Blog Post

Microsoft Entra Blog
2 MIN READ

Azure AD makes sharing and collaboration seamless for any user with any account

Alex_Simons's avatar
Alex_Simons
Icon for Microsoft rankMicrosoft
Jan 28, 2019

Howdy folks,


Azure AD B2B Collaboration provides customers with an easy way to share applications and collaborate with people from any organization, whether or not they have Azure AD or an IT department. We’ve been working to make B2B Collaboration even more seamless by helping partners bring their own identity. For example, last summer we announced support for Google social IDs.


Today, I'm thrilled to announce the next major step for B2B Collaboration—the public preview of email one-time passcodes (OTP), which lets you support B2B sharing with anyone in the world with an email account!


With email OTP, any partner who doesn't have an existing Microsoft-backed account or Google social ID can seamlessly access shared resources and collaborate without having to create a new account. When you invite a guest who doesn’t have an Azure AD, Google, or Microsoft Account, they can use their existing email account to collaborate. Each time they sign-in using Azure AD, they receive an OTP code via email, which they can enter to prove continued ownership of the email inbox.


By using this new capability, you allow guest users to use their work email account for authentication while making sure your corporate resources are protected by the same security standards that are mandated by your partner organization. In addition, you can optionally apply additional security through conditional access and Multi-Factor Authentication (MFA).


Guests using email OTP are just like any other B2B guests, and they have access to the same Azure AD features.

 

 

Our Email OTP capability also has built-in lightweight lifecycle management. Each authentication session only lasts 24 hours, after which guests have to re-authenticate with a new email OTP. This means your guests have to prove they still have access to their work email inboxes and have not left the partner company every 24 hours.


Email OTP enables you to collaborate with anyone, no matter where they are in their cloud journey. If your partner organization is not yet in the cloud or in a hybrid environment, on-premises guests can simply sign in with email OTP instead of having to use cloud sync, federation, or another solution.


Let me walk you through the user sign in experience. At redemption time and subsequent authentications, the guest sees a sign in prompt that asks them to request a code.

 

 

Then, they receive a one-time passcode code via email, which allows them to sign in.

 

 

We’re very excited for you to try email OTP, so go ahead and dive into the documentation to see how to preview email OTP today! Let us know your thoughts about the feature design by completing our survey.

 

And let us know what you think in the comments below or post your feedback and suggestions in our Azure AD UserVoice feedback forum.

 

Best regards,

Alex Simons (@Alex_A_Simons )

Corporate VP of Program Management

Microsoft Identity Division

Updated Jul 24, 2020
Version 7.0

26 Comments

  • SPO365's avatar
    SPO365
    Copper Contributor

    This is a good feature/addition! 

    What about ‘federation across multiple O365 tenants’ though? Wherby tenants can enjoy a seamless GAL, IM Presence and easy adding of users from GAL to SP sites/groups etc. across the tenants. Just like one would do these things within a single tenant? Any info/thoughts on this please?

  • Maria_Lai's avatar
    Maria_Lai
    Former Employee

    Jonas Back This will replace the one-time passcode sent in SharePoint soon. Please watch the message center for an announcement from OneDrive/SharePoint coming later.

  • wroot's avatar
    wroot
    Silver Contributor

    The survey asks for an opinion to make this enabled for everyone with no off switch. Some might consider such auth not secure enough (email with a working code leaks). I think it might be a default for a new tenant, but not without an off switch.

  • Anonymous's avatar
    Anonymous

    Big news. Glad to see this covers everyone now. I like the 24-hour check to ensure the guest is still employed. Was a major risk at a previous employer that limited our use of external access. Well done.