logo
search
Permission & Access Issues

Fix OneDrive API Entra B2B Error for External User Permissions

Ayan MasoodAyan Masood Sep 30, 2026 868 views

Question details

The user encounters an Entra B2B error when attempting to use the OneDrive API to share a file privately with an external user.

How to Fix OneDrive API Entra B2B Error When Adding Private Permissions
Product
OneDrive API
Device & OS
not provided
Scenario
Sharing a file privately with an external user using the API parameters requireSignIn=true and sendInvitation=false.
Observed behavior
The API returns a Microsoft Entra B2B configuration error instead of granting private permissions, and altering settings sometimes generates a public URL instead.
Before you start

Ensure you have Microsoft Entra ID administrator privileges to review cross-tenant access and external collaboration settings for your organization.

Solution 1Recommended

Review Microsoft Entra B2B Collaboration Settings

Verify that your tenant's external collaboration settings permit B2B invitations and cross-tenant access without sending an email.

When using requireSignIn=true and sendInvitation=false, the OneDrive API attempts to silently grant permissions. If the external user is not already a guest in your Azure AD (Entra ID) directory, the operation will fail unless cross-tenant access policies allow it.

1
Sign in to Microsoft Entra admin center

Log in to the Microsoft Entra admin center with at least an External Identity Provider Administrator role.

2
Access External Identities

Navigate to 'Identity' > 'External Identities' > 'External collaboration settings'.

3
Adjust Guest Invite Settings

Review the 'Guest invite settings' to ensure that your API application or administrators have the correct permissions to invite guests to the directory.

4
Check Cross-tenant Access Policies

Go to 'Cross-tenant access settings' and ensure inbound and outbound B2B collaboration settings are configured to allow access for the target external organization.

Review Microsoft Entra B2B Collaboration Settings
Guest Provisioning: In many cases, the external user must be pre-provisioned as a B2B guest in your tenant before you can use sendInvitation=false.
Free Microsoft Office alternative

Looking for a Hassle-Free Office Suite? Try WPS Office

While troubleshooting complex Microsoft OneDrive APIs and Entra B2B setups can be tedious, sharing and collaborating on documents doesn't have to be. WPS Office is a free, lightweight alternative that offers built-in cloud storage and excellent compatibility with Microsoft formats, making file sharing incredibly simple without needing developer APIs.

  1. 1. Download WPS Office: Visit the official WPS website and download the free suite for your operating system.
  2. 2. Install and Launch: Run the quick installation process, open the application, and sign in to activate your free cloud storage.
  3. 3. Share Documents Easily: Open any document and click the 'Share' button in the top right corner to instantly generate secure, permission-controlled sharing links.
High compatibility with Microsoft Word, Excel, and PowerPoint formats.Built-in cloud sharing features for simple and secure external collaboration.Lightweight application that requires minimal system resources.Familiar and intuitive user interface with zero learning curve.
microsoft office alternative - wps office

Frequently Asked Questions

Why does requireSignIn=true and sendInvitation=false cause an Entra B2B error?

This combination fails if the external user is not already a recognized guest in your Microsoft Entra ID tenant. By disabling the invitation email, the system cannot prompt the user to complete the standard B2B redemption flow.

Can I share OneDrive files privately with external users without sending an email?

Yes, but the external user usually needs to be pre-provisioned as a B2B guest in your Azure AD directory, or your tenant's cross-tenant access policies must be explicitly configured for seamless access.

Why does my API call generate a public URL instead of a private link?

If your API request does not strictly enforce authentication, or if your organization's sharing policies block external private sharing, the API fallback behavior may generate an anonymous or organization-wide public link.