logo
search
Permission & Access Issues

Fix SharePoint Microsoft Authenticator Issues for External Customers

Maira MehtabMaira Mehtab Sep 30, 2026 868 views

Question details

External customers face access bottlenecks to shared SharePoint folders because multi-factor authentication is tied to a single manager's Microsoft Authenticator app across multiple locations.

How to Fix SharePoint Microsoft Authenticator Issues for External Customers
Product
Microsoft SharePoint
Device & OS
not provided
Scenario
Providing external customers working across various locations with reliable access to shared SharePoint folders.
Observed behavior
Users are unable to access shared folders when the single manager controlling the Microsoft Authenticator device is away or unavailable.
Before you start

Ensure you have Microsoft Entra ID (formerly Azure AD) or SharePoint administrator privileges to add new external guest users and modify folder access permissions.

Solution 1Recommended

Add Individual Guest Users in Microsoft Entra ID

Assign individual guest accounts to each external team member so they can register their own Microsoft Authenticator app, completely removing the dependency on a single manager.

By inviting each external customer as a distinct guest user, you allow them to configure multi-factor authentication on their personal or work devices. This ensures that users across different locations can authenticate themselves independently.

1
Sign in to Microsoft Entra admin center

Log in to the Microsoft Entra admin center using an account with Global Administrator or Guest Inviter permissions.

2
Invite new guest users

Navigate to 'Identity' > 'Users' > 'All users', click on 'New user', and select 'Invite external user'.

3
Enter external user details

Input the email addresses of every individual external team member who needs access, craft a personalized invitation message, and click 'Invite'.

4
Set up individual Authenticators

Instruct each guest to accept the email invitation and follow the prompts to set up Microsoft Authenticator on their own mobile device during their first login.

5
Update SharePoint permissions

Go to your shared SharePoint folder, click 'Manage Access', remove the old shared group if necessary, and grant direct permissions to the newly added individual guest users.

Add Individual Guest Users in Microsoft Entra ID
Independent Authentication Achieved: Each user can now securely log in and authenticate from any location without waiting for another person to approve the Microsoft Authenticator prompt.
Free Microsoft Office alternative

Need a simpler way to collaborate? Try WPS Office

While managing SharePoint permissions and Microsoft Entra ID guest authentication can be complex, WPS Office provides a lightweight, highly compatible alternative for creating, editing, and sharing documents effortlessly.

  1. 1. Download WPS Office: Install WPS Office on your PC, Mac, or mobile device.
  2. 2. Upload to WPS Cloud: Save your collaborative documents directly to the built-in WPS Cloud storage.
  3. 3. Generate a Share Link: Click 'Share' in the top right corner of your document to create a secure, accessible link for your external customers.
Seamlessly compatible with Microsoft Word, Excel, and PowerPoint file formats.Built-in cloud collaboration for easy and secure file sharing across multiple locations without complex MFA setups.Lightweight installation with a familiar, easy-to-use interface that requires no learning curve.Free to use with comprehensive PDF editing and document management tools included.
microsoft office alternative - wps office

Frequently Asked Questions

Can external users bypass Microsoft Authenticator for SharePoint?

If your organization's Conditional Access policies or Security Defaults in Microsoft Entra ID require multi-factor authentication (MFA) for guest users, they cannot bypass it. However, administrators can configure Conditional Access to exempt specific trusted locations, though this may reduce overall security.

How do I revoke access for a guest user who leaves the customer's company?

An administrator must go to Microsoft Entra ID, locate the former employee's profile under 'All users', and delete the guest account. This instantly revokes their authentication capabilities and removes their access to all shared SharePoint folders.

Why does SharePoint force external customers to use an authenticator app?

This behavior is typically driven by your tenant's security defaults or specific Conditional Access policies designed to protect sensitive shared data from unauthorized access due to compromised passwords.

Can multiple people share one Microsoft Authenticator account?

No, Microsoft Authenticator is designed to be tied to a specific user's individual mobile device for secure multi-factor authentication. Sharing a single account or device across multiple locations causes login delays, timeouts, and severe security risks.