Forum Discussion
Enable Conditional Access template for guest MFA requirement and SharePoint sharing
- Feb 09, 2024
Hi sumo83,
When you start using this template all external users will be included, see screenshot below. That means that all authentication to Entra that is not from a member user will be affected by this conditional access rule.
So to concretely answer your question: Yes this also applies to external users with whom you have shared an SP folder.
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
I'm still a bit confused about it...
sumo83 It depends who you share with and what platform he is on.
- sumo83Feb 10, 2024Iron Contributor
may I have one more question please...
as the external user is not a guest in our MS Entra.... how the MFA will work for him? Or will enabling MFA cause that also external users that are not a GUESTS will be added as GUESTS to our Entra?... Lets say that they will have issue with MFA at some point, on which site it needs to be fixed?
If they are as Guests showing in our Entra, i know their the MFA is managed by our Entra... But if I share it externaly via link, and they are not GUESTs in our Entra.... how MFA works in that case?
Trying to search for some good documentations and trainings... but these are not really answered there... :?- MatejKlemencicFeb 11, 2024Brass Contributor
To enforce MFA through Conditional Access for users, it's necessary to activate the Entra B2B integration for SharePoint and OneDrive. In cases where SharePoint External Sharing is utilized, users authenticate by entering a verification code sent to their email. My personal advice is to opt for the Entra B2B integration, as it offers extra security enhancements. Check this > https://learn.microsoft.com/en-us/sharepoint/sharepoint-azureb2b-integration
- sumo83Feb 28, 2024Iron ContributorI'm about to enable B2B integration... Do I understand that correctly that when I enable it, even one-time password via email external users will be created as guests in our Entra... and then I can enable MFA for guests/external....
for existing sharing - user will just need to re-authenticate via email one time password again (before I go to next step and enable MFA)
- sumo83Feb 09, 2024Iron ContributorI see... OK.. looks like I need to do some research about those groups to get more familiar with it... Thanks again!