The accountant emails to say the folder link stopped working. The link is the same one they have used since spring. Nothing was moved, nothing was deleted, and nobody changed a permission.
Within a week the monthly documents are travelling as email attachments again, which is precisely what the shared folder was bought to stop.
What changed behind the link
External sign-in for SharePoint and OneDrive moved from SharePoint Online to Microsoft Entra B2B. The one-time passcode is still there as the default way a guest proves who they are, so the change is not about the login screen. What changed is which system holds the identity behind that passcode.
Microsoft's FAQ on the external sharing improvements is direct about the consequences (checked: 2026-08-20). There is no opt out, the rollout picks tenants automatically, and manual enablement closed at the end of April 2026.
Two sentences from it matter to a business owner. Previously shared links do not need to be reshared, as long as the recipient has a Microsoft Entra B2B guest account in your directory. External collaborators without such an account see access denied, starting July 2026.
So the link did not break. The identity it depended on was never registered anywhere you can see.
Every file leaving the business goes to somebody. If you cannot name that somebody, you are not sharing, you are hoping.
Two things are worth ruling out early. Anyone links, the ones that work without any sign-in, are unaffected by this change. Guests who already have a guest account keep working normally, and no duplicate account gets created for them.
Find out who you actually share with
Start with evidence rather than a settings page. At site level, the external sharing report lists guests invited through the old SharePoint passcode route who do not yet have a guest account in your directory. The "User E-mail" column is the one to read.
That report tends to produce an uncomfortable moment. Most small businesses discover names of people who left a supplier two years ago, a former bookkeeper, a contractor from a finished project, and at least one address nobody recognises.
Write down four things for each entry:
- who the person is and which organisation they belong to
- what they were given access to
- who inside your business shared it
- whether that access should still exist today
The last column is the useful one. This is the first list many owners have ever had of everyone standing outside the business holding a key.
Restore access without opening the door wider
For a partner who should still have access, the fix is small. A guest account appears in your directory in three ways. Someone shares or reshares a file, folder or site with them, a site was shared with them at some point in the past, or an administrator creates the account directly.
Handle the people you need one at a time, deliberately. Resist the reflex to reshare everything to everyone who complained, because that turns a support ticket into a permanent grant.
For entries that should not exist any more, do nothing. Access that has already stopped working is a problem that solved itself, and re-enabling it out of politeness is how a temporary arrangement becomes permanent.
This is the part of a tenant review where technical configuration meets the way the business actually works, and it is the usual starting point for our Microsoft 365 and Cloud work. The deliverable is a short list of who is outside, why, and until when, rather than a permissions dump.
Decide what sharing should look like from now on
The access failure is worth using, because it exposes a question that never gets asked on a calm week: who is allowed to share company files with the outside world, and on what terms.
Three decisions cover most small businesses. Which areas may be shared externally at all, and which are internal by definition. Whether external access has an end date rather than lasting until somebody remembers. Who reviews the list, and how often, with quarterly being enough for most firms.
Write the answers down somewhere other than one person's head. A rule that lives in the head of whoever set up the tenant is not a rule, and this change is a reminder of what that costs.
What not to do
Do not fix it by emailing the file. It works today, it removes any record of who has the current version, and six months later the shared folder is decoration.
Do not switch external sharing off in a panic. Turning the tap off across the tenant breaks the partners who are working correctly and pushes everyone towards personal accounts and private drives, where you will never see any of it again.
Do not reshare in bulk to clear the complaints. Each reshare creates an identity in your directory, which is fine when you meant it and quietly wrong when you did not.
Do not assume this is the only change of its kind. The Exchange Web Services retirement is landing on many of the same tenants this autumn, with the same pattern: a platform change that surfaces as an ordinary complaint from a colleague.
When you can handle this internally
An internal fix is realistic when one person can open the sharing report, recognises most of the names, and has the authority to say that an old access should end. Keep it narrow: read the report, identify the people, restore what is needed one by one, close the rest, write down the rule.
Bring in help when nobody recognises the names, or when sharing has been happening from personal OneDrive accounts as well as team sites. The same applies when a partner needs access restored today and the work cannot wait, or when one folder is shared with a dozen outsiders and nobody can say which project they belonged to.
The immediate job is getting the right partner back into the right folder. The lasting one is being able to answer, at any point, who is outside the business and what they can see.