Forum Discussion
SharePoint Guests vs Azure AD Guests
Does this mean we can delete unneeded users from Azure AD and not lose their ability to access their existing links?
- StephenRiceFeb 19, 2019Microsoft
Hi Maxwell Shifman ,
Hopefully I can shed some light here :)
At the moment, when you share to an entirely new person (i.e. never been shared to before) from ODB and share via the "specific people" option, one of two things can happen. If the recipient is an O365 user, when they redeem the link, they will be added to your directory as a full guest user (note that there are some cases where this may not occur). If they are not an O365 user, they are only instantiated on that site collection (or OneDrive).
This will all change in a few months when we fully migrate over to Azure B2B as the backing guest account service for ODB/SPO (as announced/demo'd at Ignite). Once done, all new shares will result in guest accounts being created.
The biggest difference between guest account created/not created is how you apply management & policy to those users.
Hope that helps!
Stephen RiceOneDrive Program Manager II
- roniyJul 05, 2020Brass Contributor
Hi StephenRice
Could you please update whether currently, every share creates a guest user in AAD?
Thanks
- StephenRiceJul 06, 2020Microsoft
Hi roniy,
As of this moment, the answer is no, every share (from OneDrive or SharePoint) does not create a guest user. Some do (as discussed above) but the Azure B2B integration I mentioned previously is still opt-in at the moment. Hope that helps!
Stephen RiceSenior Program Manager, OneDrive
- JonasBackApr 15, 2021Steel Contributor
StephenRice Just wondering about the "Azure B2B as the backing guest account service for ODB/SPO"? Are all tenants now using the new way of sharing?
- StephenRiceNov 09, 2023Microsoft
JonasBack, the short answer is "it's complicated, but getting less so" 🙂
All new tenants as of June 2023 have Entra B2B Integration with SPO on by default. All guest sharing will go through B2B as a result.
For existing tenants, they can opt into using B2B in all cases if desired. Otherwise file/folder sharing will use B2B accounts (if the guest already exists) or SharePoint one time passcode (if they do not). Sharing a site with a guest will always use B2B. There are a few other minor edge cases that use the legacy SharePoint Invitation Manager but we are working on deprecating those.
Hopefully this all makes sense but let me know if you have any questions!
Stephen Rice
Principal Product Manager, OneDrive