I am trying to remove an old corporate Microsoft 365 / Entra ID account from the “Add another account” picker in New Microsoft Teams for macOS.
After extensive troubleshooting, this no longer appears to be a normal Teams cache or sign-out issue. The evidence indicates that the obsolete identity is being returned to Teams by Microsoft OneAuth machine-account discovery.
TL;DR: New Teams on macOS continues to show a former corporate account after the Teams caches, account-specific OneAuthAccount Keychain records, OneAuth BlobStore identity data, and legacy Office identity data have been selectively removed/tested. Native Teams diagnostics showed the stale identity being returned by OneAuthReadMachineAccounts as one of three machine accounts. A fresh macOS user on the same Mac does not see the old account. I am looking for the supported way to remove one specific stale OneAuth machine account from the device, without authenticating it and without deleting my other Microsoft identities.
Related Microsoft Q&A already reviewed
I found the February 2026 Microsoft Q&A question “Easy way to delete old accounts on macOS Teams startup window”. The Microsoft moderator confirms that Teams for macOS does not currently provide a direct UI mechanism to remove an old account and recommends clearing the relevant Keychain credentials and the New Teams containers.
I have already performed that troubleshooting selectively (to preserve my two valid Microsoft identities), including removal of the obsolete account's OneAuthAccount Keychain entries and rebuilding the Teams containers. The stale identity is still returned by OneAuthReadMachineAccounts.
Therefore, I believe this case goes beyond the normal Teams cache/Keychain procedure described in that answer.
https://learn.microsoft.com/en-my/answers/questions/5769367/easy-way-to-delete-old-accounts-on-macos-teams-sta
Environment
- macOS
- New Microsoft Teams (
com.microsoft.teams2)
- Current valid identities:
- Personal Microsoft Account
- Current Microsoft Entra work account
- Obsolete identity:
- Former corporate Microsoft Entra account
- I no longer use/have access to this account
- I do not want to authenticate against or contact the former employer's tenant merely to clean up local identity state
- Microsoft Company Portal is not installed
- No Microsoft Enterprise SSO plug-in appears to be registered on this Mac
The Teams account picker shows the valid identities plus the obsolete corporate identity.
If I select the obsolete identity, Microsoft immediately presents the Enter password page for its old UPN. Therefore this does not appear to be merely a cached display name/avatar: sufficient identity information remains locally for OneAuth/Microsoft authentication to identify the UPN and route the authentication request.
Separate guest-tenant relationship
There was also a separate relationship between my Personal Microsoft Account and the former company's tenant, where my Personal account was a Guest.
Teams showed that organization under Settings → Accounts and orgs. I disabled that organization and am deliberately not trying to remove that relationship as part of this investigation.
The problem here is different: the former corporate account itself appears as a separate identity under Add another account.
I have deliberately avoided destructive global resets because my Personal and current Work Microsoft identities must remain intact.
1. Teams application/cache state
Relevant New Teams container/group-container state was cleared/rebuilt.
Result: obsolete account remained in the picker.
Searching the Teams/WebView state for the old corporate identity did not identify an authoritative source for it. References to the former tenant found in WebView/IndexedDB could be attributed to the separate Personal-account Guest relationship, so those were deliberately left untouched.
2. macOS Internet Accounts
The obsolete account is not registered in macOS Internet Accounts.
**3. Traditional Keychain — **OneAuthAccount
The login Keychain originally contained three OneAuthAccount generic-password entries associated with the obsolete corporate UPN.
I selectively removed only those three obsolete-account entries, preserving the valid Personal and current Work OneAuthAccount entries.
After removal, the obsolete corporate OneAuthAccount entries were confirmed absent.
Result: obsolete account still remained in the Teams picker.
This suggests that Teams machine-account discovery is not simply enumerating the traditional OneAuthAccount generic-password records.
4. OneAuth BlobStore
The Microsoft OneAuth group container contained identity-provider/metadata files associated specifically with the obsolete corporate identity.
Those files were moved to a backup rather than permanently deleted.
Result: the account remained in the picker, but its corporate profile photo disappeared and was replaced by initials.
This suggests that the BlobStore data was supplying at least some profile/avatar metadata, but was not the authoritative source for the machine-account identity itself.
5. Legacy Office identity state
The Keychain object Microsoft Office Identities Settings 3 contained separate structures relating to the obsolete account and the current Work account.
As a controlled and reversible test, I removed only the obsolete-account branches while preserving the current identity.
Result: no change to the Teams account picker.
The original Keychain object was then restored byte-for-byte.
Strongest evidence: OneAuth machine-account discovery
The most significant evidence came from native Teams authentication diagnostics.
During Teams startup/account discovery, the following sequence was observed:
InitiateMachineAccountDiscovery
OneAuthDiscoverMachineAccounts
AuthenticationService::GetAccountsFromMachine
OneAuthReadMachineAccounts
Result count: 3
When accessing the account picker, Teams again invoked machine-account discovery, including:
AuthTrusted: GetAccountsFromMachine
OneAuthReadMachineAccounts
Result count: 3
OneAuthGetAccountPicture
...
Returning 3 machine users
This strongly suggests that the stale identity presented by Teams originates from the OneAuth machine-account layer, rather than from the Teams UI/WebView cache.
Control test: new macOS user
I created a temporary second macOS user on the same physical Mac, using the same installed Microsoft Teams application.
The obsolete corporate account was not present in Teams for that macOS user.
This appears to rule out the Teams installation itself or machine-wide application configuration. The stale identity seems to reside in identity state associated with the original macOS user profile.
Data Protection Keychain / Universal Storage investigation
This led to the macOS Data Protection Keychain and Microsoft's access group:
UBF8T346G9.com.microsoft.identity.universalstorage
There are hundreds of objects belonging to this access group.
I have not modified the Data Protection Keychain database and have deliberately avoided attempting to inspect/decrypt credential or token payloads.
Instead, I made read-only SQLite snapshots before/after controlled operations and compared only object structure/metadata and whether opaque payloads changed.
Tests included:
- Teams startup;
- opening/closing the account picker;
- associating the current Work account with Teams;
- signing out the current Work account;
- fully re-authenticating the current Work account;
- signing out the Personal Microsoft Account.
Some observations:
- OneAuth startup/authentication causes changes in Universal Storage.
- Opening the account picker while Teams is already running produced no database changes in the controlled test, consistent with account enumeration being read-only.
- Signing out accounts modifies/deletes various Universal Storage objects.
- However, signing out an account does not remove its identity from the machine-account picker.
- The opaque Universal Storage
acct/svce identifiers could not safely be correlated with UPNs or known account GUIDs.
- Several objects are shared/transversal to authentication operations, so deleting individual database rows based on structural inference would be unsafe.
I therefore stopped this line of reverse engineering rather than risk corrupting Microsoft's identity store.
What I am trying to understand
I would appreciate input from anyone familiar with Microsoft OneAuth/MSAL implementation on macOS, particularly the distinction between application token-cache accounts and OneAuth "machine accounts":
What persistent store is actually enumerated by OneAuthReadMachineAccounts / GetAccountsFromMachine on macOS?
Is com.microsoft.identity.universalstorage the authoritative machine-account store, or is there another OneAuth account-metadata store involved?
What is Microsoft's supported mechanism to remove one specific machine account from the device, rather than merely signing it out of Teams?
Is there an equivalent of “Remove account from this device” that can be invoked when Company Portal / Microsoft Enterprise SSO Extension is not installed?
Can such removal be performed without successfully authenticating the obsolete account? This is important for accounts belonging to former employers, deleted accounts, expired tenants, etc.
Public MSAL APIs expose operations such as removeAccount and signoutWithAccount. Do any of these remove the identity from the shared OneAuth machine-account store, or do they only remove application/token-cache state?
If the obsolete account no longer exists or its credentials are no longer available, what is Microsoft's supported cleanup procedure on macOS?
My objective is specifically a selective and supported removal of the obsolete identity.
I want to avoid:
- removing all Microsoft identities from the Mac;
- damaging the valid Personal or current Work accounts;
- directly editing Apple's Data Protection Keychain SQLite database;
- deleting opaque Universal Storage objects by trial and error;
- modifying/re-signing Teams or Microsoft application entitlements;
- disabling macOS security mechanisms;
- authenticating against the former employer's tenant merely to remove local state.
Note on troubleshooting methodology
This investigation and the controlled tests described above were carried out with the assistance of ChatGPT (OpenAI).
ChatGPT was used to help structure the troubleshooting process, interpret diagnostic results, design reversible A/B tests, and identify potentially relevant Microsoft identity components. The observations and results reported above come from the actual Mac and the Microsoft Teams/OneAuth behavior observed during those tests.
I am posting here specifically to obtain validation or correction from people with direct knowledge of the Microsoft macOS identity stack, and ideally to identify the supported OneAuth mechanism for removing a stale machine account.