Unable to add external client accounts on Outlook and Teams mobile apps after full Intune MDM enrollment (iOS)

Alexia 0 Reputation points
2026-04-01T15:44:09.6266667+00:00

Hello,

Since we fully enrolled our iOS devices under Intune MDM management, our users are no longer able to add their clients' accounts on the Microsoft Outlook and Microsoft Teams mobile apps.

Symptoms:

  • When attempting to add an external (client) account on Outlook or Teams mobile (from another tenant), users receive an "Incorrect configuration alert" stating that the organization's IT team requires them to sign in with a specific account, but they are trying to sign in with a different one. (picture below) User's image
  • The connection attempt is blocked and the account cannot be added.

What we identified so far:

  • A Conditional Access Policy is triggering a failure at sign-in.
  • The failure appears to be related to the device compliance condition (Device: Not matched), meaning the enrolled iOS devices are not satisfying the compliance requirements set in the policy.
  • The issue not affect all professional accounts, some organisations accounts are not blocked (for all users) and others are blocked (for all users).
  • When we add App protection Policy (on Intune) and Conditional Access (on EntraID) on a test tenant, we can reproduce the same issue when adding the test account.
  • Affected apps: Microsoft Outlook and Microsoft Teams (Mobile Apps).
  • Affected platform: iOS.

Impact: All users with fully Intune-managed iOS devices are affected and cannot access their clients' Microsoft environments through mobile apps.

Could you please investigate and advise on whether this is expected behavior following the full MDM enrollment, and whether an exception or a policy adjustment can be made to allow users to add external accounts?

Thank you in advance for your help.

Best regards,

Alexia.

Microsoft Security | Intune | Microsoft Intune iOS

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-01T15:44:50.2866667+00:00

    This behavior is expected when Outlook and Teams on iOS are configured in Organization allowed accounts mode and/or when Conditional Access requires a compliant device + approved client app for the corporate tenant.

    What is happening

    1. Organization allowed accounts mode is designed to allow only a single corporate account in Outlook/Teams on managed devices.
      • For Outlook for iOS and Android, this mode “can be configured to only allow a single, corporate account to be provisioned within Outlook for iOS and Android… however, only a single corporate account can be added to Outlook for iOS and Android.”
      • Similar “only allow work or school accounts” settings exist for Teams and Microsoft 365 (Office) mobile apps on enrolled devices.
      • When this mode is active, attempts to add any other account (including external client tenants) are blocked and the app shows an alert instructing the user to sign in with the configured corporate account.
    2. Conditional Access + Intune compliance is enforcing that:
      • Access to your organization’s data is allowed only from devices that are marked as compliant and using approved client apps.
      • The documentation explicitly states that to ensure users can only access corporate email on enrolled devices, a Conditional Access policy must use the grant controls Require device to be marked as compliant and Require approved client app.
      • The “Device: Not matched” condition in the sign‑in logs for external accounts indicates that the Conditional Access evaluation cannot match the device as compliant for that external tenant, so the sign‑in is failed.
    3. Why some external tenants work and others do not:
      • The external (client) tenants have their own Conditional Access and app protection configurations.
      • Tenants that do not require a compliant device or do not enforce similar restrictions may still allow sign‑in from your users’ devices.
      • Tenants that do require compliant devices or have their own “only allow work or school accounts”/approved app requirements will block sign‑in when the device cannot be evaluated as compliant in their tenant.

    Is this expected after full MDM enrollment?

    Yes. When:

    • Outlook/Teams are configured with Organization allowed accounts mode or “only allow work or school accounts” on enrolled devices, and
    • Conditional Access is configured with Require device to be marked as compliant and Require approved client app,

    then the result is that:

    • Only the single, configured corporate account is allowed in Outlook/Teams on those managed iOS devices.
    • External client accounts are blocked by design.

    Possible options to allow external accounts

    Any change requires adjusting policy design. The documentation supports these behaviors but does not prescribe a specific exception model. In practice, administrators typically consider:

    1. Relaxing Organization allowed accounts mode / “only allow work or school accounts”
      • For Outlook/Teams and Microsoft 365 (Office) mobile apps, review the app configuration policies that enforce:
        • Organization allowed accounts mode for Outlook.
        • “Only allow work or school accounts” for Teams and Office.
      • If external accounts must be allowed, these policies would need to be adjusted or scoped so that affected users/devices are not restricted to a single corporate account.
    2. Adjusting Conditional Access scope
      • The documented pattern to lock access to corporate data is to require compliant device and approved client app.
      • To permit external accounts, administrators can:
        • Review target and exclusion groups in Conditional Access so that policies enforcing compliant devices/approved apps apply only where required.
        • Ensure that policies intended to protect your tenant’s resources are not inadvertently blocking sign‑in scenarios to other tenants where that protection is not needed.
    3. Accepting the current security posture
      • The described configuration is aligned with the goal of ensuring that “devices are only used for corporate communications” and that all corporate communications are captured and controlled.
      • If this is a requirement, then blocking external accounts on fully managed devices is consistent with the documented design and may need to remain in place.

    Summary

    • The combination of Intune MDM, app configuration (Organization allowed accounts mode / only allow work or school accounts), and Conditional Access (require compliant device + approved app) is intended to restrict Outlook and Teams on managed iOS devices to a single corporate account.
    • Because of this, adding external client accounts in Outlook and Teams mobile is blocked and results in the “Incorrect configuration alert.”
    • Allowing external accounts would require relaxing or scoping out these controls for the affected users/devices, with the trade‑off of reduced enforcement that devices are used only for corporate communications.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.