Microsoft 365

SharePoint Online external sharing settings at tenant and site level

Configure SharePoint and OneDrive guest sharing end to end: Entra B2B invite settings, tenant and site sharing levels, domain limits, Anyone link expiry and guest access expiration.

13 min read
On this page

SharePoint Online external sharing is controlled in layers: Microsoft Entra external collaboration settings decide who may invite guests and from which domains, the organization-level sharing level in the SharePoint admin center sets the most permissive option any site can use, and each site or OneDrive can then be set to the same level or tighter. To configure it, set the Entra invite settings first, choose the organization level for SharePoint and OneDrive under Policies > Sharing, add domain limits, Anyone link expiry and guest access expiration, then tighten individual sites in Active sites or with Set-SPOSite. Since mid-2026, all new external sharing in commercial tenants goes through Entra B2B, which changes how guests sign in and how domain lists interact.

Who this is for and what you will have

This guide is for Microsoft 365 and SharePoint administrators setting up or tightening guest collaboration. At the end you will have:

  • Entra invite and domain settings that match your SharePoint plans.
  • Organization sharing levels for SharePoint and OneDrive, with consistent domain lists.
  • Expiring, view-only Anyone links if you allow them, and automatic guest access expiry.
  • Verified site-level overrides for sensitive and partner-facing sites.

How the layers fit together

LayerWhat it controlsWhere
Entra external collaboration settingsWho can invite guests, what guests can see in the directory, allowed or blocked domains for invitationsEntra admin center > Entra ID > External Identities > External collaboration settings
Microsoft 365 Groups guest settingsWhether group owners can add guests and whether guests can access group resourcesMicrosoft 365 admin center
SharePoint organization settingsSharing level for SharePoint and OneDrive, domain lists, who can share, link defaults, Anyone link rules, guest expirationSharePoint admin center > Policies > Sharing, or Set-SPOTenant
Site settingsSharing level, domain list, default links and guest expiration for one siteSharePoint admin center > Active sites, or Set-SPOSite
OneDrive per userSharing level for one user's OneDriveMicrosoft 365 admin center > user > OneDrive tab, or Set-SPOSite

The most restrictive applicable setting wins, including when an Entra setting is stricter than SharePoint. Site owners can't change site-level external sharing settings; that needs at least the SharePoint Administrator role.

What changed in 2026

Two changes affect every commercial tenant:

  • Entra B2B integration is always on. Between May and July 2026, Microsoft enabled SharePoint and OneDrive integration with Entra B2B for new external sharing in commercial tenants. EnableAzureADB2BIntegration no longer controls sharing behavior there, and the integration can't be disabled. Invited external people get a guest account in your directory and are subject to Entra policies such as multifactor authentication and to the Entra invite and domain settings.
  • SharePoint one-time passcode authentication is retiring. Starting in October 2026, SharePoint OTP is retired for commercial tenants; Entra B2B email one-time passcode stays supported. External users who reach previously shared Specific people links without a matching Entra guest account get access denied. Creating a guest account for the email address used in the original share, or sharing at least one file, folder or site with that person, restores access to everything previously shared with them.

Prerequisites

  • SharePoint Administrator role for the SharePoint admin center and SharePoint Online Management Shell steps.
  • A role that can update external collaboration settings in Entra, such as External Identity Provider Administrator. Microsoft's allow and block list procedure uses Global Administrator; use the least privileged role that works.
  • The SharePoint Online Management Shell:
Connect-SPOService -Url https://contoso-admin.sharepoint.com
  • A list of partner domains, the sites that must never be shared externally, and an agreed guest access lifetime.
  • A test account outside your organization for verification.

Step 1: Set Entra invite and domain rules

In the Microsoft Entra admin center, go to Entra ID > External Identities > External collaboration settings.

Under Guest invite settings, choose who can invite:

OptionEffect
Anyone in the organization can invite guest users including guests and non-adminsMost inclusive
Member users and users assigned to specific admin roles can invite guest users including guests with member permissionsMembers can invite; guests can't unless they have member permissions
Only users assigned to specific admin roles can invite guest usersOnly User Administrator or Guest Inviter role holders
No one in the organization can invite guest users including adminsMost restrictive

This matters for SharePoint: Entra settings decide who can invite guests for site sharing, and with B2B integration they also apply to file and folder sharing. If you later restrict external sharing in SharePoint to specific security groups, those users must also be allowed to invite in Entra.

Under Guest user access, the default limits what guests can see in the directory; the most restrictive option limits guests to their own profile.

Under Collaboration restrictions, choose an allow list or a block list:

  • You can have one or the other, not both, and switching discards the existing list.
  • The whole policy is limited to 25 KB (25,000 characters), which is about 1,600 domains if entries average 15 characters.
  • The list doesn't affect guests who already redeemed an invitation; a pending invitation to a newly blocked domain fails at redemption.

Cross-tenant access settings are also checked when an invitation is sent. To require MFA or other conditions for guests, use Conditional Access; the zero trust remote access architecture includes a guest-specific Conditional Access signal.

Step 2: Choose the organization sharing level

In the SharePoint admin center, expand Policies and select Sharing. Under External sharing, set separate levels for SharePoint and OneDrive. OneDrive can be more restrictive than SharePoint, never more permissive.

Admin center levelSharingCapability valueWhat users can do
AnyoneExternalUserAndGuestSharingShare files and folders with links that need no sign-in; share sites with guests who authenticate
New and existing guestsExternalUserSharingOnlyShare with people outside the organization who sign in or verify with a code; they are added to the directory
Existing guestsExistingExternalUserSharingOnlyShare only with guests already in the directory
Only people in your organizationDisabledNo external sharing

Choose the most permissive level any site genuinely needs. The PowerShell equivalent:

Set-SPOTenant -SharingCapability ExternalUserSharingOnly -OneDriveSharingCapability ExistingExternalUserSharingOnly

If you restrict or turn off external sharing, guests typically lose access within one hour. If you turn external sharing off for the organization and later turn it back on, guests regain access and shared links resume working, so turn sharing off on specific sites first if you want those guests gone for good.

Step 3: Limit sharing by domain

On the same Sharing page, expand More external sharing settings, select Limit external sharing by domain, then Add domains. Choose Allow only specific domains or Block specific domains and enter up to 5,000 domains, one per line, in the format fabrikam.com. Wildcards aren't supported.

# Organization: only allow two partner domains
Set-SPOTenant -SharingDomainRestrictionMode AllowList -SharingAllowedDomainList "fabrikam.com litware.com"
 
# Or block specific domains instead
Set-SPOTenant -SharingDomainRestrictionMode BlockList -SharingBlockedDomainList "adatum.com"

PowerShell takes a single space-separated string. Rules for combining the organization and site lists:

  • The organization configuration takes precedence where they conflict.
  • With an organization allow list, a site allow list must be a subset of it, and sites can't use a block list.
  • With an organization block list, a site can use either an allow list or a block list.
  • A site list holds up to 500 domains.
  • OneDrive accounts and group-connected sites that don't appear in the admin center list need Set-SPOSite for site-level domain limits.

Entra's collaboration restrictions also apply to SharePoint invitations, so keep both lists aligned.

Step 4: Control who can share and whether guests can reshare

Still under More external sharing settings:

  • Allow only users in specific security groups to share externally, then Manage security groups. Add up to 12 security groups and set Can share with to Authenticated guests only (the default) or Anyone for each. Only members of those groups can share externally.
  • Allow guests to share items they don't own should normally stay off. By default, guests need Full Control to share items externally. In PowerShell, -PreventExternalUsersFromResharing $true prevents external users from resharing files, folders and sites they don't own.
Set-SPOTenant -PreventExternalUsersFromResharing $true

Under File and folder links, choose the default link type users see. Specific people is the most restrictive. Anyone with the link is only offered when the external sharing level is Anyone; if a site only allows authenticated guests, the default falls back to Only people in your organization.

If you allow Anyone links, use the advanced settings to require them to expire within a set number of days and to restrict them to view permission. When you shorten the expiration, existing links are updated to the shorter limit; when you lengthen it, existing links keep their current expiration.

Set-SPOTenant -RequireAnonymousLinksExpireInDays 30 -FileAnonymousLinkType View -FolderAnonymousLinkType View
Set-SPOTenant -CoreDefaultShareLinkScope SpecificPeople -CoreDefaultShareLinkRole View
Set-SPOTenant -OneDriveDefaultShareLinkScope SpecificPeople

RequireAnonymousLinksExpireInDays accepts 0 to 730, where 0 removes the requirement. CoreDefaultShareLinkScope and CoreDefaultShareLinkRole set the defaults for SharePoint sites and replace the older DefaultSharingLinkType and DefaultLinkPermission parameters; OneDriveDefaultShareLinkScope does the same for OneDrive.

Step 6: Expire guest access automatically

Select Guest access to a site or OneDrive will expire automatically after this many days and enter the number of days. In PowerShell:

Set-SPOTenant -ExternalUserExpirationRequired $true -ExternalUserExpireInDays 90

The value can be 30 to 730 days. How it behaves:

  • Expiration is set on guests as they join a site. Guests who had permissions before you turned the policy on aren't affected.
  • When the date passes, the guest is removed from the site. Sharing links don't deactivate, but the guest can't get in. The Entra guest account isn't changed.
  • Site owners see a banner two to three weeks ahead, and site collection administrators get a weekly email of upcoming expirations.
  • Owners extend access under Settings > Site permissions > Guest Expiration > Manage, then Extend.
  • Turning the policy off later stops new expiration dates being set but doesn't automatically clear existing ones; a site collection administrator can clear them.

Verification code reauthentication

The setting People who use a verification code must reauthenticate after this many days (EmailAttestationRequired and EmailAttestationReAuthDays, 1 to 365 days) applies to recipients using SharePoint verification codes. When Entra B2B integration is in use, the Entra email one-time passcode setting applies instead, so with B2B now always on in commercial tenants, manage this in Entra.

Step 7: Tighten individual sites and OneDrive accounts

New sites don't all start in the same place:

Site typeDefault sharing setting
CommunicationOnly people in your organization
Modern team site without a groupOnly people in your organization
ClassicOnly people in your organization
Group-connected, including TeamsNew and existing guests if group owners can add people outside the organization, otherwise Existing guests only
OneDriveAnyone

The root communication site (contoso.sharepoint.com) defaults to Anyone; check it in every tenant.

To change a site in the admin center, go to Active sites, select the site (for a channel site, select the link in the Channel sites column first), and on the Settings tab select More sharing settings. Choose the sharing level, expand Advanced settings for external sharing to limit by domain, and clear Same as organization-level setting to set the site's own guest expiration, default link type or link permission. Select Save.

The same for a partner extranet site in PowerShell:

$site = "https://contoso.sharepoint.com/sites/fabrikam-project"
 
Set-SPOSite -Identity $site -SharingCapability ExternalUserSharingOnly
Set-SPOSite -Identity $site -SharingDomainRestrictionMode AllowList -SharingAllowedDomainList "fabrikam.com"
Set-SPOSite -Identity $site -OverrideTenantExternalUserExpirationPolicy $true -ExternalUserExpirationInDays 60
Set-SPOSite -Identity $site -DefaultShareLinkScope SpecificPeople -DefaultShareLinkRole View

For a site that allows Anyone links with a shorter lifetime than the organization, use -OverrideTenantAnonymousLinkExpirationPolicy $true -AnonymousLinkExpirationInDays 7. The override can be more or less restrictive than the organization value.

For a single user's OneDrive, go to the Microsoft 365 admin center, Users > Active users, select the user, open the OneDrive tab and select Manage external sharing, or run Set-SPOSite with -SharingCapability against the OneDrive URL.

Verify the configuration

Get-SPOTenant | Select-Object SharingCapability, OneDriveSharingCapability,
    SharingDomainRestrictionMode, SharingAllowedDomainList, SharingBlockedDomainList,
    RequireAnonymousLinksExpireInDays, ExternalUserExpirationRequired, ExternalUserExpireInDays,
    PreventExternalUsersFromResharing
 
Get-SPOSite -Identity https://contoso.sharepoint.com/sites/fabrikam-project |
    Select-Object Url, SharingCapability, SharingDomainRestrictionMode, SharingAllowedDomainList,
        ExternalUserExpirationInDays, OverrideTenantExternalUserExpirationPolicy

Read sites by -Identity. When Get-SPOSite is run with -Limit or -Filter, sharing properties such as SharingCapability, SharingAllowedDomainList and ExternalUserExpirationInDays aren't populated and can show default values.

Then test with an external account: share from the partner site with an allowed domain and confirm the guest signs in, then share with a blocked domain and confirm the error.

Troubleshooting

Sharing fails with a domain error. The recipient's domain isn't allowed in the SharePoint list or in the Entra collaboration restrictions. If the user is already in your directory, the share appears to succeed but the guest is blocked when they open the site.

Guests of a Microsoft 365 group can't open site content even though the site allows guests. The group's guest settings may prevent guest members from accessing group resources. Check guest access in Microsoft 365 Groups as well as the site level.

The Anyone link option is missing. Anyone links need both the organization and the site set to Anyone. If external sharing is limited to specific security groups, members of a group set to Authenticated guests only can share only with guests who authenticate.

An external user gets access denied on a link that used to work. After SharePoint OTP retirement reaches the tenant, users without a matching Entra guest account lose access to Specific people links. Create a guest account for the email address the item was shared with, or share one item with them again. The Purview audit log's sharing events help identify affected users.

A guest can't redeem an invitation. If you added their domain to the Entra block list, or removed it from an allow list, after the invitation was sent, redemption fails. Also check the Entra guest invite settings for the person who shared.

Guests still have access after you tightened settings. Allow up to an hour. Guest expiration doesn't apply to guests who had access before the policy was enabled; remove those guests from the site.

Checklist

  • Entra invite settings chosen; Entra and SharePoint domain lists aligned.
  • Organization levels for SharePoint and OneDrive no more permissive than needed.
  • Sharing limited to security groups if required; guest resharing off.
  • View-only default links; Anyone links view-only and expiring.
  • Guest access expiration set; site owners know how to extend it.
  • Root site, sensitive sites and partner sites reviewed and restricted.
  • Guests from older SharePoint OTP shares given Entra guest accounts where needed.
  • Settings verified with PowerShell and a test guest.

References

Questions people ask

Can a SharePoint site allow more external sharing than the organization setting?

No. Each site can be set to the same level as the organization or a more restrictive one, never a more permissive one. OneDrive follows the same rule: its setting can be more restrictive than the SharePoint setting but not more permissive.

Why did external users lose access to files shared with them in October 2026?

Microsoft is retiring SharePoint one-time passcode authentication for commercial tenants starting in October 2026. External users who opened Specific people links through SharePoint OTP and have no matching Entra B2B guest account get access denied. Creating a matching guest account, or sharing at least one item with the user again, restores access.

How do I make SharePoint Anyone links expire?

In the SharePoint admin center under Policies, Sharing, set the advanced settings for Anyone links to require expiration within a number of days, or run Set-SPOTenant -RequireAnonymousLinksExpireInDays with a value of up to 730 days (0 removes the requirement). A site can override the organization value with OverrideTenantAnonymousLinkExpirationPolicy and AnonymousLinkExpirationInDays.

Do SharePoint domain restrictions and Entra B2B domain restrictions both apply?

Yes. The Entra allow or block list works independently of the SharePoint and OneDrive list. Entra restrictions always apply to site sharing and, with B2B integration, to file and folder invitations, so a domain must be allowed in both places for sharing to succeed.

SharePoint OnlineOneDriveEntra ID B2BSharePoint admin center
  1. SharePoint and OneDrive standalone plan retirement: licensing paths to 2029

    Microsoft is retiring SharePoint Online Plan 1 and 2 and OneDrive for Business Plan 1 and 2. Find affected users, size storage and move them to a suite or storage add-on.

    Microsoft 36514 min read
  2. SharePoint Migration Tool: move file shares to SharePoint and OneDrive

    Plan, scan and migrate on-premises file shares to SharePoint, OneDrive and Teams with the SharePoint Migration Tool or Migration Manager, then verify the result with the migration reports.

    Microsoft 36517 min read
  3. SharePoint Online permissions done right: groups, sharing links and inheritance

    Stop SharePoint Online permission sprawl with group-based access, sensible sharing link defaults, controlled member sharing and a clear rule for when to break inheritance.

    Microsoft 36514 min read