Jul 20, 2026

Microsoft’s External Collaboration Changes Should Be a Wake-Up Call for Every CISO

Microsoft has announced two major changes that, viewed independently, may look like routine security modernization.

Viewed together, they represent a looming identity and external-collaboration challenge for every large enterprise using Microsoft 365.

First, Microsoft is moving Entra users away from SMS and voice authentication and toward passkeys. Beginning September 1, 2026, users enabled for SMS or voice authentication will be automatically brought into Microsoft’s passkey registration campaign. On February 1, 2027, Microsoft-provided SMS and voice authentication will be retired.

Second, Microsoft is retiring the legacy SharePoint Online one-time-passcode authentication experience and moving external sharing in SharePoint and OneDrive to Microsoft Entra B2B.

The security rationale behind both decisions is understandable.

The combined operational impact could be a nightmare.

What Microsoft Is Changing

Microsoft has effectively put an expiration date on SMS and voice MFA.

Beginning September 1, 2026, Entra users who are enabled for SMS or voice authentication will be automatically enabled for passkeys and targeted by Microsoft-managed registration campaigns.

On February 1, 2027, Microsoft will stop providing native SMS and voice authentication. Organizations that still require telephone-based authentication will need to contract with a telecommunications provider through the Microsoft Security Store.

Microsoft is making a clear statement: phishable authentication methods are no longer an acceptable long-term foundation for enterprise identity security.

That direction is overdue.

SMS and voice authentication helped move enterprises beyond passwords, but they remain vulnerable to phishing, social engineering, SIM swapping, interception, account-recovery attacks and other techniques that increasingly sophisticated attackers know how to exploit.

Passkeys use public-key cryptography and are resistant to the credential-harvesting techniques behind many modern account compromises.

But this is not simply an MFA migration.

It becomes much more complicated when external users and B2B guest identities are involved.

The Other Change: External Sharing Now Creates an Identity Problem

Microsoft is also transitioning external authentication for SharePoint and OneDrive from the legacy SharePoint OTP system to Microsoft Entra B2B.

There is an important distinction here.

Microsoft is not eliminating email one-time passcodes entirely. External users who cannot authenticate through an Entra work account, Microsoft account or another supported identity provider can still receive an email OTP.

What is changing is the identity architecture behind that experience.

Under the legacy SharePoint OTP model, an external recipient could access specifically shared content after proving control of the email address. A persistent Entra B2B guest account was not necessarily required.

Under the new model, external authentication is handled through Microsoft Entra B2B. When content is shared externally, the recipient becomes a guest identity in the host organization’s Entra tenant—even when that person ultimately authenticates using an email OTP.

That means a seemingly simple action such as sharing a document can now create another identity object that the enterprise must govern, secure, review, support and eventually remove.

Because files shared through Microsoft Teams are generally stored in SharePoint or OneDrive, this change extends beyond users who think of themselves as “SharePoint users.” It affects a significant portion of external document collaboration taking place through Microsoft 365.

Microsoft began transitioning new external-sharing invitations to Entra B2B in May 2026, with retirement of the legacy SharePoint OTP model beginning in July 2026. Microsoft says organizations cannot opt out of the transition.

Two Changes, One Converging Problem

These two initiatives collide directly around B2B guest accounts.

Large enterprises may have tens or hundreds of thousands of contractors, suppliers, customers, advisers and business partners represented as guest identities across their Microsoft 365 environments.

At the same time, their own employees may be registered as guests in dozens—or even hundreds—of customer and partner tenants.

Now add a fundamental authentication migration.

Every external identity may have a different:

  • Home identity provider
  • Authentication-method policy
  • Conditional Access configuration
  • Passkey implementation
  • Device-management policy
  • Browser or operating-system configuration
  • Credential-recovery process
  • Security maturity level
  • Help desk—or no help desk at all

The organization hosting the content may control the resource tenant and its Conditional Access policies.

It usually does not control the guest’s home tenant, endpoint, authentication configuration or support organization.

This creates a fragmented responsibility model in which every party controls one piece of the authentication chain, but no one necessarily owns the complete user experience.

The Contractor and Partner Support Nightmare

Consider a contractor who has access to several Teams workspaces and SharePoint sites inside a large enterprise.

The contractor may already have:

  • A home account issued by an employer
  • One or more guest identities in the enterprise’s Entra tenant
  • Additional guest identities belonging to the enterprise’s subsidiaries
  • Different guest identities created from aliases or historical email addresses
  • Multiple Microsoft Authenticator registrations
  • Credentials tied to personal and corporate devices
  • Access granted directly, through a group or through a Teams membership

Now the contractor encounters a mandatory passkey-registration prompt.

Which identity is being registered?

Which organization’s policy is being enforced?

Is the passkey synchronized or device-bound?

Is a personal device permitted?

What happens when the contractor changes employers, email addresses or phones?

Who helps when the credential is lost?

Does the contractor call the home employer, the enterprise help desk, the project manager, the Microsoft 365 team or the identity team?

The authentication failure may involve four independently managed components:

  1. The contractor’s home identity
  2. The enterprise’s guest identity
  3. The contractor’s device and credential provider
  4. The SharePoint, OneDrive or Teams resource being accessed

This is not an edge case.

For global enterprises with large supply chains, project-based workforces, acquisitions, joint ventures and regulated data-sharing requirements, it can become the normal operating model.

Your Employees Are Someone Else’s Guests

The problem is also bidirectional.

Enterprises tend to focus on the contractors and partners accessing their own tenant. But their employees are simultaneously guest users in other organizations’ tenants.

A sales executive may be a guest in several customer Teams environments.

An engineer may access SharePoint sites operated by suppliers, aerospace partners or government contractors.

An attorney may participate in collaboration spaces operated by outside counsel.

A consultant may work across dozens of client tenants.

Each resource tenant can impose its own authentication, Conditional Access, device-compliance and session-management policies.

Your IT organization may have carefully designed a passwordless strategy for your employees, but those employees can still be subjected to registration prompts and access requirements imposed by organizations you do not control.

When access fails, they will still call your help desk.

Your team may then be expected to troubleshoot an authentication journey occurring inside someone else’s Entra tenant, governed by someone else’s policies, involving a guest identity your administrators may not be able to see.

This is one of the least understood costs of tenant-to-tenant B2B collaboration.

The True Cost of “Free” B2B Guest Accounts

Microsoft B2B guest accounts are frequently treated as free.

The license cost may be low or nonexistent for many common scenarios.

The operating model is not free.

Every guest identity can introduce some combination of:

  • Identity provisioning and invitation management
  • Group and Teams membership administration
  • Conditional Access evaluation
  • Authentication-method support
  • Access reviews
  • Entitlement management
  • Sponsor or owner assignment
  • Duplicate-account resolution
  • Stale-account discovery
  • Dormant-access removal
  • Audit and compliance reporting
  • Data-access investigation
  • Help-desk incidents
  • Offboarding and lifecycle management

Enterprises also need to determine whether a guest still works for the same supplier, still supports the same project and still has a legitimate business need for access.

The guest’s home organization may terminate the user’s original account, but that does not automatically mean every resource tenant has correctly removed every corresponding entitlement, direct permission, sharing link and group membership.

Even where Microsoft provides tools to address these problems, those tools must be licensed, configured, operated and monitored.

The word “free” describes the initial account creation—not the total cost of governing the identity throughout its lifecycle.

AI Raises the Stakes

AI makes this issue even more urgent.

Identity is becoming the control plane not only for human users, but also for AI assistants, autonomous agents and applications capable of discovering and processing information at machine speed.

A compromised external identity may no longer result in a person manually browsing a few files.

It could allow an attacker or malicious agent to rapidly enumerate accessible sites, identify sensitive content, summarize documents, correlate information and extract valuable data at a scale that would previously have required significant time and effort.

At the same time, Microsoft 365 Copilot and other enterprise AI systems increase the importance of accurate permissions and identity hygiene.

AI does not fix overexposure.

It makes overexposure easier to discover and exploit.

Enterprises therefore need to ask whether creating a persistent guest identity inside the corporate tenant is appropriate for every external file-sharing and collaboration use case.

In many cases, it is not.

Not Every External Collaborator Needs an Identity in Your Tenant

B2B guest accounts remain appropriate for some scenarios.

A long-term joint-venture participant working deeply within a shared Teams workspace may require a persistent identity, group memberships and application access.

A contractor performing an internal operational role may need access that closely resembles employee access.

But many external-collaboration scenarios are much narrower:

  • Sending a large file to a customer
  • Collecting documents from a supplier
  • Sharing a controlled project folder
  • Requesting feedback on a document
  • Exchanging regulated technical data
  • Collaborating with an outside adviser
  • Maintaining a secure external deal room
  • Providing time-limited access to a specific data set

These interactions do not necessarily justify placing another persistent identity inside the enterprise tenant.

The architecture should follow the business interaction—not force every external interaction into an internal identity model.

Enterprises should distinguish between access to the corporate environment and secure collaboration with the corporation.

Those are not the same requirement.

What CISOs Should Do Now

The February 1, 2027 deadline may appear distant.

It is not.

Large-enterprise identity migrations require discovery, policy design, pilot programs, user communication, application testing, support preparation, exception handling and phased rollout.

B2B environments add another level of difficulty because many of the affected users and devices are not controlled by the enterprise.

CISOs should begin by answering several questions:

1. How dependent are we on SMS and voice?

Identify employees and guests who rely on SMS or voice for MFA, self-service password reset or account recovery.

Do not limit the assessment to employees.

2. How many B2B guest identities do we have?

Count active, inactive, duplicated, unredeemed and stale guest accounts across production tenants.

Then determine how many guests have direct permissions, Teams memberships, group memberships and access to sensitive SharePoint sites.

3. Which guests can realistically adopt passkeys?

Segment guests by relationship, device ownership, home identity provider, geography, risk and support model.

A strategic technology partner and a temporary construction contractor may require very different migration plans.

4. How will external-user recovery work?

Define who owns recovery when a guest loses a device, cannot register a passkey or is blocked by a cross-tenant authentication conflict.

“Call the help desk” is not a strategy when neither help desk controls the entire transaction.

5. Where are our own employees registered as guests?

Enterprises need visibility into the other organizations and tenants in which employees collaborate.

This is difficult, but ignoring the outbound side of B2B dependency leaves half the problem unaddressed.

6. Which collaboration scenarios truly require guest accounts?

Classify external interactions by business purpose and technical requirement.

Use persistent B2B identities where they are justified—not by default.

7. What can be migrated to a purpose-built external-collaboration model?

Evaluate approaches that allow external parties to collaborate securely without placing every recipient inside the corporate Entra directory.

The goal is not merely to replace one login screen with another. It is to reduce the number of external identities, permissions and lifecycle dependencies the enterprise must continuously govern.

The Wake-Up Call

Microsoft’s strategy is directionally correct.

Phishing-resistant authentication is necessary.

Centralizing external authentication in Entra can provide stronger Conditional Access, governance and audit consistency than the legacy SharePoint OTP system.

But stronger individual controls do not automatically produce a simpler operating model.

Microsoft is simultaneously:

  • Increasing the number of external-sharing scenarios that create Entra B2B guest identities
  • Moving those identities toward a more sophisticated authentication model
  • Retiring Microsoft-provided SMS and voice authentication
  • Leaving enterprises responsible for managing the resulting identity lifecycle, migration and support complexity

For large organizations, that combination should be a wake-up call.

This is not simply a passkey deployment.

It is an opportunity—and a deadline—to reconsider the architecture of external collaboration.

Enterprises should stop assuming that every contractor, supplier, customer and partner needs an identity inside their Microsoft 365 tenant.

They should reduce unnecessary guest accounts, clean up the guest identities they retain and move appropriate collaboration workloads to models designed specifically for secure external participation.

February 2027 is just around the corner in enterprise-program terms.

Organizations that have not started discovering their SMS dependency, guest population, external-sharing exposure and migration options are not preparing early.

They are already behind.

Microsoft References

Nick Stamos

Download Mark Cassetta's Presentation

Build Bridges, Not Barriers:
Achieving Trusted Collaboration in the AI Era

Contact Us

Fill in the form and download the full comparison datasheet.

Better collaboration.
Higher productivity.
Better employee and client engagement.

Transform the way you collaborate. Contact eSHARE to get started.

Schedule a Demo