Issue sharing wih external users in OneDrive

%3CLINGO-SUB%20id%3D%22lingo-sub-251703%22%20slang%3D%22en-US%22%3EIssue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-251703%22%20slang%3D%22en-US%22%3E%3CP%3EHas%20anyone%20else%20come%20across%20this%20scenario%20where%20a%20user%20is%20unable%20to%20share%20with%20external%20contacts%3F%20The%20error%20says%20that%20you%20%22cannot%20share%20a%20secure%20link%20containing%20both%20people%20inside%20and%20outside%20of%20your%20organization%22.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20investigating%20it%20seems%20that%20in%20this%20case%20one%20of%20the%20external%20users%20is%20auto-added%20as%20a%20guest%20in%20Azure%20AD%20(presumably%20because%20their%20company%20use%20O365%20too)%2C%20and%20is%20now%20treating%20them%20as%20an%20internal%20user.%20This%20makes%20sense%20to%20me%20but%20won't%20make%20sense%20to%20our%20users...%20just%20because%20they%20have%20been%20auto-added%20to%20Azure%20AD%2C%20doesn't%20make%20them%20'internal%20users'.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESee%20attached%20example%20-%20look%20forward%20to%20people's%20thoughts%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-251703%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOneDrive%20for%20Business%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-292988%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-292988%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20encountered%20this%20issue%20in%20our%20tenant%20too.%20It%20seems%20that%20once%20the%20user%20is%20added%20to%20the%20Azure%20AD%20as%20a%20Guest%20SP%20treats%20the%20user%20as%20a%20internal%20user%20and%20any%20future%20sharing%20links%20that%20include%20said%20user%20along%20with%20another%20external%20user%20not%20added%20to%20the%20tenant%20Azure%20AD%20generate%20the%20error%20OP%20mentioned.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20like%20to%20know%20if%20anybody%20understands%20why%20the%20user%20is%20treated%20as%20a%20internal%20user%20once%20he%20is%20added%20to%20the%20Azure%20AD.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-253583%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-253583%22%20slang%3D%22en-US%22%3E%3CP%3EWe'll%20see%20what%20results%20Alex%20will%20have.%20In%20my%20case%20no%20matter%20what%20variant%20i%20try%20i%20only%20get%20an%20informational%20message%20that%20some%20users%20listed%20are%20not%20in%20my%20organization%20(no%20matter%20if%20already%20existing%20guest%20user%20or%20if%20i%20put%20some%20fictional%20email%20address%20in).%20I%20can't%20make%20it%20show%20me%20same%20error%20as%20Alex%20has%20(in%20his%20first%20message%20in%20attachment).%20And%20the%20error%20he%20gets%20is%20confusing%2C%20as%20there%20shouldn't%20be%20difference%20whom%20you%20are%20sharing%20a%20link%20with%20or%20if%20you%20mix%20guests%20and%20internal%20users%20in%20the%20same%20link.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-253549%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-253549%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20have%20a%20hypothesis%20on%20what's%20happening%20here%20and%20hopefully%20you%20can%20give%20this%20a%20try%20and%20let%20me%20know%20if%20it%20makes%20sense.%20Today%2C%20you%20can't%20create%20a%20Specific%20People%20link%20that%20is%20supposed%20to%20work%20for%20both%20internal%20and%20external%20users.%20Under%20the%20covers%2C%20my%20hypothesis%20is%20that%20the%20issue%20here%20is%20really%20that%20you%20are%20entering%201%20user%20who%20is%20present%20in%20AAD%20and%201%20user%20who%20is%20not.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECan%20you%20try%20creating%20a%20link%20for%20specific%20people%20where%20both%20people%20are%20%3CEM%3Enew%3C%2FEM%3E%20external%20users%20(i.e.%20not%20in%20your%20directory)%3F%20And%20if%20that%20works%2C%20also%20try%20creating%20a%20specific%20people%20link%20where%20both%20people%20are%20existing%20external%20users%20in%20your%20directory.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20both%20of%20these%20work%2C%20I%20think%20its%20expected%20but%20the%20error%20message%20is%20probably%20wrong.%20Thanks!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EStephen%20Rice%3C%2FP%3E%0A%3CP%3EOneDrive%20Program%20Manager%20II%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252214%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252214%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20weird.%20If%20i%20try%20to%20add%20both%20guests%20users%20to%20sharing%20dialog%20as%20specific%20people%20or%20just%20one%20guest%20and%20one%20internal%2C%20i%20get%20a%20message%20that%20they%20are%20outside%20of%20my%20organization.%20I%20don't%20see%20warning%20shown%20to%20you%20and%20i%20can't%20find%20a%20setting%20that%20might%20cause%20it.%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20336px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F49681i26E299B1B61B98B5%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22onedrive-internal-external.png%22%20title%3D%22onedrive-internal-external.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252145%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252145%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20issue%20isn't%20that%20we%20have%20guest%20users%20in%20AAD%20-%20we%20frequently%20share%20files%20with%20external%20contacts%20requiring%20authentication%20(usually%20via%20OneDrive).%20The%20problem%20is%20they%20are%20appearing%20as%20'internal'%20from%20the%20end%20user's%20perspective%2Fwhen%20they%20go%20to%20share%20files.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESee%20example%20from%20my%20initial%20post%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FOneDrive-for-Business%2FIssue-sharing-wih-external-users-in-OneDrive%2Fm-p%2F252141%3Fattachment-id%3D7981%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FOneDrive-for-Business%2FIssue-sharing-wih-external-users-in-OneDrive%2Fm-p%2F252141%3Fattachment-id%3D7981%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20this%20example%20these%20are%20both%20external%20to%20the%20company%2C%20however%20OneDrive%20is%20seeing%20one%20of%20them%20as%20'internal'%20(the%20one%20that's%20in%20AAD).%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252141%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252141%22%20slang%3D%22en-US%22%3E%3CP%3EWhy%20do%20you%20think%20you%20have%20a%20problem%3F%20If%20you%20have%20guests%2C%20then%20guest%20access%20is%20enabled%20in%20your%20tenant.%20So%20you%20might%20want%20to%20disable%20it%20and%20then%20remove%20guests%20users%2C%20if%20your%20tenant%20should%20only%20work%20with%20internal%20users.%20But%20if%20you%20want%20to%20share%20files%20with%20other%20organizations%20and%20also%20require%20for%20them%20to%20authenticate%20and%20be%20able%20to%20edit%20files%20(not%20just%20share%20as%20anonymous%20read%20only%20link)%2C%20then%20you%20have%20to%20have%20guest%20access%20enabled.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252137%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252137%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Christopher%20for%20your%20message.%20Yes%20definitely%20sure%20it%20isn't%20an%20internal%20account%20which%20we%20have%20created.%20When%20searching%20in%20Azure%20AD%20it%20appears%20a%20guest.%20This%20to%20me%20suggests%20we%20do%20have%20an%20issue%20of%20some%20sort%20within%20our%20tenant.%20Thanks%20for%20your%20help.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252046%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252046%22%20slang%3D%22en-US%22%3E%3CP%3E%26gt%3BAfter%20investigating%20it%20seems%20that%20in%20this%20case%20one%20of%20the%20external%20users%20is%20auto-added%20as%20a%20guest%20in%20Azure%20AD%20(presumably%20because%20their%20company%20use%20O365%20too)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20normal%20and%20they%20have%20to%20have%20at%20least%20regular%20MS%20account%20(not%20only%20O365)%20to%20become%20guests.%20They%20still%20are%20labeled%20as%20guests%20in%20Azure%20AD%20and%20they%20are%20not%20treated%20as%20internal%20users.%20The%20error%20you%20receive%20is%20odd.%20Maybe%20you%20somehow%20picked%202%20options%20while%20sharing%2C%20although%20this%20shouldn't%20be%20possible.%20You%20can%20try%20removing%20all%20sharing%20and%20sharing%20again.%20A%20file%20can%20only%20be%20shared%20as%20a%20not%20secure%20anonymous%20link%20or%20with%20the%20authentication%20(secure)%20-%20either%20to%20only%20internal%20users%20or%20to%20anyone%20with%20MS%20account.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252034%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20sharing%20wih%20external%20users%20in%20OneDrive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252034%22%20slang%3D%22en-US%22%3EExternal%20365%20users%20won't%20be%20treated%20as%20internal%2C%20or%20they%20shouldn't%20be.%20That%20is%20odd%2C%20you%20sure%20someone%20just%20didn't%20create%20the%20user%20to%20have%20an%20account%20in%20your%20tenant%20using%20the%20external%20e-mail%20address%20associated%20with%20the%20user%20record%3F%20If%20you%20search%20for%20the%20user%20in%20portal.azure.com%20in%20active%20directory%20what%20comes%20up%3F%20what%20type%20of%20user%3F%3C%2FLINGO-BODY%3E
Highlighted
Deleted
Not applicable

Has anyone else come across this scenario where a user is unable to share with external contacts? The error says that you "cannot share a secure link containing both people inside and outside of your organization".

 

After investigating it seems that in this case one of the external users is auto-added as a guest in Azure AD (presumably because their company use O365 too), and is now treating them as an internal user. This makes sense to me but won't make sense to our users... just because they have been auto-added to Azure AD, doesn't make them 'internal users'.

 

See attached example - look forward to people's thoughts?

9 Replies
Highlighted
External 365 users won't be treated as internal, or they shouldn't be. That is odd, you sure someone just didn't create the user to have an account in your tenant using the external e-mail address associated with the user record? If you search for the user in portal.azure.com in active directory what comes up? what type of user?
Highlighted

>After investigating it seems that in this case one of the external users is auto-added as a guest in Azure AD (presumably because their company use O365 too)

 

This is normal and they have to have at least regular MS account (not only O365) to become guests. They still are labeled as guests in Azure AD and they are not treated as internal users. The error you receive is odd. Maybe you somehow picked 2 options while sharing, although this shouldn't be possible. You can try removing all sharing and sharing again. A file can only be shared as a not secure anonymous link or with the authentication (secure) - either to only internal users or to anyone with MS account.

Highlighted

Thanks Christopher for your message. Yes definitely sure it isn't an internal account which we have created. When searching in Azure AD it appears a guest. This to me suggests we do have an issue of some sort within our tenant. Thanks for your help.

Highlighted

Why do you think you have a problem? If you have guests, then guest access is enabled in your tenant. So you might want to disable it and then remove guests users, if your tenant should only work with internal users. But if you want to share files with other organizations and also require for them to authenticate and be able to edit files (not just share as anonymous read only link), then you have to have guest access enabled. 

Highlighted

The issue isn't that we have guest users in AAD - we frequently share files with external contacts requiring authentication (usually via OneDrive). The problem is they are appearing as 'internal' from the end user's perspective/when they go to share files.

 

See example from my initial post: https://techcommunity.microsoft.com/t5/OneDrive-for-Business/Issue-sharing-wih-external-users-in-One...

 

In this example these are both external to the company, however OneDrive is seeing one of them as 'internal' (the one that's in AAD).

Highlighted

This is weird. If i try to add both guests users to sharing dialog as specific people or just one guest and one internal, i get a message that they are outside of my organization. I don't see warning shown to you and i can't find a setting that might cause it.onedrive-internal-external.png

Highlighted

Hi all,

 

I have a hypothesis on what's happening here and hopefully you can give this a try and let me know if it makes sense. Today, you can't create a Specific People link that is supposed to work for both internal and external users. Under the covers, my hypothesis is that the issue here is really that you are entering 1 user who is present in AAD and 1 user who is not.

 

Can you try creating a link for specific people where both people are new external users (i.e. not in your directory)? And if that works, also try creating a specific people link where both people are existing external users in your directory.

 

If both of these work, I think its expected but the error message is probably wrong. Thanks!

 

Stephen Rice

OneDrive Program Manager II

Highlighted

We'll see what results Alex will have. In my case no matter what variant i try i only get an informational message that some users listed are not in my organization (no matter if already existing guest user or if i put some fictional email address in). I can't make it show me same error as Alex has (in his first message in attachment). And the error he gets is confusing, as there shouldn't be difference whom you are sharing a link with or if you mix guests and internal users in the same link.

Highlighted

We have encountered this issue in our tenant too. It seems that once the user is added to the Azure AD as a Guest SP treats the user as a internal user and any future sharing links that include said user along with another external user not added to the tenant Azure AD generate the error OP mentioned.

 

Would like to know if anybody understands why the user is treated as a internal user once he is added to the Azure AD.