Skip to content
Screenshot 2026-05-07 at 10.24.10 am
DekkoCORE
File Sharing & Collaboration
Screenshot 2026-05-11 at 12.13.50 pm
DekkoDEMS
Digital Evidence Management
Two products. One secure platform.
DekkoCORE and DekkoDEMS both feature:

  Web-based app with no installs

  End-to-end encrypted security

  No file size or type restrictions

  Easy account creation process

  Comprehensive sharing controls

Law Enforcement
Securely collect and share digital evidence across agencies with full chain-of-custody.
law-enforcement
Defence Supply Chain
Protect classified designs and supplier data in a sovereign, fully encrypted workspace.
defence
National Security
Enable secure inter-agency intelligence collaboration with controlled encrypted access.
national-sec
Judiciary Departments
Exchange case files and evidence securely with clients and prosecutors without risk.
legal
Professional Services
Collaborate on client documents and financial data securely on a trusted platform.
prof-services
Healthcare
Share medical records and research securely across clinics and partners with compliance.
health

Not in this list? DekkoSecure is used anywhere sensitive data needs to be shared and controlled.

The July 2026 SharePoint External Sharing Change | DekkoSecure

From July 2026, every file you share externally through SharePoint creates a guest account you have to govern.

Microsoft is retiring One-Time Passcodes for external sharing in SharePoint Online and OneDrive for Business. Existing sharing links stop working, and every new external recipient becomes an identity in your directory. The migration work is unavoidable. The question is whether your most sensitive external exchanges should be rebuilt on the same architecture.

Microsoft is consolidating external sharing onto Entra B2B guest accounts

Microsoft 365 message center notification MC1243549 (March 2026) confirmed the final step in a transition that began in 2021: One-Time Passcodes are being removed from SharePoint Online and OneDrive for Business. From now on, sharing a file or folder with someone outside your organisation automatically creates a guest account for them in your Entra ID directory.

Microsoft's rationale is legitimate. Guest accounts support auditing, conditional access policies, and domain-level controls that OTP never could. This page is not an argument that SharePoint became less secure. It is an accounting of what the new model costs to run, and what it reveals about the architecture underneath.

Timeline: May 2026 new invitations use guest accounts. July 2026 OTP links stop working. August 31, 2026 retirement effective across all clouds. May 2026 New external invitations use guest accounts July 2026 Existing OTP links fail; links must be recreated WE ARE HERE August 31, 2026 Retirement effective across all Microsoft 365 clouds

External sharing is now an identity management program

Under the new model, a quick external share is no longer a lightweight action. It creates a standing identity that must be sponsored, reviewed, expired, and in many cases licensed. Microsoft's own recommended governance framework sets out the minimum.

1 share= 1 directory identity

Guest account proliferation

Every external recipient becomes an Entra guest object with implicit tenant exposure. The population grows in direct proportion to how much your organisation shares.

Entra P1required for access reviews

Licensed governance

Cleaning up stale guests via Entra ID access reviews requires premium licensing. Sponsors, B2B policies, and expiration policies all need standing administration.

50,000free guest MAU, then billing

Usage-based cost at scale

Premium guest features beyond the free monthly active user allowance move to consumption billing through an Azure subscription.

July 2026every OTP link fails

Broken continuity

Links embedded in long-running matters must be found, reissued, and re-communicated. External recipients face invitation redemption and, depending on your policies, MFA enrolment.

Sources: Microsoft 365 message center notification MC1243549 via Microsoft 365 for IT Pros (March 2026); Microsoft Learn, Entra External ID pricing and access reviews documentation.

The change surfaces what external sharing in SharePoint has always been

SharePoint's sharing model was designed for collaboration inside one organisation and extended outward. The consequences are well documented. Three of the four sharing link types create unique item-level permissions that override site permissions. Forwarded links grant access to new recipients by default. Across more than 700 enterprise tenant security reviews, EPC Group reports an average of 150 to 300 overshared SharePoint sites per tenant, with 40 to 60 percent of sites showing at least one oversharing pattern.

Microsoft 365 Copilot has removed the last natural safeguard: content a user technically had access to but would never have found is now surfaced by a natural language prompt. Microsoft's own Purview documentation acknowledges that generative AI amplifies oversharing and now ships dedicated risk assessment tooling to remediate exposure before Copilot rollout.

The sharpest question a security-conscious buyer can ask any platform: what can the platform itself see?

SharePoint's answer, by design, is that Microsoft's services process content in plaintext. That is what powers search, Copilot, and eDiscovery, and it is a deliberate trade-off. DekkoCORE's answer is different by architecture: content is end-to-end encrypted on the user's device, and no one, including DekkoSecure and its cloud providers, can see user data. For PROTECTED-level government work, law enforcement material, and legally privileged content, this is frequently the deciding criterion.

External sharing: SharePoint Online and DekkoCORE compared

Every SharePoint claim below is drawn from Microsoft's own documentation or independent reporting. Every DekkoCORE claim is published on our security and compliance pages and independently tested.

Dimension SharePoint Online DekkoCORE
Encryption model

Microsoft manages the keys

Service-side encryption; content is processed in plaintext to enable search, Copilot, and eDiscovery.

End-to-end encryption on every file

Encrypted on the user's device (AES-256, ECC-384 key pairs); each file is individually encrypted.

Vendor access to content

The platform can read your content

Access is technically possible by design.

No one can see your data, not even DekkoSecure

Zero-knowledge architecture; decryption keys never leave customer control.

External sharing model

Every recipient becomes a guest in your directory

Each guest identity requires ongoing lifecycle governance.

Sharing without directory sprawl

External parties join an encrypted workspace built for cross-organisation sharing; no guest objects accumulate.

Governance overhead

Safety is assembled across six admin surfaces

B2B policies, conditional access, sensitivity labels, DLP, expiration policies, and access reviews (Entra P1).

Safety is built in

Explicit access, expiry dates, and auditing are native functions; no key management falls on users.

Oversharing surface

Links can outrun their audience

Sharing links create unique item-level permissions; forwarding grants access to new recipients by default.

Access is explicit, always

Only named, authorised users can decrypt content. There is no "anyone with the link" equivalent.

Audit

Audit exists, with documented visibility gaps

Comprehensive review typically involves Purview and additional tooling.

Tamper-proof record of every action

Views, downloads, and shares recorded for compliance and defensible accountability.

Sovereignty and jurisdiction

Residency options, vendor jurisdiction

Content remains technically accessible to the platform operator and subject to the legal regimes applying to Microsoft.

Jurisdiction-bound by architecture

Sovereign hosting in Australia, Canada, the United States, and Switzerland; data visible only to authorised users.

Cost to operate safely

Governance is a licensing tier

Entra P1/P2, Purview, and E5-tier features, plus MAU billing at scale.

Security is a property of the platform

No premium tier is required to be safe.

Where SharePoint remains the right tool

We are not suggesting you replace SharePoint.

For collaboration inside a single Microsoft 365 tenant, with intranet, document management, Teams integration, and co-authoring across the Office suite, SharePoint is a capable and deeply integrated platform. Organisations invested in Microsoft 365 should keep using it for what it does well.

The gap is specific: sensitive information crossing organisational boundaries. That is precisely where SharePoint's architecture carries the most cost, in guest governance, vendor-readable content, and oversharing surface, and it is exactly what DekkoCORE was built for. The strongest deployment pattern is complementary: SharePoint for general internal collaboration, DekkoCORE for the external exchanges where end-to-end encryption, sovereignty, and defensible auditability are non-negotiable.

Claims you can check

IRAP assessed at PROTECTED

DekkoSecure's Australian environment is independently assessed against the ISM at PROTECTED level under IRAP.

Independently tested claims

Security claims tested by Enex TestLab and the platform independently penetration tested.

End-to-end encrypted by default

Files, messages, eSignatures, and video meetings encrypted on the user's device. No configuration required to be safe.

Sovereign hosting options

Data sovereignty options in Australia, Canada, the United States, and Switzerland, keeping data jurisdiction-bound.

The migration work is happening either way. Make it count.

Download the complete comparison analysis, or talk to us about your external sharing workflows before the August 31 deadline.

The full document covers everything on this page in depth, with sources throughout:

  • The complete OTP retirement timeline and its operational consequences
  • The guest governance framework Microsoft recommends, and what it requires in licensing and administration
  • SharePoint's structural pain points: oversharing mechanics, Copilot amplification, the encryption model, and the 2025 ToolShell campaign in accurate context
  • A thirteen-dimension comparison against DekkoCORE, every claim sourced
  • Guidance on the complementary deployment model

Contact DekkoSecure

Download the comparison analysis

PDF, sent to your work email.

SharePoint external sharing change: FAQ

What exactly is changing with SharePoint external sharing in 2026?

Microsoft is retiring One-Time Passcodes (OTP) for external sharing in SharePoint Online and OneDrive for Business. From May 2026, new external invitations use Entra B2B Collaboration guest accounts. From July 2026, existing OTP links stop working and must be recreated. Microsoft expects the retirement to be effective across commercial, government, and sovereign clouds by August 31, 2026.

Will our existing sharing links break?

If they used OTP authentication, yes. Those links fail from July 2026 due to lack of authentication. Affected workflows need to be identified, counterparties notified, and links reissued. New links automatically create guest accounts for recipients in your Entra ID directory.

What does governing guest accounts actually involve?

Microsoft's recommended framework includes a B2B Collaboration policy governing allowed domains, sponsor assignment for accountability, Entra ID access reviews to remove stale guests (which require Entra P1 licensing), site-level expiring access policies, and inactive guest reporting. Entra ID includes 50,000 free monthly active guest users, with monthly active user billing for premium features beyond that.

Is DekkoCORE a replacement for SharePoint?

No. SharePoint remains a capable platform for internal collaboration inside a Microsoft 365 tenant. DekkoCORE is purpose-built for the specific gap: sensitive information crossing organisational boundaries. Most customers run both, using DekkoCORE for the external exchanges where end-to-end encryption, sovereignty, and defensible auditability are non-negotiable.

How is DekkoCORE's security verified?

DekkoSecure's Australian environment is IRAP assessed at PROTECTED level against the ISM. The platform's security claims have been independently tested by Enex TestLab, and the platform is independently penetration tested. All content is end-to-end encrypted on the user's device, and DekkoSecure's zero-knowledge architecture means neither DekkoSecure staff nor the underlying cloud providers can see user data.