Guest access with Google Workspace account using OTP doesn't work

I. BACHAR 0 Reputation points
2024-03-27T10:09:46.57+00:00

Hello,

Guest access is configured in our Microsoft 365 tenant and works correctly, except for users with Google Workspace accounts using @fabrikam.com domain (example).

 

No federation is configured in our tenant.

One Time Passcode is configured in our tenant.

We need to explicitly allow a domain in Entra External collaboration settings : Fabrikam domain is allowed

 

This is the current flow :

  1. We add a guest user with the @fabrikam.com domain to a Team
  2. The Fabrikam user receive an invitation email
  3. He clicks on the link “Open Microsoft teams”
  4. [UNEXPECTED] He is redirected to Microsoft login page showing his Fabrikam email address :  he needs to enter his password
  5. [UNEXPECTED] He enters his password and he has an error message : “Votre compte ou mot de passe est incorrect. Si vous avez oublié votre mot de passe, réinitialisez-le maintenant »

 

For the step 4, we expect Fabrikam user to be redirected to a page to send the OTP code (instead of being redirected to a page to enter password), as explained in the Microsoft documentation “Invitation Redemption flow” :

https://learn.microsoft.com/en-us/entra/external-id/redemption-experience#invitation-redemption-flow

 

FYI, we also test Fabrikam users to access to another test tenant, and we have same behavior.

 

Could you please help us to allow Fabrikam external users (using Google Workspace accounts) to access our tenant with One Time Passcode (OTP) (we don’t want to configure any federation).

 

Thanks,

Regards,

Microsoft Entra External ID
Microsoft Entra External ID
A modern identity solution for securing access to customer, citizen and partner-facing apps and services. It is the converged platform of Azure AD External Identities B2B and B2C. Replaces Azure Active Directory External Identities.
2,640 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,474 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Navya 3,915 Reputation points Microsoft Vendor
    2024-03-28T09:39:12.67+00:00

    Hi @I. BACHAR

    Thank you for posting this in Microsoft Q&A.

    OTP (one-time passcode) will work on below scenarios.

    • The inviting tenant didn't set up federation with social (like Google) or other identity providers.
    • Email one-time passcode is enabled.
    • If user don't have a Microsoft Entra account.
    • They don't have a Microsoft account.
    • They don't have any other authentication method or any password-backed accounts.

    Based on the information you provided, it seems that you have set up One Time Passcode in your tenant. Can you please check remaining scenarios?

    For your reference: When does a guest user get a one-time passcode

    The redemption process verifies whether the user possesses a home directory or not. In the event that the user's home directory is recognized, the user is directed to the relevant identity provider for authentication. If no home directory is detected and the email one-time passcode functionality is activated for guests, a passcode is dispatched to the user via the provided email address.

    Thanks,

    Navya.

    Hope this helps. Do let us know if you any further queries.

    0 comments No comments