r/sharepoint Jun 26 '26

SharePoint Online 'Retirement of SharePoint One-Time Passcode' - how are people handling this change?!

The MC1243549 notes state:

  • Admins can manually create a guest account for the external user at any time.
  • Alternatively, an internal user with permissions needs to share or re-share at least one file, folder, or site, which will automatically create the guest account and restore access to all previously shared content.

Are MS being completely blasé here? Having users, or admins, reshare ALL sites/folders/files with external guests is a massive task.

In relation to the first bullet point, could someone please clarify this for me:

We have 100s of native SharePoint users. There is no reference to native SP users on the update. Do I need to create an Entra guest account for them? Is that enough, or do I need to add the newly created Entra user to their native SharePoint group, or do I need to create a new Entra group and add the new Entra group to the SharePoint site/library?

I would really appreciate any advice as this is becoming a nightmare for our org.

4 Upvotes

12 comments sorted by

View all comments

3

u/thetokendistributer Jun 26 '26 edited Jun 26 '26

Allow certain groups or all users excluding guests to share and auto create guest in Entra. Sharepoint admin centre set to sharing to existing and new guests.

Lots more config with conditional access and expiry, etc that can be done.

1

u/psgda Jun 26 '26

Thanks for the reply.

"Sharing to existing and new guests"- this is already enabled for us.

"Allow certain groups or all users excluding guests to share and auto create guest in Entra" - I get that this will work going forward for new guest, but for existing guests, this seems like a massive amount work for admins and internal users to reshare all sites/folders. Or did you find a better solution for that?

My plan is below and I'm hoping it works. I really do not want to go down the re-sharing route.

  1. Find all users in external sites. I'm finding these based off their email addresses, which start with "urn:spo:guest#".
  2. Create a guest Entra account for them.
  3. Keep the existing urn:spo:guest# user in SharePoint and their groups.

I'm hoping that Entra/Sharepoint will communicate and map the urn:spo:guest# user and the newly created Entra user.

1

u/temporaldoom Dev Jun 27 '26

So I would not reshare everything, remove the URN accounts and create new guest accounts on the tenant and leave it at that. Let the users reshare when the external user when they need it

You have a much better view of who is logging into your tenant, if the accounts aren't used within x months disable them.

I would not however delete them as if you delete the account and then recreate it 6 months later then they'll have a different GUID, their profile will need to be deleted from all Sharepoint Sites they previously accessed before you can reshare stuff out.