How to allow users with enrolled BYOD phones to switch orgs and use external accounts on the Teams phone app

Tomhhhh 0 Points de réputation
2025-08-13T17:53:51.5633333+00:00

Hi everyone,

We’re encountering an issue with users enrolled in our BYOD program via Intune when using the Teams app.

When they use the Teams app on their enrolled phone devices, they can log in and use the app with their primary org account without any problems. However, when they try to switch to an external org account (e.g., an external tenant account), they cannot fully add the account to the app: they can go through the login process, validate the MFA, but receive an error message stating that the switch failed when trying to select the external org.

Our current setup includes Conditional Access policies that block logins from non-compliant devices. While I initially assumed this wouldn’t affect external account logins, I’m wondering if there’s a connection or if there are additional Intune/Teams policies we need to configure to allow this functionality.

Details:

  • Devices are enrolled in Intune under our BYOD program.
  • Users can log in and use Teams with their primary org account.
  • Attempting to switch to an external org account results in a failure message.
  • Conditional Access is in place to block non-compliant devices, but I’m not sure if this applies to external org logins.

Has anyone else experienced this issue? Are there specific Intune, Teams, or Conditional Access settings that need to be adjusted to allow users to switch orgs and use external accounts on the Teams phone app?

Any insights or guidance would be greatly appreciated!

Microsoft Teams | Microsoft Teams pour les entreprises | Teams sur appareils mobiles
0 commentaires Aucun commentaire

3 réponses

Trier par : Le plus utile
  1. Anonyme
    2025-08-18T22:09:36.4233333+00:00

    Hi @Tom,

    I hope you are having a great day.

    I'm reaching out again to follow up on your issue and check if everything has been resolved. My goal is to ensure your experience remains smooth and hassle-free. If you're still encountering any problems or have run into new challenges, please let me know which steps you're currently stuck on and happy to provide further help whenever you need it. 

    If you have any further questions, feel free to tag me in your reply so I can assist you directly.

    Looking forward to your update.

    Cette réponse vous a-t-elle été utile?

    0 commentaires Aucun commentaire

  2. Anonyme
    2025-08-15T22:32:52.9733333+00:00

    Hi @Tom,

    Hope things are running smoothly on your end.

    Following up on the support thread we've been working on. I hope the information I shared in my previous answer resolve the issue you were facing. If you are still facing the same issue or need assistance with anything else, kindly respond to this email, and I will be happy to help.

    We want to make sure everything is working as expected and that your experience remains uninterrupted.

    Thank you for your patience and understanding throughout the troubleshooting process. 

    I look forward to hearing from you soon.

    Cette réponse vous a-t-elle été utile?

    0 commentaires Aucun commentaire

  3. Anonyme
    2025-08-13T19:31:39.7566667+00:00

    Hi @Tom,

    Thank you for reaching out to Microsoft Q&A forum. We are happy to assist your concern.

    This issue is almost certainly tied to Conditional Access (CA) policies and Intune compliance settings, even though you're trying to switch to an external organization account on a BYOD-enrolled device.

    When users try to switch to an external org in the Teams mobile app:

    • The app attempts to authenticate against the external tenant
    • Your CA policies may still evaluate the device's compliance status - even for external accounts
    • If the device doesn't meet the external tenant’s compliance requirements (or if your policies block unmanaged orgs), the switch fails.

    Here're suggestions you can try to fix your issue:

    1. Review Conditional Access policies

    • Go to Microsoft Entra Admin Center > Conditional Access
    • Look for policies that:
      • Require compliant devices
      • Block access from untrusted locations
      • Apply to all cloud apps or Teams
    • Consider excluding BYOD users or external tenants from these policies

    2. Use App-Based Conditional Access

    Instead of relying solely on device compliance:

    • Configure App Protection Policies in Intune
    • Use App-based CA policies that allow access based on app-level controls, not device-level compliance

    3. Create a Separate Policy for External Org Access

    • Target only the Teams app
    • Allow sign-in from non-compliant devices
    • Exclude external tenant domains or guest accounts from strict enforcement.

    Or you can try using App Protection Policies for BYOD scenarios and avoiding device compliance enforcement when users need to access multiple tenants. Please take a look at: Create a device-based Conditional Access policy.

    I hope the above information is clear. If there's anything else I can help you with, please feel free to reach out again. 

    Thank you very much for your understanding and your cooperation.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment”.    

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  

    Cette réponse vous a-t-elle été utile?

    0 commentaires Aucun commentaire

Votre réponse

Les réponses peuvent être marquées comme « Acceptées » par l’auteur(e) de la question et « Recommandées » par les modérateurs, ce qui aide les utilisateurs à savoir que la réponse a résolu le problème de l’auteur(e).