Accessing Shared SharePoint Files and Folders

by | Sep 17, 2026

Why Access Has Changed

Microsoft has recently increased the security requirements for accessing files and folders that are shared externally through SharePoint and OneDrive. These changes are designed to better protect business data from unauthorised access, phishing attacks and account compromise.

As a result, some people who could previously access shared folders using a one-time email code (OTP) may now be required to sign in with a Microsoft account and complete additional identity verification steps.

This change applies across Microsoft 365 and is intended to improve security for everyone.

What Changed?

Previously, many recipients could open a shared SharePoint link by entering a code sent to their email address.

Microsoft has retired this access method for many scenarios and now typically requires:

  • Sign-in using a Microsoft account
  • Identity verification through Multi-Factor Authentication (MFA)
  • Compliance with security policies that may be enforced by either organisation

This means access is more secure, but the sign-in process can be more complex than it was previously.

Prerequisites for Access

Before attempting to access a shared SharePoint folder, ensure you have an account that can be used to verify your identity.

In most cases, you can sign in using:

  • A Microsoft 365 Work or School Account
  • A Microsoft personal account (such as Outlook.com, Hotmail.com or Live.com)
  • Another supported identity, such as Gmail or other email providers, where Microsoft can authenticate your identity through the external sharing process
  • The account you use must match the email address that the folder was originally shared with. For example, if the invitation was sent to johnsmith@gmail.com, you should sign in using that same Gmail address.
    If you attempt to sign in with a different email address, even if you have access to the invitation email, you may receive an “Access Denied” message.

Multi-Factor Authentication (MFA)

You will almost certainly be required to verify your identity through MFA. Make sure you complete this important step.

Things That Can Block Access

Even if the sharing link is valid, security controls may prevent access.

Conditional Access Policies

The organisation sharing the files may have policies that:

  • Require MFA
  • Block access from certain countries
  • Block access from anonymous users
  • Block access from high-risk sign-ins
  • Restrict access from unmanaged devices

Your Own Organisation’s Security Policies

Your employer may prevent access to externally shared SharePoint resources through:

  • Conditional Access policies
  • Identity Protection policies
  • Browser restrictions
  • Endpoint security controls

Other Factors

Access may also be affected by:

  • VPN services
  • Starlink or other satellite internet providers allocating overseas IP addresses
  • Browser sign-in conflicts
  • Cached Microsoft credentials
  • Signing in with the wrong Microsoft account

Tips for Smooth Access

To avoid the most common issues:

  • Use the exact email address that received the sharing invitation
  • Complete all MFA prompts when requested
  • Sign out of any Microsoft accounts you are not using
  • Open the link in a private browsing window if you use multiple Microsoft accounts
  • Disable VPN software temporarily if permitted by your organisation
  • Ensure your browser is up to date

Your Troubleshooting Checklist

Before reporting an issue, please try the following:

1. Confirm Your Email Address

Verify you are signing in with the exact email address the folder was shared to.

2. Open the Link in a Private Browser Window

This avoids conflicts with existing Microsoft sign-ins.

3. Complete All Authentication Prompts

If Microsoft requests additional verification, complete every step before returning to the shared folder.

4. Try Another Browser

Testing in a different browser can quickly identify browser-related issues.

Still Having Problems ?

If access still does not work then please gather the following information:

  • The email address you are signing in with
  • The date and time of your access attempt
  • Your physical location
  • Whether you are using a VPN
  • Screenshots of any error messages
  • Details of any MFA prompts you received

Send this information to the person or organisation that shared the folder with you.

They can review the sharing settings and, if required, engage their IT support team for further investigation.

Frequently Asked Questions

Do I need a Microsoft 365 subscription?
No. You only need a Microsoft account that can complete Microsoft’s sign-in requirements.

Why does my colleague have access but I don’t?
Your account, device, browser session or organisation’s security policies may be different.

Why am I being asked to install Microsoft Authenticator?
Many organisations require MFA to protect sensitive business information.

Can the organisation sharing the folder bypass Microsoft’s security requirements?
No, the enhanced security requirements are controlled by Microsoft.

More Information:

For more information you can refer to these sites:

https://learn.microsoft.com/en-us/sharepoint/sharepoint-azureb2b-integration

https://learn.microsoft.com/en-us/sharepoint/faqs-odspintegrationwithentrab2b