage the team.

But if someone simply needs to receive one sensitive document, the situation is different. The goal is usually straightforward: make sure the right person receives the file, protect the information, and make access easy for them without creating unnecessary administration.

How Tresorit can complement Microsoft

This is where a different approach can make sense.

Tresorit is purpose-built for secure collaboration across organizational boundaries. It allows organizations to share sensitive information with external parties without creating an account and without requiring every recipient to become part of the organization's internal identity environment.

For example, an employee can share a confidential contract with a lawyer using a protected link. Depending on the situation, the organization can require email verification, add a password, limit downloads, apply a watermark, set an expiration date or track activity through audit trails.

The same applies when information needs to come in rather than go out. A company can send a secure file request to a supplier or customer and ask them to upload documents through a protected channel, with controls such as email verification and link expiration.

And when the relationship is more involved, Tresorit Engage provides end-to-end encrypted data rooms designed for ongoing work with external partners and clients. Instead of managing individual file exchanges, teams can work together in a dedicated, secure environment.

This gives organizations different options for different situations. A one-off exchange does not have to become a guest-account management exercise, while a longer-term relationship can have the structure and controls it needs.

The takeaway

The transition from SharePoint OTP to Microsoft Entra B2B has changed what happens behind the simple act of sharing a file. For organizations that work with external people regularly, this can mean more guest accounts to manage and, in some cases, extra steps when existing access needs to be restored.

For long-term project teams, that may be a reasonable trade-off. But many everyday business interactions are much simpler: sending a contract, collecting documents from a supplier or giving an advisor short-term access to sensitive files.

Organizations need the flexibility to choose the approach that fits the situation. Microsoft provides a strong foundation for ongoing, identity-based teamwork. Tresorit can complement it with a purpose-built approach to secure collaboration across organizational boundaries, from easy yet secure file sharing and file requests to encrypted data rooms for more complex workflows.

The key point is simple:

    • Microsoft Entra B2B is well suited to ongoing, identity-based collaboration where external users need structured access over time.
    • Tresorit is well suited to secure external sharing workflows where organizations need to exchange sensitive files quickly, without turning every recipient into a managed guest account.
    • Most organizations need both models: one for internal and long-term collaboration, and one for secure, low-friction work across organizational boundaries.