SPO OTP retirement: why Nextcloud addresses Entra B2B limits

April 30, 2026

Microsoft is aligning external sharing in SharePoint Online and OneDrive with an identity-centred model. SharePoint One-Time Passcode (SPO OTP) is being retired in favour of Entra B2B.

For many organizations, this is not a minor technical tweak: it ends simple external sharing in favour of a model that adds friction for users and workload for IT. Nextcloud brings back smooth sharing without giving up security or control over your data.

Official timeline:

  • May 2026: new external shares use Entra B2B ;
  • July 2026: "specific people" links created under the old model stop working if the recipient has no guest account ;
  • 31 August 2026: retirement completes across Microsoft 365 tenants.

What we lose with SPO OTP

SPO OTP enabled a workflow users knew well:

  • share a document from SharePoint or OneDrive ;
  • email to the recipient ;
  • temporary code ;
  • file access without a Microsoft account, with no guest created in the tenant.

For local government, consultancies, associations or SMBs in constant contact with external parties, it was the right balance: low friction, low IT overhead. Microsoft now treats that model as incompatible with centralised identity governance.

Do not confuse: email OTP remains available through Entra B2B for guest accounts. What goes away is SharePoint's standalone mechanism: direct access without a guest in your Azure AD directory.

What Entra B2B enforces

Every external partner becomes a guest in Microsoft Entra ID. Access runs through your policies (MFA, conditional access, revocation), with full traceability in Azure AD.

On paper, IT gains: Zero Trust, NIS2 alignment, third-party access reviews. On the ground, organizations without a dedicated Entra team quickly hit limits:

  • Every partner becomes a guest to manage: the external directory grows, access reviews become time-consuming ;
  • MFA and invitations: user support increases, files are not opened "in time" ;
  • Sharing turns into an identity topic: teams fall back to "Anyone" links, often less secure ;
  • Microsoft's roadmap moves on its own: tomorrow, another mechanism changes without your input.

Security improves in reports; real-world practice degrades if sharing becomes too painful.

What to do on the Microsoft side (minimum)

Before July 2026, if you stay entirely on M365, a compliance plan is required:

  1. Inventory external shares ;
  2. Migrate "specific people" links to Entra B2B ;
  3. Adjust guest policies (MFA, conditional access) ;
  4. Train users ;
  5. Monitor anonymous links.

This plan does not fix structural friction: it brings you in line with Microsoft's direction. For organizations where external sharing is central to daily work, it is not a lasting answer.

Nextcloud: the right answer for the document layer

Nextcloud is an open source platform for file storage, sync and sharing. Self-hosted or hosted with a provider of your choice, it delivers what SPO OTP did well (simple external sharing) plus what Entra B2B promises (traceability, governance, MFA), without locking partners into your Azure AD tenant.

What Nextcloud brings against Entra B2B problems

Nextcloud addresses Entra B2B friction point by point:

  • No Azure AD guest for every one-off partner: secure link (password, expiry) for a single exchange ;
  • Recurring partner: federated account via Keycloak or LDAP, no Microsoft account ;
  • User simplicity restored: share in a few clicks, flow close to the old OTP ;
  • Independence from Microsoft: sharing rules under your control, auditable open source code ;
  • End of default "Anyone" links: configurable external sharing, fine rights, revocation and local logs.

You do not give up security: you relocate it where it makes sense, on a platform you operate.

What it is in practice

Nextcloud covers the document scope end to end:

  • storage and sync (desktop, mobile, WebDAV) ;
  • internal and external sharing with granular rights ;
  • office co-editing through Collabora Online or OnlyOffice ;
  • SSO and MFA via Keycloak, LDAP or Active Directory ;
  • encryption, retention, hosting choice (on-premise, sovereign host).

Teams, Exchange and Power Automate can stay on M365 if you want. Nextcloud is not trying to replace everything: it takes on the file layer, precisely the one SPO OTP retirement undermines.

A dedicated Nextcloud article will follow (architecture, costs, field experience). The key point here: it is the most mature open source document brick to address this issue.

An architecture that holds up

Keycloak (identity, MFA, federation)  →  Nextcloud + Collabora
                      ↓
            Linux servers (on-premise or hosted)
  • Keycloak: centralised authentication without multiplying Azure AD guests ;
  • Collabora Online: Office editing in the browser ;
  • Nextcloud: files, external sharing, workflows ;
  • Linux: controlled hosting, reproducible (NixOS, Debian…).

Initial investment exceeds a click in an existing M365 tenant. The return is a stable document platform: no more surprises like "Microsoft retires tomorrow the sharing mode your 200 contractors relied on".

Coexistence with Microsoft 365

No need to switch everything at once. The most effective approach we see in the field:

  • M365 for mail, Teams, SharePoint intranet ;
  • Nextcloud for external sharing, partner spaces, archives or any use case where Entra B2B becomes unmanageable ;
  • Keycloak as an identity hub, optionally federated with Entra ID for internal accounts.

SPO OTP retirement is the right moment to pilot Nextcloud on external document scope, where Entra B2B creates the most friction.

In short

Entra B2B answers Microsoft's security vision. It does not answer the need for simple, controlled external sharing that thousands of organizations had with SPO OTP.

Nextcloud fills that gap: smooth sharing, local governance, auditable open source, independence from vendor roadmap. For any organization where external sharing weighs heavily on operations, it is the most coherent path to evaluate before July 2026.

At HeBeKo, we deploy and support Nextcloud as part of open source stacks (Keycloak, Collabora, Linux). If you are mapping external shares and considering a pilot, the contact form is the place to discuss it.

Sources: Microsoft Entra B2B FAQ, Nextcloud documentation.

Ready to take back control of your infrastructure?

A no-commitment audit to spot what's costing too much, what's exposed, and what's slowing your teams down.

Request an audit