From July 2026, every file you share externally through SharePoint creates a guest account you have to govern.
Microsoft is retiring One-Time Passcodes for external sharing in SharePoint Online and OneDrive for Business. Existing sharing links stop working, and every new external recipient becomes an identity in your directory. The migration work is unavoidable. The question is whether your most sensitive external exchanges should be rebuilt on the same architecture.
Microsoft is consolidating external sharing onto Entra B2B guest accounts
Microsoft 365 message center notification MC1243549 (March 2026) confirmed the final step in a transition that began in 2021: One-Time Passcodes are being removed from SharePoint Online and OneDrive for Business. From now on, sharing a file or folder with someone outside your organisation automatically creates a guest account for them in your Entra ID directory.
Microsoft's rationale is legitimate. Guest accounts support auditing, conditional access policies, and domain-level controls that OTP never could. This page is not an argument that SharePoint became less secure. It is an accounting of what the new model costs to run, and what it reveals about the architecture underneath.
External sharing is now an identity management program
Under the new model, a quick external share is no longer a lightweight action. It creates a standing identity that must be sponsored, reviewed, expired, and in many cases licensed. Microsoft's own recommended governance framework sets out the minimum.
Guest account proliferation
Every external recipient becomes an Entra guest object with implicit tenant exposure. The population grows in direct proportion to how much your organisation shares.
Licensed governance
Cleaning up stale guests via Entra ID access reviews requires premium licensing. Sponsors, B2B policies, and expiration policies all need standing administration.
Usage-based cost at scale
Premium guest features beyond the free monthly active user allowance move to consumption billing through an Azure subscription.
Broken continuity
Links embedded in long-running matters must be found, reissued, and re-communicated. External recipients face invitation redemption and, depending on your policies, MFA enrolment.
Sources: Microsoft 365 message center notification MC1243549 via Microsoft 365 for IT Pros (March 2026); Microsoft Learn, Entra External ID pricing and access reviews documentation.
The change surfaces what external sharing in SharePoint has always been
SharePoint's sharing model was designed for collaboration inside one organisation and extended outward. The consequences are well documented. Three of the four sharing link types create unique item-level permissions that override site permissions. Forwarded links grant access to new recipients by default. Across more than 700 enterprise tenant security reviews, EPC Group reports an average of 150 to 300 overshared SharePoint sites per tenant, with 40 to 60 percent of sites showing at least one oversharing pattern.
Microsoft 365 Copilot has removed the last natural safeguard: content a user technically had access to but would never have found is now surfaced by a natural language prompt. Microsoft's own Purview documentation acknowledges that generative AI amplifies oversharing and now ships dedicated risk assessment tooling to remediate exposure before Copilot rollout.
The sharpest question a security-conscious buyer can ask any platform: what can the platform itself see?
SharePoint's answer, by design, is that Microsoft's services process content in plaintext. That is what powers search, Copilot, and eDiscovery, and it is a deliberate trade-off. DekkoCORE's answer is different by architecture: content is end-to-end encrypted on the user's device, and no one, including DekkoSecure and its cloud providers, can see user data. For PROTECTED-level government work, law enforcement material, and legally privileged content, this is frequently the deciding criterion.
External sharing: SharePoint Online and DekkoCORE compared
Every SharePoint claim below is drawn from Microsoft's own documentation or independent reporting. Every DekkoCORE claim is published on our security and compliance pages and independently tested.
| Dimension | SharePoint Online | DekkoCORE |
|---|---|---|
| Encryption model |
Microsoft manages the keys Service-side encryption; content is processed in plaintext to enable search, Copilot, and eDiscovery. |
End-to-end encryption on every file Encrypted on the user's device (AES-256, ECC-384 key pairs); each file is individually encrypted. |
| Vendor access to content |
The platform can read your content Access is technically possible by design. |
No one can see your data, not even DekkoSecure Zero-knowledge architecture; decryption keys never leave customer control. |
| External sharing model |
Every recipient becomes a guest in your directory Each guest identity requires ongoing lifecycle governance. |
Sharing without directory sprawl External parties join an encrypted workspace built for cross-organisation sharing; no guest objects accumulate. |
| Governance overhead |
Safety is assembled across six admin surfaces B2B policies, conditional access, sensitivity labels, DLP, expiration policies, and access reviews (Entra P1). |
Safety is built in Explicit access, expiry dates, and auditing are native functions; no key management falls on users. |
| Oversharing surface |
Links can outrun their audience Sharing links create unique item-level permissions; forwarding grants access to new recipients by default. |
Access is explicit, always Only named, authorised users can decrypt content. There is no "anyone with the link" equivalent. |
| Audit |
Audit exists, with documented visibility gaps Comprehensive review typically involves Purview and additional tooling. |
Tamper-proof record of every action Views, downloads, and shares recorded for compliance and defensible accountability. |
| Sovereignty and jurisdiction |
Residency options, vendor jurisdiction Content remains technically accessible to the platform operator and subject to the legal regimes applying to Microsoft. |
Jurisdiction-bound by architecture Sovereign hosting in Australia, Canada, the United States, and Switzerland; data visible only to authorised users. |
| Cost to operate safely |
Governance is a licensing tier Entra P1/P2, Purview, and E5-tier features, plus MAU billing at scale. |
Security is a property of the platform No premium tier is required to be safe. |
Where SharePoint remains the right tool
We are not suggesting you replace SharePoint.
For collaboration inside a single Microsoft 365 tenant, with intranet, document management, Teams integration, and co-authoring across the Office suite, SharePoint is a capable and deeply integrated platform. Organisations invested in Microsoft 365 should keep using it for what it does well.
The gap is specific: sensitive information crossing organisational boundaries. That is precisely where SharePoint's architecture carries the most cost, in guest governance, vendor-readable content, and oversharing surface, and it is exactly what DekkoCORE was built for. The strongest deployment pattern is complementary: SharePoint for general internal collaboration, DekkoCORE for the external exchanges where end-to-end encryption, sovereignty, and defensible auditability are non-negotiable.
Claims you can check
IRAP assessed at PROTECTED
DekkoSecure's Australian environment is independently assessed against the ISM at PROTECTED level under IRAP.
Independently tested claims
Security claims tested by Enex TestLab and the platform independently penetration tested.
End-to-end encrypted by default
Files, messages, eSignatures, and video meetings encrypted on the user's device. No configuration required to be safe.
Sovereign hosting options
Data sovereignty options in Australia, Canada, the United States, and Switzerland, keeping data jurisdiction-bound.
The migration work is happening either way. Make it count.
Download the complete comparison analysis, or talk to us about your external sharing workflows before the August 31 deadline.
The full document covers everything on this page in depth, with sources throughout:
- The complete OTP retirement timeline and its operational consequences
- The guest governance framework Microsoft recommends, and what it requires in licensing and administration
- SharePoint's structural pain points: oversharing mechanics, Copilot amplification, the encryption model, and the 2025 ToolShell campaign in accurate context
- A thirteen-dimension comparison against DekkoCORE, every claim sourced
- Guidance on the complementary deployment model
Download the comparison analysis
PDF, sent to your work email.
SharePoint external sharing change: FAQ
What exactly is changing with SharePoint external sharing in 2026?
Microsoft is retiring One-Time Passcodes (OTP) for external sharing in SharePoint Online and OneDrive for Business. From May 2026, new external invitations use Entra B2B Collaboration guest accounts. From July 2026, existing OTP links stop working and must be recreated. Microsoft expects the retirement to be effective across commercial, government, and sovereign clouds by August 31, 2026.
Will our existing sharing links break?
If they used OTP authentication, yes. Those links fail from July 2026 due to lack of authentication. Affected workflows need to be identified, counterparties notified, and links reissued. New links automatically create guest accounts for recipients in your Entra ID directory.
What does governing guest accounts actually involve?
Microsoft's recommended framework includes a B2B Collaboration policy governing allowed domains, sponsor assignment for accountability, Entra ID access reviews to remove stale guests (which require Entra P1 licensing), site-level expiring access policies, and inactive guest reporting. Entra ID includes 50,000 free monthly active guest users, with monthly active user billing for premium features beyond that.
Is DekkoCORE a replacement for SharePoint?
No. SharePoint remains a capable platform for internal collaboration inside a Microsoft 365 tenant. DekkoCORE is purpose-built for the specific gap: sensitive information crossing organisational boundaries. Most customers run both, using DekkoCORE for the external exchanges where end-to-end encryption, sovereignty, and defensible auditability are non-negotiable.
How is DekkoCORE's security verified?
DekkoSecure's Australian environment is IRAP assessed at PROTECTED level against the ISM. The platform's security claims have been independently tested by Enex TestLab, and the platform is independently penetration tested. All content is end-to-end encrypted on the user's device, and DekkoSecure's zero-knowledge architecture means neither DekkoSecure staff nor the underlying cloud providers can see user data.











