Something happened to SharePoint external sharing this year that most people administering it have not noticed. It stopped being a SharePoint feature. Invitation, authentication, domain restriction and cross-tenant trust for every externally shared file in your tenant are now decided in Entra, and the sharing page you have been using for a decade is a veneer over settings that live somewhere else. Microsoft did this to every tenant, whether or not the setting was enabled, and removed the ability to turn it off.
That single change is the frame for this baseline, and it has a date attached that matters more than any setting in the series. External people who were given links under the old model, and who do not have a guest account in your directory, lose access during October. Not degraded access. Access denied. The work to prevent that is an inventory and it takes time, which means the deadline is really the end of September.
The conventions here are the ones set in the first series and I will not restate them. Tiered items, grouped by control-plane domain rather than by admin centre, the reasoning with the value, and the automation equivalent per section. What is worth saying is that this is the first wave with a real prerequisite: the Entra ID baseline is no longer adjacent reading, it is the layer this one now sits on.
Which domains this series occupies
External Trust is the centre of gravity, and it is the domain the identity wave could only partly fill. Guest identity was governed there; what guests can actually reach is governed here. Together they are one control, split across two products, which is exactly the kind of seam a baseline organised by portal blade never sees.
Data and Email appears again, because Teams messages are a delivery channel with its own protection policy sitting outside everything the mail baseline covered, and because the file estate is where sensitivity labels and retention actually bite. Device Trust appears for sync and unmanaged-device access to documents. Tenant Governance covers group lifecycle, naming and the structural question of which container a piece of work belongs in. Monitoring and Response covers the sharing reports, which for once are the primary tool rather than an afterthought.
Application Trust and Privileged Access belong to the identity wave and I will not duplicate them. Teams app governance is the one place they overlap, and it gets a section rather than an article.
Four things that changed, and one that was never true
External sharing runs on Entra B2B, and you cannot opt out. From May 2026 Microsoft enabled the integration for every tenant regardless of the tenant’s own setting, and the documentation says plainly that the setting now has no effect and the ability to disable it is removed. The consequence is architectural rather than cosmetic: invitation permissions, domain allow and block lists, cross-tenant access and guest session behaviour are Entra concerns now, always, not conditionally. Four separate rows in an older checklist collapse into that one sentence.
The October cutoff is the wave’s only real deadline, and it moved. SharePoint’s own one-time passcode authentication retires, and external users holding links but no guest account lose access when it does. That was announced for July and rescheduled to run through October. Worth knowing: Microsoft’s own documentation had not caught up at the time of writing and still said July, so if you are checking this yourself, the Message Center post is the authority and the docs page lags it.
Teams protection is in E3 now, and that is this wave’s licensing headline. Zero-hour auto purge for Teams, Teams messages in quarantine, and user-reported Teams items are Defender for Office 365 Plan 1 capabilities, and Plan 1 became part of E3 and Microsoft 365 E3 on the first of July 2026. It was already in Business Premium. So the entire mid-market can protect Teams messages at no extra cost, having been told for years that this required an upgrade. Every licensing column written before this summer is wrong on that point.
The tooling for governing Copilot is licensed by buying Copilot. Microsoft’s recommended sequence is to fix oversharing before deploying Copilot, and the instrument it recommends for doing that arrives with a Copilot licence. Any organisation planning to govern first and purchase second discovers the packaging assumes the reverse. That is not a reason to skip the work, but it is a procurement conversation nobody warns you about.
And the thing that was never true: anonymous links are not simply on by default. The claim gets repeated everywhere, including by people I respect, and it is a layer confusion. The tenant permits them. Whether a user can actually mint one depends on the site type, and most site types ship at organisation-only or existing-guest tiers. The two surfaces that do bleed anonymous out of the box are OneDrive and the tenant root site. That makes the recommendation much smaller and much easier to sell than it is usually framed, and I would rather hand a client a precise change than a frightening one.
Where the federal baseline and Microsoft disagree
I anchor tier assignments to the CISA baselines where a matching control exists, because they are quotable, stable and free, and because a client’s auditor recognises them. In this wave they collide with Microsoft’s own recommendation in a way worth naming at the front rather than burying in a row.
Microsoft ships a balanced preset for Teams external collaboration and describes it as matching the defaults an enterprise tenant already has. That preset allows communication with all external domains. The federal baseline says external access shall be permitted on a per-domain basis only. So a tenant sitting on Microsoft’s recommended configuration fails a mandatory control. Neither party is being careless. They are answering different questions, one about a workable commercial default and one about a floor for federal civilian agencies, and the useful thing a consultant can do is say which question the client is actually asking. I do that in the critical tier rather than picking a side here.
Two practical notes on citing those baselines. The SharePoint set has no section four any more, because the control it held became moot when Microsoft disabled custom scripting platform-wide. The Teams set has no section three. Numbering was preserved rather than closed up when both were removed, so a document citing the missing sections is quoting a retired baseline, and a good deal of published commentary does exactly that. And there is no federal control at all for shared channels, Copilot governance, restricted content discovery or sensitivity labels, which is worth saying plainly instead of inventing a mapping.
What this series contains
| Article | What it covers |
|---|---|
| [BP 3.1] The Critical Tier | External sharing by site type, the guest lifecycle across the Entra seam, the domain lists that moved, Teams external and guest access, and the Teams protection policy that sits outside everything else. |
| [BP 3.1.1] Build Sheet: The Guest Account Inventory Before October | Finding every external person holding a link without a guest account, creating the accounts, and proving it worked. On a worked estate, with a deadline. |
| [BP 3.2] Recommended and Optional Tiers | Link defaults and expiry, guest resharing, container labels, group lifecycle and naming, sync and unmanaged-device controls, Teams apps and meeting policy. |
| [BP 3.3] Before Copilot: Fixing What Everyone Can Already See | Oversharing as its own discipline. Microsoft’s blueprint, the assessments worth running, restricted content discovery as an interim control, and the sequencing problem. |
| [BP 3.4] Retirements and What Already Broke | The calendar. Four things died this year that a 2025 runbook still references, the October cutoff, and the last tail date in February 2027. |
| [BP 3.5] The Collaboration Quick Checklist | Every action above as a scannable list, each row with a way to verify it and a pointer to the article that defends it. |
If you read one of these, read the build sheet, and read it this month. Everything else in the series is a position you can adopt at your own pace. The guest inventory is the only piece with a date that arrives whether or not anyone did the work.
Best Practices
‹ Previous: [BP 2.4] The Exchange Online Quick Checklist
Next: [BP 3.1] The Collaboration Baseline: The Critical Tier ›




