Not everything shaking up secure collaboration this year is CMMC. There's a much quieter change coming out of Microsoft that's going to touch something a lot of teams do a dozen times a day without thinking about it: sharing a file with someone outside your own tenant.
It's worth understanding now, because the timeline is short and — like most of these things — the headline version is a little off from what's actually happening.
Microsoft has announced (Message Center notice MC1243549) that it's retiring the SharePoint One-Time Passcode (SPO OTP) method for external sharing in OneDrive and SharePoint. Starting around May–June 2026, new external sharing invitations and authentication begin moving to Microsoft Entra B2B, and the old SPO OTP mechanism is slated to retire starting July 2026.
Let me be precise here, because this is the part people are getting wrong: the one-time passcode as a concept isn't disappearing. Microsoft's own FAQ says as much — external authentication is transitioning from SharePoint Online to Entra B2B, and Entra B2B still uses a one-time passcode as its default method. So if someone tells you "OTP is dead," they're overstating it.
What's actually changing is the mechanism and the plumbing underneath it. External sharing is moving from a lightweight, SharePoint-native passcode flow to the Entra B2B identity model. That's a meaningful difference in how external people get access to your files — even if the end user still ends up typing in a code.
One practical note: exact rollout dates vary by tenant and environment, and government clouds don't always move on the same clock as commercial. Before you plan around any specific date, confirm your own timeline in the Microsoft 365 admin center under MC1243549.
For a commercial tenant with a handful of outside collaborators, moving to Entra B2B is mostly a manageable transition.
For those of us living in GCC High — defense contractors, their supply chains, anyone handling CUI — it's more involved, for a few reasons:
External collaborators become identities you manage. The B2B model brings outside users into your directory as guest or B2B identities. That's a governance question, not just a login question — provisioning, lifecycle, offboarding, and licensing all come with it.
Cross-cloud collaboration is genuinely more complex. Connecting a GCC High tenant with partners in commercial or other clouds through B2B involves cross-tenant configuration that many teams haven't stood up. It's doable — it's just not a shrug.
The casual external-sharing path gets more structured. The quick "send them a link, they enter a code" workflow a lot of teams quietly rely on for outside sharing is exactly the flow that's changing.
None of this is a reason to panic, and it's certainly not Microsoft doing anything wrong — Entra B2B is a more robust identity foundation. But if a chunk of how your organization exchanges sensitive documents with outside parties runs through SPO OTP today, that path is changing, and "just make everyone a guest account" is not a realistic answer at scale.
Whatever mechanism you use to move CUI to an outside party, it still has to satisfy the same NIST SP 800-171 controls that CMMC and your DFARS 7012 obligations are built on. External file sharing sits directly on top of several control families:
Access control (AC): limit access to authorized users, control how CUI flows, and govern access from external systems (3.1.1, 3.1.3, 3.1.20).
Identification & authentication (IA): uniquely identify and authenticate every external user, with multifactor where it's required (3.5.1–3.5.3).
Audit & accountability (AU): log external access and tie every action back to a specific individual (3.3.1–3.3.2).
System & communications protection (SC): encrypt CUI in transit and keep public-facing access properly separated (3.13.8, 3.13.5).
Here's the important nuance: the SPO OTP change doesn't automatically put you out of compliance — Entra B2B is a legitimate, arguably stronger identity model. The real exposure is the scramble. When a familiar sharing path disappears, the workarounds people reach for — spinning up guest accounts in bulk, loosening external sharing settings, or just emailing files to get around the friction — are exactly how organizations quietly slip on their AC and AU controls without noticing. Whatever you move to, make sure it still proves out all four of the families above.
Here's the reframe I'd encourage, and it's bigger than this one Microsoft change.
For years, the default way to collaborate with someone outside your organization has been to invite them in — give them a guest identity, a passcode, a seat inside your SharePoint or OneDrive. If you don't have a separate, parallel system for exchanging files with outside parties, that invite-them-in approach is the only tool you've got. And it's exactly the tool that's changing.
When the SPO OTP flow goes away, companies without a parallel file-sharing and transfer channel are left with essentially one option: push every external collaborator through Entra B2B as a managed identity. That works for your core, long-term partners. It does not scale to every sub, prime, auditor, outside counsel, and one-off recipient you trade files with over the course of a program — each one now a directory identity you have to provision, govern, license, and offboard, plus a small addition to your own attack surface. Multiply that across a busy DIB supply chain and it adds up fast.
So the question isn't just "how do we replace SPO OTP." It's "should our external file exchange be living inside our production Microsoft tenant at all — or should it have its own home?"
This is the problem we're built for, so I'll be direct about it.
Sharetru Federal is a FedRAMP Moderate authorized file sharing and managed file transfer platform -- all three layers covered: IaaS, PaaS, and SaaS. It gives you a dedicated, compliant channel for exchanging files with people outside your organization — without turning every external recipient into a managed identity inside your Microsoft tenant. You control access, you get the audit trail, and your outside collaborators get a straightforward way to send and receive files.
Think of it as complementary to your Microsoft environment, not a rip-and-replace. Keep running Microsoft 365 for everything it does well; route sensitive, high-volume, or many-to-many external file exchange through a purpose-built channel that was designed for exactly that — including large files and automated transfers via MFT — and that carries its own FedRAMP authorization.
And this isn't hypothetical for us. A lot of our customers already run Sharetru in parallel with GCC and GCC High today — not because Microsoft can't hold a file, but because the administrative burden of managing external collaboration inside their tenant got heavy enough that a dedicated, FedRAMP-authorized channel was simply easier to operate. The SPO OTP change adds a completely new layer to that burden. If you've already felt that friction, this is the point where it goes from a standing annoyance to a decision worth making.
The upshot: when the SPO OTP change lands, your external collaboration doesn't have to become a directory-management project.
Look up your tenant's specific timeline for the SPO OTP change in the admin center (MC1243549). Don't assume a date.
Inventory where your team shares files with outside parties today — especially anything touching CUI — and note how much of it depends on the current external-sharing flow.
Decide which of those relationships genuinely belong in Entra B2B, and which are really just file exchange that shouldn't require a directory identity at all.
Pilot an alternative path for that second bucket before the summer cutover, not during it.
Microsoft's change is a good prompt to ask a question worth asking anyway: how much of your external collaboration should live inside your production tenant, and how much would be safer, simpler, and more scalable somewhere built for it?
If you want to talk through where the line is for your environment, that's a conversation we have all the time — reach out.