Managing external identities to enable secure access for partners, customers, and other non-employees
The personal Microsoft account itself cannot directly leave a Microsoft Entra tenant via the “work or school” sign-in flow. The disassociation must be done from inside the tenant by an internal administrator.
To get the personal account removed from the tenant:
- An internal admin in that Entra tenant must sign in to the Microsoft Entra admin center (
https://entra.microsoft.com/). - The admin must locate the personal account’s guest user object in the tenant and delete it. This removes the external/guest relationship between the tenant and the personal Microsoft account.
- After the guest account is deleted, the personal Microsoft account is no longer associated with that tenant, and the Azure Portal will no longer show that directory for that account.
If there is no existing internal admin using that tenant, a new internal admin account must be created in the tenant first, and then that admin can delete the personal Microsoft account from the tenant (as described in the moderator’s recommended solution in the context).
If self-service “Leave organization” is not available or is stuck in a loop, Microsoft’s own guidance is that the tenant admin must remove the external user account on the organization’s side.
References: