SharePoint OTP Retirement: Why External Sharing Is Becoming a Governance and Cost Problem
Every external file share your organization makes through SharePoint or OneDrive is about to leave a permanent trace in your corporate directory. That is not a hypothetical risk scenario, it is the mechanical result of a licensing and identity change Microsoft has already begun rolling out, and it lands in full by October 2026.
For years, sending a file to a supplier, auditor, or outside counsel through SharePoint Online could mean generating a one-time-passcode (OTP) link: the recipient typed in a code sent to their email or phone, opened the file, and never touched your identity infrastructure. That option is going away. Microsoft is retiring OTP-based external sharing and routing every external share through Entra B2B, which means each external recipient becomes a guest object inside your Entra corporate directory, tracked, licensed in some cases, and, if you want it governed, billed.
This is not framed by Microsoft as a security regression, and it is not one. Conditional Access, multi-factor authentication, and centralized audit logging for guests are genuine governance improvements over an anonymous passcode link. But the operational reality for IT, security, and compliance teams is that a process which used to create no directory footprint now creates one for every recipient, every time. Multiply that by however many contractors, auditors, patients, claimants, or supply chain partners your organization exchanges files with in a given year, and the scale of the shift becomes clear.
This post walks through exactly what is changing, why most organizations are underestimating how many guest identities they already carry, what the new governance model actually costs, and how a purpose-built external data exchange layer avoids the guest-sprawl problem entirely while still meeting the audit and compliance bar regulated organizations are held to.
Key Takeaways
1. OTP-based external sharing in SharePoint and OneDrive is being retired.
Phase 2 lands October 1-31, 2026 for most production tenants (GCC, GCC High, and DoD environments follow later), after which every external share creates an Entra B2B guest account with no opt-out.
2. Guest governance now carries a per-guest meter with no free tier.
Applying access reviews, lifecycle workflows, or entitlement management to a guest costs roughly $0.75 per governed guest per month, and that charge applies even within the 50,000 monthly-active-user free collaboration tier.
3. The identities pile up faster than most teams realize.
Years of ad-hoc file sharing already leave many tenants with two to four times more guest accounts than employees, and most of those “shadow guests” were never added to a team, group, or review cycle.
4. The licenses used to secure those guests got more expensive.
Entra ID P1 and P2, which provide the Conditional Access and Identity Protection features needed to govern external identities, both rose on July 1, 2026.
5. A governed external data exchange layer avoids the tradeoff.
Kiteworks lets external parties collaborate using their own business email, with no directory guest created, while still producing the audit trail and compliance evidence that regulated data exchange requires.
What’s Actually Changing in SharePoint External Sharing
Three separate Microsoft changes are landing close together, and each one compounds the others. None of them sounds dramatic on its own. Together, they reshape how much it costs, in dollars and in administrative labor, to share a file with someone outside your organization.
Start with the OTP retirement itself, covered in Message Center notification MC1243549. SharePoint Online’s one-time-passcode authentication for external sharing is being phased out. Phase 1 has already shipped: new external shares now route through Entra B2B rather than issuing a passcode link. Phase 2, rescheduled to run October 1-31, 2026 for standard commercial tenants, removes the opt-out entirely, so the tenant setting that currently lets organizations keep B2B integration off will simply stop doing anything. Government cloud environments (GCC, GCC High, and DoD) follow on a later timeline. After Phase 2, an external recipient without a matching guest account finds their existing OTP link stops working, quietly, with no notification to anyone.
Then there’s the guest governance meter, covered in MC1225192. Since January 30, 2026, applying premium governance to a guest account, whether that’s access reviews, lifecycle workflows, entitlement management approvals, or just marking a guest as “governed,” requires a linked Azure subscription and runs about $0.75 per governed guest per month. There’s no free allowance for this charge, even for tenants that stay under the 50,000 monthly-active-user threshold where basic guest collaboration itself remains free. Run quarterly access reviews across a guest population and that $0.75 charge repeats every quarter, per guest.
Finally, the licenses used to secure those guests got more expensive at the same time. Effective July 1, 2026, Entra ID P1 rose from roughly $6 to $7 per user per month and P2 rose from roughly $9 to $10, alongside related increases to the Microsoft 365 E3/E5 suites that bundle them. Those are the exact licenses that provide the Conditional Access policies, Identity Protection signals, and access review capabilities an organization needs to actually govern the guest population OTP retirement is about to create.
None of this is a ban on inviting external users, and it is worth being precise about that. Basic guest collaboration inside the 50,000-MAU tier remains free, and Microsoft has not capped how many guests a tenant can invite. What changed is narrower and, for most organizations, more consequential: the path of least resistance for external sharing now defaults to creating a directory identity, and doing anything more than the bare minimum with that identity now has a price tag attached.
What Are the Best Secure File Sharing Use Cases Across Industries?
The Shadow Guest Problem: Why Most Tenants Already Have More Guests Than Employees
The OTP retirement doesn’t create guest sprawl out of nothing, it exposes a problem many organizations already have and forces them to confront it on a deadline. Industry analysts covering Entra B2B adoption have repeatedly noted that tenants with years of ad-hoc external sharing history commonly carry two to four times more guest accounts than they have employees. Those accounts accumulate the way most unmanaged systems do: quietly, one file share at a time, with nobody assigned to clean them up.
Call these “shadow guests.” They were never added to a team, never scoped into a group-based access review, and in many cases were created for a single file exchange years ago and then forgotten. Standard access controls and governance tooling are built around guests who are visible in some administrative workflow, assigned to a project, a team, or a review cycle. A shadow guest, by definition, is invisible to that workflow until someone goes looking.
Phase 1 of the OTP retirement is already making the shadow guest problem worse in the background, because every new external share since that phase went live has created a guest object, whether or not anyone intended to build a managed guest population. By the time Phase 2 removes the opt-out in October 2026, tenants that haven’t actively inventoried their guest directory will be governing, or failing to govern, at a cost either way, a population considerably larger than the one they think they have.
This matters because data governance programs are typically built around known, cataloged assets and identities. A directory quietly carrying thousands of ungoverned guest accounts, each one a potential access point to a shared file or folder, is a governance gap that predates the OTP change and simply becomes unavoidable once it lands.
The Hidden Cost of Governing Guest Sprawl
Run the math on a mid-sized organization with 5,000 active external guest accounts, and the numbers stop looking like a rounding error. Governing that population under quarterly access reviews, a defensible cadence for any organization with compliance obligations around external access, means four review cycles a year at $0.75 per guest per cycle, or $3 per guest annually. At 5,000 guests, that’s $15,000 a year in governance billing alone, before counting the linked Azure subscription required to enable it, the Entra P1/P2 licenses needed to run Conditional Access on those identities, or the administrative time spent running the reviews.
Skip the paid governance tier to avoid that cost, and the alternative isn’t free either, it’s labor. Expiration, access reviews, and offboarding fall to administrators working by hand or scripting workarounds in PowerShell, which is a real option for cost-sensitive organizations but replaces a licensing cost with an ongoing engineering commitment that has to be maintained as Microsoft’s APIs and licensing model continue to evolve.
Either path, paying the meter or building the workaround, is a cost that scales with how much external collaboration an organization does. That is the structural issue: a governance model priced and administered per guest means the cost of doing business with outside parties grows every time the business grows its partner, client, contractor, or supplier relationships. For organizations already managing third-party risk management programs across large partner ecosystems, that is a cost curve worth modeling before the October window closes, not after.
Why This Is Also a Compliance Problem, Not Just a Licensing One
For regulated organizations, the guest governance shift isn’t only a budget line, it’s an audit exposure. Financial services, healthcare, life sciences, defense supply chain, and government contractors all share sensitive data externally as a matter of routine, and most of them answer to a compliance framework that specifies exactly how that access has to be authenticated, scoped, and logged.
SharePoint Online’s external sharing model produces logs, but those logs sit inside a broader Microsoft 365 audit subsystem that wasn’t purpose-built to serve as audit trail evidence for a CMMC assessment package, a HIPAA breach investigation, or a FedRAMP system security plan. SharePoint Online, notably, cannot itself carry a FedRAMP authorization, that gap doesn’t close no matter which sharing method a tenant uses. For organizations that need to produce complete, retained, and standardized evidence of who accessed what external data and when, a directory quietly filling with ungoverned shadow guests is exactly the kind of finding an assessor flags.
This is where the OTP retirement and the governance meter intersect with obligations under HIPAA compliance, GDPR, ISO 27001, and CMMC 2.0 compliance. Each of these frameworks expects least-privilege external access, defined data retention and expiration, and an audit trail an assessor can actually use as evidence, not a set of logs scattered across separate sharing, email, and collaboration subsystems that each retain data differently. A guest population that grew faster than anyone tracked it is a difficult thing to explain in an assessment interview.
A Different Model: Governed External Collaboration Without Guest Accounts
The alternative to choosing between guest sprawl and a per-guest governance bill is to not generate the guest identity in the first place for routine external sharing. That is the design point behind Kiteworks secure data exchange: external recipients authenticate and collaborate using their own business email, managed in Kiteworks’ own directory rather than the customer’s Entra corporate directory, so ordinary file sharing does not create a governed identity that has to be licensed, reviewed, and eventually cleaned up.
One-off and infrequent recipients still authenticate the way many organizations rely on today, an SMS or email passcode, so processes built around passcode-based access keep working even after SharePoint’s own OTP option disappears. Every share carries expiration, least-privilege defaults, and built-in lifecycle cleanup, governed through a central policy set rather than a per-guest meter. That policy layer combines ABAC with more familiar RBAC folder-level controls, so access decisions can key off data sensitivity and recipient attributes, not just static folder permissions.
Every external interaction, file sharing, secure email, managed file transfer, and API-driven exchange, lands in one standardized, immutable audit log rather than separate logs per subsystem, which is precisely the kind of complete, retained evidence that CMMC, HIPAA, GDPR, and ISO 27001 assessments look for. Organizations that need to keep control of the underlying data can pair that with customer-controlled encryption keys and deployment on a hardened virtual appliance on-premises, in a single-tenant cloud instance, or air-gapped, with upgrade and maintenance windows the organization controls rather than a vendor-driven rollout landing on a date it didn’t pick.
None of this requires abandoning Microsoft 365. A native Microsoft Office 365 plugin and a repository gateway back to SharePoint and OneDrive mean internal work continues unchanged in the tools people already use, while external exchange moves to a layer designed for it from the start. For organizations that also exchange unusually large files, CAD files, imaging data, research datasets, that same layer removes the size-cap pressure that otherwise pushes users toward unsanctioned workarounds like consumer file-sharing tools. And where a file needs to stay reviewable but never actually change hands, possessionless editing lets an external party work on a document without ever holding a copy of it.
The proof points that matter for a compliance-driven evaluation are worth stating plainly: FedRAMP High authorization is in process, building on FedRAMP Moderate authorization maintained continuously since 2017, alongside FIPS 140-3 validated encryption, SOC 2 Type II, and support for 90% of CMMC Level 2 requirements out of the box. Sector-specific programs for financial services, healthcare, and government organizations build on the same underlying zero trust architecture, so the governance model doesn’t have to be rebuilt industry by industry.
What to Do Before the October 2026 Deadline
Organizations still relying on OTP-based SharePoint links have a narrowing window to act.
Start with an inventory. Most tenants have never run a full accounting of the shadow guests created by years of ad-hoc sharing, and that inventory is the only way to size the actual exposure, both the governance cost under the $0.75-per-guest meter and the compliance risk of accounts nobody has reviewed. From there, identify which external recipients still depend on OTP links that will break silently once Phase 2 retires the fallback, and migrate or notify them proactively rather than finding out through a support ticket from an outside partner. The harder call is deciding, deliberately, which external sharing should stay inside Microsoft 365 as an Entra B2B guest relationship, a reasonable fit for ongoing, recurring collaboration with known partner organizations, and which sharing belongs on a governed secure file sharing layer that doesn’t generate a directory footprint for one-off or high-volume external exchange.
That third decision matters most, because it determines whether guest governance costs keep scaling with the business or get contained now. Organizations with a Microsoft 365 renewal falling shortly after July 1, 2026 have a natural moment to make that call as part of the renewal conversation, modeling the deferred cost of a governed external layer against the compounding cost of a guest population that keeps growing on its own.
To learn more about keeping external collaboration governed and predictable ahead of the October 2026 OTP retirement, schedule a custom demo today.
Frequently Asked Questions
Microsoft is retiring one-time-passcode (OTP) authentication for external sharing in SharePoint Online and OneDrive. Phase 1 already routes new external shares through Entra B2B; Phase 2, which removes the ability to opt out, runs October 1-31, 2026 for most commercial production tenants, with GCC, GCC High, and DoD environments following on a later schedule. After Phase 2, every external share creates a guest identity in the organization’s Entra corporate directory, and existing OTP links to recipients without a matching guest account stop working. Treat it as a fixed deadline on the same calendar as any other regulatory compliance date, not a footnote in a Microsoft admin bulletin.
No. Basic guest collaboration remains free within the 50,000 monthly-active-user tier, and there is no cap on how many external users a tenant can invite. What changed is that ordinary external sharing now defaults to creating a directory guest identity where OTP previously created none, and applying premium governance, access reviews, lifecycle workflows, entitlement management, to those guests carries a per-guest charge with no free allowance. The shift is about governance and identity architecture, not access restriction. Organizations evaluating audit trail requirements should treat this as a directory-management question first.
Governance billing runs approximately $0.75 per governed guest per month, applied whenever a tenant uses premium governance features, access reviews, lifecycle workflows, or entitlement management, on a guest account, and it requires a linked Azure subscription with no free tier. A tenant running quarterly access reviews pays that charge four times a year per guest reviewed. Layer on the July 1, 2026 increases to Entra ID P1 (roughly $6 to $7 per user per month) and P2 (roughly $9 to $10), which provide the Conditional Access and Identity Protection features used to secure those guests, and the total cost of governing a large external population grows quickly. Organizations can model this against a Kiteworks secure MFT or secure file sharing deployment to compare predictable licensing against a per-guest meter.
Skipping the governance meter doesn’t eliminate the guest population, it just shifts the work. Expiration, periodic access reviews, and offboarding fall to administrators managing accounts by hand or maintaining PowerShell scripts to replicate governance actions outside Microsoft’s paid tier. That approach can control direct licensing costs, but it substitutes ongoing administrative labor and leaves the underlying data governance gap in place: a directory that keeps accumulating shadow guests from ad-hoc sharing, with no unified policy or audit log covering how those accounts were used.
Kiteworks manages external recipients in its own directory rather than the customer’s Entra corporate directory, so a partner, client, or contractor authenticates with their own business email, or an SMS/email passcode for one-off access, without becoming a licensed, governed identity inside the customer’s tenant. Every share still carries expiration, least-privilege defaults, and lifecycle cleanup, enforced through central policy and captured in one immutable audit log, which is what regulated organizations need for CMMC 2.0 compliance and similar frameworks. A native Microsoft Office 365 plugin and repository gateway keep internal Microsoft 365 workflows unchanged while external exchange moves to this governed layer.
Additional Resources