External Sharing in SharePoint and OneDrive is changing: What You Need to Know

In an ongoing effort to create a more secure environment by default, Microsoft is introducing an important security update that will affect how external users access content shared through SharePoint and OneDrive. Starting July 1, 2025, any links shared with external users before your organization enabled Microsoft Entra B2B integration will no longer work. This change applies to all organizations that have already enabled or will enable SharePoint and OneDrive integration with Microsoft Entra B2B (Most organizations I have looked into so far). External users trying to use old links will see an error message saying the organization has updated its guest access settings. To regain access, the content must be reshared. Highlights of how the change affects organizations who have enabled B2B: All external sharing will require guest registration. External users must be added as guests in your Microsoft Entra directory. Access will be managed through Microsoft Entra B2B Invitation Manager. T...

Leagcy portals to control MFA is set to retire in September 2025

Microsoft recently introduced a new campaign to encourage users to register for Multifactor Authentication, and move away from less secure authentication methods, such as SMS and phone calls. When users sign in with these legacy methods, they will be prompted to set up the Microsoft Authenticator. Users can ignore this a couple of times, but will eventually be forced to register.

IT administrators looking for guidance on how to control the behavior, start an early migration or maybe exempt certain users, can follow this guidance

As a follow-up to this new way of controlling MFA, Microsoft recently announced that the legacy version of Multifactor Authentication will be retired on September 30th, 2025. Organizations are advised to transition their authentication methods before the deadline in 2025.