Forum Discussion
SharePoint Online enabled MFA for guest accounts, but I see the onetime passcode
We enabled MFA for guest accounts in a conditional access policy. I test it 2 weeks before with some gmail and hotmail private accounts and SharePoint. It was working fine. The guest accounts needed to do the MFA configuration and authentication.
Now I see at some guest account it receives the onetime passcode. I now this features is just rolled out by MS in november and is default enabled on all tenants. But what is now the behaviour with the onetime passcode and MFA for guest accounts? Do they get both or just one?
https://docs.microsoft.com/en-us/azure/active-directory/external-identities/one-time-passcode
See picture below for conditional access for all guest accounts:
5 Replies
Kem_Mal Hello, these are two different things. You have the CA enforcement of MFA configured for your external users according to the dump, and then you have the auto-enabling of OTP which is best described by attaching this.
Let me add this for the redemption flow as well (the invite)
Invitation redemption in B2B collaboration - Azure AD | Microsoft Docs
Consider enabling this (the way going forward)
Azure AD B2B integration for SharePoint & OneDrive - SharePoint in Microsoft 365 | Microsoft Docs
- Kem_MalCopper ContributorThanks Christian. What is the behaviour of MS guest accounts already registered in AAD?
What is the behaviour of non-MS guest (for example gmail) accounts already registered in AAD?
What is the behaviour of new MS guest accounts (not registered in AAD)?
What is the behaviour of new non-MS guest (for example gmail) accounts (not registered in AAD)?- You have to do your own reading here. I believe the docs referenced by us already have this info. If you need further assistance go with the official support (ticket from M365 admin center).