At Ignite we announced a major improvement to the way secure external sharing of files and folders works in both OneDrive and SharePoint in Office 365 and we wanted to share what this means for users...
this feature is not enabled on a tenant level. This features replaces the default sharing currently used. At the moment in NON FR tenants a AAD account or Microsoft Account is required. After the rollout this is no longer the case. Any sharing activity will trigger the new sharing described in this post and the external party is not asked to login using a AAD or Microsoft Account.
At the tenant level the configuration will still be the same (based on the new or old admin UI):
The 3rd option is related to the current version (AAD guest account from AAD oder MSA) and the new version (email sharing+pin).
It gets complicated if the email you are using to invite an external is already in your AAD as an guest account. At this point the user will still have to login with his AAD account. This happens in the normal B2B environment like adding a Guest to an O365 Group. The intent is to make things easier... but I'm not sure this will be the case for most scenarios. Especially as current releases as Microsoft Teams guest access is relying on this B2B model.