Skip to content

Instantly share code, notes, and snippets.

@terrillmoore
Created January 28, 2026 18:11
Show Gist options
  • Select an option

  • Save terrillmoore/7b055cc946756ae0491a48ef80c6ae69 to your computer and use it in GitHub Desktop.

Select an option

Save terrillmoore/7b055cc946756ae0491a48ef80c6ae69 to your computer and use it in GitHub Desktop.
Resolving Personal MSA / Work M365 Email Address Collision

Resolving Personal MSA / Work M365 Email Address Collision

Problem

A user has a personal Microsoft account (MSA) using their work email address (e.g., userid@example.com), which conflicts with the organization's M365 tenant where example.com is a verified domain. This causes "Work or school account?" prompts and prevents using the work email as the M365 sign-in.

Prerequisites

  • User has an alternate email address they control (e.g., Gmail, Yahoo)
  • Admin access to M365 tenant
  • Your domain (example.com) is already a verified domain on the tenant

Part 1 — User releases the email from their personal MSA

  1. Sign into the personal MSA at account.live.com/names/manage
  2. Add a new alias (their personal Gmail, Yahoo, etc.)
  3. Verify the new alias via the confirmation email
  4. Set the new alias as primary
  5. Remove the work email address (e.g., userid@example.com) from the account

Store purchases, Visual Studio subscriptions, and other MSA-linked assets remain intact—they follow the account, not the alias.

Part 2 — Admin assigns the email to the M365 account

  1. Sign into admin.microsoft.com
  2. Go to Users → Active users → select the user
  3. Add the released email as an alias (Manage email aliases)
  4. Optionally, set it as the primary username/UPN

Part 3 — Post-change cleanup

  1. Sign out of Teams completely, then sign back in with the new identity. Teams may show a stale cached entry for the old account—ignore it and sign into the correct account.
  2. Reboot Windows devices to clear cached credentials.
  3. Sysadmin should work with the user to verify all M365 services are authenticating correctly (Outlook, OneDrive, SharePoint, etc.). Expect some re-authentication prompts.

Notes

  • The .onmicrosoft.com address (e.g., userid@example.onmicrosoft.com) is retained automatically and cannot be removed
  • OneDrive URLs retain the original UPN structure (cosmetic only)
  • Some apps may retain stale account entries in their picker UI even after successful migration
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment