A Microsoft file hosting and synchronization service.
Dear @Bejhan Pacadzioski,
I hope you’re having a good day.
Thank you for the detailed explanation of your requirements.
Based on Microsoft's current External Identities and SharePoint Online architecture, the behavior you are seeing appears to be expected. When "Allow invitations only to the specified domains" is enabled in Microsoft Entra External Identities, guest invitations are restricted to the domains included in that allowlist. Because SharePoint Online and OneDrive now rely on Microsoft Entra B2B for guest collaboration, external sharing invitations are also evaluated against the same restriction.
This means the desired configuration of:
- Restricting Teams Guests to approved domains only,
- While allowing SharePoint and OneDrive sharing to users from any external domain,
does not appear to be supported through a separate policy today, because Teams Guests, SharePoint Guests, and OneDrive Guests all use the same Entra B2B invitation framework.
Given your objectives, there are two realistic approaches to consider:
If controlling which organizations can become guests is the highest priority, keeping the Entra allowlist is likely the best option. In that case, external users who need access to SharePoint or OneDrive content would need to belong to domains included in the allowlist, and additional partner domains can be added as business requirements evolve.
If flexible file sharing is the higher priority, consider changing the Entra setting to allow invitations to any domain and then applying governance at other layers, such as SharePoint sharing policies, sensitivity labels, Conditional Access, access reviews, and cross-tenant access settings. This allows broader document sharing while still maintaining administrative controls over external access
One point that may help with your requirements is that Teams External Access (federated chat and meetings) is separate from Teams Guest Access. As a result, organizations can often continue to support external chats and meetings with users from many domains without creating guest accounts, while keeping tighter controls on guest collaboration.
Based on the currently published documentation, I have not found a supported configuration that would allow SharePoint and OneDrive guest sharing to bypass the Entra domain allowlist while simultaneously keeping Teams Guest access restricted to only approved domains. This makes the current behavior look more like a consequence of the Entra B2B integration model than a service regression.
For additional reference:
- Configure external collaboration settings
- Allow or block B2B collaboration with organizations
- Cross-tenant access overview
If this workflow was functioning differently in your environment before July 2026, it may be worth reviewing any Message Center announcements or change records around that timeframe. That information could help determine whether a specific service rollout changed the sharing experience, or whether another tenant-level setting was previously allowing the scenario.
I hope this information helps point you in the right direction. Please feel free to reply below if you have any update or further concern.
Warm regards,
If the answer is helpful, please select "Yes" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.