OneDrive and SharePoint One-Time Passcode Share Retiring

Please see the following scheduled Microsoft change:

Date: May 2026 and July 2026 (An exact implementation date is unavailable for WSU’s Microsoft environment.)

The following work is being completed: Microsoft is retiring SharePoint One-Time Passcode (SPO OTP) authentication for external sharing in OneDrive and SharePoint. SPO OTP is a feature that sends a one-time code via email to open a shared file.

All affected groups: External users who access OneDrive or SharePoint files, folders, and sites hosted in the WSU Microsoft 365 tenant

All affected processes:

  • This change will transition external sharing and authentication in OneDrive and SharePoint to an expiring anonymous link (also known as “Anyone with the link” sharing) or a guest Microsoft account.
  • May 2026:
    • New external sharing invitations and authentication will begin using this updated process instead of SPO OTP.
    • External users who have previously authenticated via SPO OTP can continue doing so until July 2026.
  • July 2026:
    • SPO OTP will begin retiring.
    • When accessing new shared “Specific people” links, external users without a guest Microsoft account in the WSU Microsoft directory will automatically have one created for them.
    • When accessing previously shared “Specific people” links that utilized SPO OTP, external users without a guest Microsoft account in the WSU Microsoft directory will receive an “Access Denied” error.
    • External users who already have a guest Microsoft account in the WSU Microsoft directory will not experience any change.

Duration of impact: This is a permanent, Microsoft-driven change.

Necessary follow-up steps:

  • External Users: Must authenticate using a guest Microsoft account or be provided with an expiring anonymous link.
  • Internal WSU Users: Can share or re-share at least one file, folder, or site following this retirement which will automatically create a guest Microsoft account and restore access to all previously shared content.
  • WSU Microsoft Administrators: Can manually create a guest Microsoft account for an external user following this retirement which will restore access to all previously shared content.

Questions? Please contact Crimson Service Desk at crimsonservicedesk@wsu.edu or 509-335-4357.