SharePoint Guest Access with Email One-Time Passcode

Answer Correct answer: B — User2 receives the passcode because they are a new external guest, while User1 is an existing guest who has already redeemed their invitation.

You have a Microsoft 365 tenant that uses the domain name fabrikam.com. The External collaboration settings are configured as shown in the Collaboration exhibit. (Click the Collaboration tab.) The Email one-time passcode for guests setting is enabled for the tenant. A user named [email protected] shares a Microsoft SharePoint Online document library to the users shown in the following table. Which users will be emailed a passcode? - image - image

  1. User1 only
  2. User2 only Correct Answer
  3. User1 and User2 only
  4. User1, User2, and User3

Community Votes

B
61%
C
39%

61% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding that the Email OTP feature applies only to new guests or those who haven't redeemed an invitation, excluding existing authenticated guests.

Determines which external users receive an email one-time passcode when sharing SharePoint resources based on their existing guest status in the tenant.

Selecting all external domains because they are not part of the organization, ignoring the distinction between existing and new guest identities.

Community Discussion (12 comments)

SilverFox 👍 7 Selected: B
Repeat question.
criminal1979 👍 7 Selected: C
I say the answer is C in this case.
armid 👍 4 Selected: B
Answer the question guys, don't start confusing yourselves with whether this is one time or every time code or if they recive it just ince or every time, because THEY ARE NOT ASKING THAT. They are asking who will be sent a code at the time Bob invites them. NOT at the time the users try to access the resources. Email with OTP and invitation will be sent to B only. But to cover all basis, if a week later User1 decides to go to that shared resource AND Contoso.com is not a Microsoft account, then they will be sent OTP to reauthenticate. But again, this is not what this question is asking!
Frank9020 👍 1 Selected: C
Correct answer is C. As long as we have not info about how User1 authenticates, C is the logical option in this case.
Matt19 👍 1 Selected: C
contoso.com and tailspintoys.com both are external domains - both should be sent a passcode - C
Mole857 👍 2 Selected: B
Existing guest users in a tenancy will not receive the emailed one-time passcode if they have already redeemed their invitation. The email one-time passcode feature is for NEW guest users or those who haven't yet redeemed their invitation. If you enable the email one-time passcode feature, it will only affect future redemption processes for NEW guest users. Existing guests will continue to use their current authentication method unless their redemption status is reset
HaubeRR89 👍 1 Selected: C
Our Email OTP capability also has built-in lightweight lifecycle management. Each authentication session only lasts 24 hours, after which guests have to re-authenticate with a new email OTP. https://techcommunity.microsoft.com/blog/identity/azure-ad-makes-sharing-and-collaboration-seamless-for-any-user-with-any-account/325949
Matt19 👍 1 Selected: C
C is correct. User2 - should be asked for OTP everytime a guest user needs to login, if we enable Email one-time passcode for guests setting within: External Identities | All identity providers.
07d6037 👍 2 Selected: B
The correct answer is B
RucasII 👍 2
My doubt is whether the question is related to the moment the guest is logged in or is related to the next time they try to logon What happens to my existing guest users if I enable email one-time passcode? Your existing guest users won't be affected if you enable email one-time passcode, as your existing users are already past the point of redemption. Enabling email one-time passcode will only affect future redemption process activities where new guest users are redeeming into the tenant.
CubicTeach 👍 4 Selected: B
I think it's "B", since user 1 is already un existing member by other meaning already received the one-time passcode
klayytech 👍 1 Selected: C
passcode apply only to None Microsoft Entra or Microsoft account like (outlook or MSN)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is B. The 'Email one-time passcode for guests' setting ensures that new external users receive a secure code via email to redeem their invitation. User2 ([email protected]) is an external user from a different domain who has not been identified as an existing member of the fabrikam.com tenant, so they will receive the passcode. User1 ([email protected]) is depicted as an existing guest (implied by the context of such questions where one user is already known), meaning they have already redeemed their invitation or are recognized in the directory, thus bypassing the OTP email step.

Why the Other Options Are Wrong

Option A is incorrect because it excludes User2, who is also an external user requiring authentication if they are new. Option C is incorrect because it includes User1, who, being an existing guest, does not need a new passcode for this specific sharing event. Option D is incorrect as it includes User3 (assuming internal or non-external context) or fails to distinguish between existing and new guests properly.

Community Comment Notes

Many learners initially chose C, assuming all external domains trigger the OTP. However, comments like those from 'armid' and 'CubicTeach' clarify that existing guests do not receive the email again. 'Mole857' correctly notes that existing guest users will not receive the emailed one-time passcode if they have already redeemed their invitation. This aligns with Microsoft's documentation on lifecycle management for guest access.

Official Reference

Exam Strategy

Always check the identity status of the recipient. If a user is already a 'Guest' in the Azure AD tenant, they skip the initial redemption flow (and thus the OTP email) unless their session expired or settings changed significantly. Focus on whether the user is 'new' to the tenant.

Frequently Asked Questions

Why doesn't User1 get an email passcode?

User1 is an existing guest in the tenant. The Email OTP feature is designed for new guests or those who haven't redeemed their invitation yet.

Does enabling Email OTP affect existing guests?

No, existing guests are not affected. They continue to use their previous authentication method or sign-in state.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide