Why some SharePoint and OneDrive guest links may stop working during the 2026 rollout

If you share files from SharePoint or OneDrive with clients, suppliers or contractors, some older authenticated sharing links may stop working during Microsoft’s 2026 external-sharing transition. Microsoft began enabling SharePoint and OneDrive integration with Microsoft Entra B2B across all tenants in May 2026. The rollout is automatic, and administrators cannot select their migration date or opt out.

The change does not retire email one-time passcodes completely. Microsoft Entra B2B can still use a one-time passcode when a guest does not have a suitable work, school or Microsoft account. What is being retired is SharePoint Online’s separate authentication model, under which some external recipients were represented only within SharePoint rather than by a Microsoft Entra B2B guest account.

What changes and when

StageWhat happensWhat it means for your business
From May 2026Microsoft begins enabling Entra B2B integration for all tenantsNew authenticated external shares create or use an Entra guest account
From July 2026Some recipients using older links without an Entra guest account may be denied accessIdentify important external users before they report a problem
During the rolloutExisting links continue working where the recipient already has a guest accountYou do not need to re-share every external link
If access failsRe-share a file, folder or site, or create the guest account manuallyThe recipient can regain access to previously shared content
No changeAnyone or anonymous links are unaffected by this particular transitionReview them separately because they carry different security risks

Microsoft says an existing link does not need to be replaced simply because it is old. The important factor is whether the external recipient has a Microsoft Entra B2B guest account in your tenant. Administrators can use the SharePoint external-sharing report to identify SharePoint one-time-passcode users who do not yet have an Entra guest identity. Read Microsoft’s own guidance for the current technical details.

Why Microsoft is making the change

Under the previous model, external identities could be managed within SharePoint rather than centrally through Microsoft Entra. Sharing activity could still be audited, but administrators had less consistent identity governance across Microsoft 365.

With Entra B2B integration, authenticated external recipients are represented as guest users in the organisation’s directory. Microsoft Entra policies can then be applied to them, including multifactor authentication and Conditional Access. Administrators can also remove a guest account or revoke its permissions when a contract or working relationship ends.

Find the links your business relies on

The most disruptive links are often the quiet ones: a supplier opening a price list, an accountant accessing a quarterly folder or a document embedded in a partner workflow. Ask teams which external files and folders they rely on, then compare those answers with sharing reports and audit information.

Do not assume that creating guest accounts completes the job. Guest identities can remain in the directory after their original purpose has ended. Review external access regularly, configure guest-access expiration where appropriate and use Microsoft Entra access reviews where your licensing supports them.

Strengthen the wider security controls

Access reviews should be the main control for stale guests and permissions. Broader vulnerability management and routine vulnerability scanning can support this work by identifying misconfigurations, weak access controls and other security gaps, but they do not replace a dedicated sharing review.

A managed SOC service can monitor relevant identity and Microsoft 365 logs for unusual behaviour when correctly configured. MDR services can investigate and contain suspicious account activity, while Dark web monitoring may identify exposed business credentials. Regular cyber security awareness training also helps employees avoid unnecessary or overly broad external sharing.

Frequently asked questions

Why has an external SharePoint link stopped working?

The recipient may have been using the previous SharePoint authentication model without an Entra guest account. Re-sharing the content or creating the guest account can restore access.

Do we need to re-share every external link?

No. Existing links should continue working where the recipient already has a Microsoft Entra B2B guest account.

Can we turn off the change?

No. Microsoft is enabling the integration automatically across tenants, and the previous setting will no longer control sharing behaviour.

For help identifying affected external users, reviewing permissions and improving Microsoft 365 guest governance, Northern Star’s managed IT support services in London can work through the transition with you. Call 0800 319 6032.

Focus on Modern Workforce Productivity and Security

Operating safely in today’s digital landscape requires a balance between seamless productivity and robust defence. At Northern Star, we optimize your operations using Microsoft Azure services in London and custom Microsoft 365 services in London, keeping your daily tools running flawlessly. We also help your team work smarter with Microsoft Copilot consulting in London and stay secure through practical cyber awareness training.

To protect your infrastructure, we deploy advanced email security services in London alongside proactive vulnerability management in London. Our continuous managed SOC services and rapid MDR services in London detect threats instantly. If an issue arises, our expert cyber incident response and dedicated business continuity services keep your organization running smoothly. Contact us to start.