With Email one-time passcode (OTP) for guests enabled, the SC-300 materials describe OTP as an authentication method "used for B2B guest users who do not have, or cannot use, an Azure AD or Microsoft account to complete sign-in." In the scenario:
[email protected] is already a guest in the tenant and will authenticate using their home directory; no OTP is sent.
[email protected] is an internal member of the same tenant and therefore does not receive a guest OTP.
[email protected] has never accessed resources in the tenant; when the library is shared, the tenant sends a guest invitation. With OTP enabled, the service provides a passcode by email to complete authentication when a straightforward federated or previously established sign-in path is not available for the invitee. Hence, under the guest invite/OTP configuration shown, User2 is the user who will be emailed a one-time passcode.