Personal MSA stuck as guest in former employer's Entra ID tenant — cannot leave; Conditional Access blocks all sign-in paths

Timothy Genser 0 Reputation points
2026-06-14T19:39:35.1933333+00:00

Personal MSA stuck as guest in former employer's Entra ID tenant — cannot leave; Conditional Access blocks all sign-in paths


Details (paste this):

My personal Microsoft account was added as a guest user in a former employer's Microsoft Entra ID tenant during my employment there. I left the company over 4 years ago and no longer have any work account in their tenant — only the stale guest invitation tied to my personal account.

The former employer's Conditional Access policies still apply to all my sign-ins. This is now actively blocking me from using my own personal Microsoft account for legitimate personal Azure use (registering Azure AD apps for personal projects).

What I've tried:

Signed in to portal.azure.com with my personal account. The page shows the former employer's branding and the message: "You cannot access this right now. Your sign-in was successful but does not meet the criteria to access this resource. For example, you might be signing in from a browser, app, or location that is restricted by your admin."

Signed in to myaccount.microsoft.com with my personal account. Got rejected with "You can't sign in here with a personal account. Use your work or school account instead." — which I no longer have.

Tried myaccount.microsoft.com/organizations directly. Same rejection.

Tried account.microsoft.com/privacy/access-tools. Got "Try another page. This link isn't working."

Signed in to account.microsoft.com with my personal account. The page loads fine but I cannot find any UI anywhere to list or leave external organizations I am a guest in.

I never had any IT-side credentials for the former employer's tenant, and my personal account is blocked from every Microsoft self-service portal that surfaces a "Leave organization" button.

My question: how can a personal Microsoft account user remove themselves as a guest from a former employer's Microsoft Entra ID tenant when they no longer have a corporate work account in that tenant, the tenant's Conditional Access policies block the personal account from reaching every documented "Leave organization" UI, and the former employer's IT is not responsive?

Is there a direct support escalation channel for stale guest invitations? An undocumented URL that exposes the "Organizations" list for a personal account? A way to file a Microsoft Support ticket for this specific scenario, and if so what product category should it be filed under?

Thank you.

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

2 answers

Sort by: Most helpful
  1. Nathan Roberts (SN) 12,656 Reputation points Student Ambassador Volunteer Moderator
    2026-06-14T20:30:54.5633333+00:00

    Hey there, Timothy Genser

    Signed in to portal.azure.com with my personal account. The page shows the former employer's branding and the message: "You cannot access this right now. Your sign-in was successful but does not meet the criteria to access this resource. For example, you might be signing in from a browser, app, or location that is restricted by your admin."

    This error shows when your account exists on the tenant, but you do not have permission to sign into the Azure portal.

    Tried myaccount.microsoft.com/organizations directly. Same rejection.

    This admin page will not allow you to sign-in using your personal Microsoft account. This is because that portal is only for work/school accounts only. Personal Microsoft accounts use https://account.microsoft.com to manage the account.

    My question: how can a personal Microsoft account user remove themselves as a guest from a former employer's Microsoft Entra ID tenant when they no longer have a corporate work account in that tenant, the tenant's Conditional Access policies block the personal account from reaching every documented "Leave organization" UI, and the former employer's IT is not responsive?

    The only other way to remove yourself from your previous employer's tenant is through Microsoft Teams. Please can you try leaving the organisation using Microsoft Teams personal. If you haven't downloaded Microsoft Teams personal, please can you download it through this link: https://www.microsoft.com/en-gb/microsoft-teams/download-app

    Once you have downloaded it, please can you sign into your personal Microsoft account in Teams and go through the process of setting up Teams. Once this process has completed, please click onto your name and check if the tenant you wish to leave is displayed under your name.

    User's image

    If it isn't, please right click onto the Teams icon in the notification tray on the Taskbar and click onto quit. Then launch Teams again.

    If it is showing, please click onto the settings icon, which is the ellipsis icon on the left-hand side of the notification icon.

    User's image

    Please then click onto "Settings"

    User's image

    Once the settings page loads, click onto "Accounts and Orgs" from the left-hand side menu

    User's image

    This will show all accounts and orgs each account belongs to on the main page. On that page, please click onto the door icon to leave that org.

    User's image

    You should get a prompt asking you if you are sure you would like to do this. Please click OK. This should then remove you from the org.

    Hope this helps,
    Nathan

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-06-14T19:39:59.87+00:00

    The scenario described (personal Microsoft account stuck as a guest in a former employer’s Microsoft Entra tenant, with Conditional Access blocking all self-service “Leave organization” paths and no responsive admin) is not directly solvable by end-user self-service based on the provided context.

    The relevant guidance in the context shows:

    • Guest accounts and B2B collaboration are controlled by the resource tenant’s admins. They can permanently delete guest users from Deleted users in the Microsoft Entra admin center, and permanent deletion can take up to 30 days for data removal.
    • For risky or blocked guest sign-ins, remediation is either self-service password reset (if enabled) or administrator action via the risky users portal. These flows all assume that the home tenant or resource tenant admins are available and that Conditional Access allows access to the remediation or “Leave organization” UI.
    • There is no documented Microsoft self-service or hidden URL in the context that allows a personal Microsoft account to unilaterally remove itself from a resource tenant when Conditional Access blocks all sign-in paths and the tenant’s admins are not responsive.
    • The context also indicates that when issues are not covered by documentation, the supported path is to use Microsoft’s standard support channels (“Learn how to get help and support”) or work with the organization’s IT/admins.

    From the provided material, the only supported resolution path is:

    1. The former employer’s Entra administrator must remove the guest account:
      • In the Microsoft Entra admin center, go to Users → Deleted users.
      • Select the deleted guest user and choose Delete permanently.
      • Data removal can take up to 30 days.
    2. If sign-in is blocked due to user risk or Conditional Access, the home or resource tenant admins must remediate or dismiss the risk using the risky users portal (for example, via https://aka.ms/RiskyUsers) or adjust Conditional Access so the guest can complete remediation.
    3. If the issue cannot be resolved with documentation and the tenant admins are not responsive, the documented next step is to use Microsoft’s general support options described in the “Need help?” section (for example, submitting a support request) and work through those channels. The context does not specify a special product category or a dedicated escalation channel for stale guest invitations beyond those general support options.

    No additional self-service mechanism, special URL, or specific support category for this exact scenario is documented in the provided context.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.