Skip to main content

๐Ÿ›ก๏ธ๐Ÿง‘โ€๐Ÿ’ผ๐Ÿ‘ˆ๐Ÿ”“Group - Multi tenant Teams Allowed users

What this group is for ๐ŸŽฏโ€‹

This is the exception group linked to:

Members of this group are explicitly allowed to sign into Microsoft Teams with accounts from other tenants.


When to use it (and when not to) ๐Ÿงโ€‹

Legitimate use cases include:

  • Mergers & acquisitions โ€” joint Teams collaboration before a full migration
  • Cross-tenant migrations โ€” staged moves where users need temporary access to both tenants
  • Partner or supplier projects โ€” close collaboration in a shared environment

๐Ÿšซ Not a use case:

  • โ€œI just want to check my old work accountโ€
  • โ€œI have a friend in another company and itโ€™s easier this wayโ€
  • Anything that sounds like โ€œjust for nowโ€ without a documented plan

Governance Notes ๐Ÿ“œโ€‹

This group should:

  • Have written customer approval for each member
  • Be reviewed regularly to remove stale access
  • Be empty by default in most tenants

Think of it like a secure keycard โ€” if youโ€™re not actively walking through that door, you shouldnโ€™t be holding one.


๐Ÿ’ก SuperVision Tipโ€‹

SuperVision can:

  • Keep this groupโ€™s name consistent across all tenants
  • Let you manage membership centrally without editing the Intune policy
  • Automatically remove users when a project or migration ends

Final Thoughts ๐Ÿ”šโ€‹

Exception groups are like sharp tools โ€” theyโ€™re great in the right hands, but dangerous if left lying around.

Use them:

  • With purpose
  • With documentation
  • And with a healthy dose of skepticism