Fix SharePoint Microsoft Authenticator Issues for External Customers
Question details
External customers face access bottlenecks to shared SharePoint folders because multi-factor authentication is tied to a single manager's Microsoft Authenticator app across multiple locations.

- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Providing external customers working across various locations with reliable access to shared SharePoint folders.
- Observed behavior
- Users are unable to access shared folders when the single manager controlling the Microsoft Authenticator device is away or unavailable.
Ensure you have Microsoft Entra ID (formerly Azure AD) or SharePoint administrator privileges to add new external guest users and modify folder access permissions.
Add Individual Guest Users in Microsoft Entra ID
Assign individual guest accounts to each external team member so they can register their own Microsoft Authenticator app, completely removing the dependency on a single manager.
By inviting each external customer as a distinct guest user, you allow them to configure multi-factor authentication on their personal or work devices. This ensures that users across different locations can authenticate themselves independently.
Log in to the Microsoft Entra admin center using an account with Global Administrator or Guest Inviter permissions.
Navigate to 'Identity' > 'Users' > 'All users', click on 'New user', and select 'Invite external user'.
Input the email addresses of every individual external team member who needs access, craft a personalized invitation message, and click 'Invite'.
Instruct each guest to accept the email invitation and follow the prompts to set up Microsoft Authenticator on their own mobile device during their first login.
Go to your shared SharePoint folder, click 'Manage Access', remove the old shared group if necessary, and grant direct permissions to the newly added individual guest users.

Need a simpler way to collaborate? Try WPS Office
While managing SharePoint permissions and Microsoft Entra ID guest authentication can be complex, WPS Office provides a lightweight, highly compatible alternative for creating, editing, and sharing documents effortlessly.
- 1. Download WPS Office: Install WPS Office on your PC, Mac, or mobile device.
- 2. Upload to WPS Cloud: Save your collaborative documents directly to the built-in WPS Cloud storage.
- 3. Generate a Share Link: Click 'Share' in the top right corner of your document to create a secure, accessible link for your external customers.

Frequently Asked Questions
Can external users bypass Microsoft Authenticator for SharePoint?
If your organization's Conditional Access policies or Security Defaults in Microsoft Entra ID require multi-factor authentication (MFA) for guest users, they cannot bypass it. However, administrators can configure Conditional Access to exempt specific trusted locations, though this may reduce overall security.
How do I revoke access for a guest user who leaves the customer's company?
An administrator must go to Microsoft Entra ID, locate the former employee's profile under 'All users', and delete the guest account. This instantly revokes their authentication capabilities and removes their access to all shared SharePoint folders.
Why does SharePoint force external customers to use an authenticator app?
This behavior is typically driven by your tenant's security defaults or specific Conditional Access policies designed to protect sensitive shared data from unauthorized access due to compromised passwords.
Can multiple people share one Microsoft Authenticator account?
No, Microsoft Authenticator is designed to be tied to a specific user's individual mobile device for secure multi-factor authentication. Sharing a single account or device across multiple locations causes login delays, timeouts, and severe security risks.




