Microsoft’s shift to Entra B2B brings external identity under one roof. For a multi-year partnership, that is the right architecture. For the five-minute document review that fills most of the workday, it is a governance lifecycle no one asked for. There is a third path.
In May 2026, Microsoft began moving external sharing in SharePoint Online and OneDrive from the SharePoint-managed One-Time Passcode experience to Microsoft Entra B2B, under Message Center notice MC1243549. One-time passcodes are not disappearing. The identity architecture behind them is. Recipients of “specific people” links are now represented by guest objects in the sharing organization’s Entra directory. Beginning in July 2026, recipients of older shares without a matching B2B guest object may hit access-denied errors until that object is created.
Microsoft’s reasoning is sound. Entra B2B brings external identities under one identity plane, extends Conditional Access coverage to guests, and enables real guest lifecycle management. Inside the tenant, that is exactly the right architecture.
Here is the tension: not all external collaboration is the same. The change treats every external share, from a five-minute document review to a five-year program, as the same kind of relationship, one that deserves a directory object, an invitation ceremony, and a governance lifecycle. When external parties need access to applications inside the organization, a guest is appropriate. For ad hoc sharing, it is friction that arrives at exactly the moment the business needs speed.
Not all external sharing is the same
External collaboration lives on a spectrum. Getting governance right starts with recognizing which scenario you are in.
Scenario 1: email is fine.
Some content is designed to leave: marketing collateral, published pricing, executed contracts, invoices. It is final, low-sensitivity, or intentionally public, and there is no case where you would take it back. Attaching it to an email is not a failure of governance. It is the point.
Scenario 2: ad hoc sharing is the gap most architectures miss.
The work is transient, but the content is sensitive: a draft agreement with outside counsel, an RFP response to a prospect, audit evidence for an external assessor, engineering specs sent to a supplier for a quote. These share three requirements: the data must not leave your control, access must be revocable, and setup should take minutes, not days. Under the new model, every one of these creates a guest object. The assessor who needed three documents for two weeks stays in your directory indefinitely unless a governance process removes them.
Scenario 3: extended collaboration warrants strong identity, not a guest for content.
A multi-year prime-and-subcontractor program, joint engineering with a design partner, an M&A workstream, a clinical trial with a CRO: these warrant verified organizational identity, MFA, and a defined lifecycle. A longer relationship does not make a guest account safer. It makes the exposure last longer. If the work is content collaboration, an eSHARE Trusted Share delivers strong authentication without the directory residue. Guests earn their place for application access: a Team membership, a line-of-business app, a role in a shared workflow. That is what Entra B2B was built for: membership, not documents.
The guest account problem, from a security chair
Every guest object in your directory is an identity relationship your security program now owns. At Scenario 3 scale, manageable. When every ad hoc share creates one, the math changes. Attack surface grows with every share. Dormancy is the default: the assessor finished in March, the losing supplier moved on in April, and their objects linger, invisible day to day but available to an attacker. Governance debt compounds: access reviews and entitlement management cost licensing, configuration, and attention.
So the rational response is to gate guest creation behind approval workflows. The account manager who needs an NDA-covered proposal in front of a prospect today waits three days. The deal does not wait. The user finds a workaround: personal Dropbox, a Gmail attachment, shadow IT. Static governance did not make the organization safer. It moved the sharing somewhere with no governance at all.
That is the impossible choice: slow down the business to govern every guest, or let guest accounts sprawl and absorb the risk. Neither is acceptable. Both are common.
The third option: Trusted Collaboration
Stop choosing between speed and control. You can have both.
Ad hoc external collaboration needs a purpose-built path, one where the data stays in M365 and access extends to external users through controlled paths. That is what eSHARE’s Trusted Collaboration Fabric provides:
- Governed, revocable Trusted Shares. External parties access data through BYOI-authenticated, time-limited links, signing in with the identity they already have: Entra, Google, whatever their organization runs. No guest account is created in your directory. Access is revocable instantly.
- Data stays in your tenant. No copies, no permanent attachments, no second source of truth. The document counsel reviews is the document in your library, with sensitivity labels enforced continuously.
- ABAC on every access. Policy is re-evaluated on every request against the attributes that matter: recipient identity, an NDA on file, sensitivity classification, time of access. Not a one-time gate at invitation. A continuous enforcement layer.
- Complete observability. Every share, view, and access is logged. When the assessor asks who accessed the evidence and when, the answer is generated, not assembled.
Map it back to the spectrum. Scenario 1 keeps email. Scenario 3 keeps guests where applications require them and moves content to Trusted Shares, shrinking the guest population to one the security team can govern. Scenario 2, the ad hoc majority, gets what it always needed: sharing that takes minutes, leaves no directory residue, works for any recipient identity, and stays under your control for its entire life.
Not every external share needs to create a guest. The ones that never did can stop.
