Microsoft Intune’s latest weekly update brings a quietly significant change for organizations managing multiple tenants: Multiple Managed Accounts (MMA) support is now extended to Microsoft Outlook on iOS/iPadOS (version 5.2626.0 or later).
If you’re an MSP, consultant, or IT admin supporting multiple organizations, this is the update you’ve been waiting for. Here’s what changed, why it matters, and what you should do about it.
What Is Multiple Managed Accounts?
Multiple Managed Accounts (MMA) is an Intune Mobile Application Management (MAM) capability that allows users to add and manage more than one managed work account within a single app instance — with app protection policies applied independently for each account.
Until now, MMA was only available in Microsoft Teams on iOS/iPadOS (v8.10.0 or later), which Microsoft introduced in service release 2605. The extension to Outlook represents the second app to support this capability, and it’s the one many multi-tenant professionals have been asking for.
Key behavioral details:
- Each account is a separately managed work identity tied to its own Intune tenant
- App protection policies (APP) are evaluated and enforced per account, not per app
- Access settings (PIN, biometrics, jailbreak checks, minimum OS) are evaluated per account at app open
- Data protection controls (copy/paste restrictions, Save As blocking, encryption) are enforced based on the currently active account’s policy
- MMA requires explicit Intune SDK integration — wrapped apps are not supported
Why Outlook MMA Matters
For anyone managing multiple work identities — consultants, MSP engineers, shared-services IT staff, or employees going through mergers and acquisitions — Outlook has always been the pain point. You could add multiple accounts to the app, but only one could be MAM-managed at a time. That meant:
- Constant sign-out/sign-in cycles when switching between tenant mailboxes
- Using a second device or alternate mail app for the “other” organization
- No DLP protection on the unmanaged account
With MMA in Outlook, a consultant can now have Tenant A’s mailbox and Tenant B’s mailbox side by side in the same Outlook app, each protected by its own organization’s app protection policies. No switching apps. No losing DLP coverage. No second phone.
How Data Isolation Works
This is the technical part that matters for security and compliance teams.
Each managed account in Outlook functions as its own logical work data container. Intune’s MAM framework encrypts and tags organizational data per account, ensuring that Tenant A’s email data is treated differently from Tenant B’s.
Practical example:
| Scenario | Tenant A Policy | Tenant B Policy | Behavior |
|---|---|---|---|
| Copy from Tenant A email, paste into personal notes | Block copy/paste to unmanaged apps | N/A | Blocked — Tenant A’s policy applies |
| Save attachment from Tenant B mailbox | N/A | Allow save to OneDrive for Business only | Allowed, but only to Tenant B’s OneDrive |
| Forward Tenant A email to Tenant B mailbox | Block send to external recipients | Allow internal forwarding | Blocked by Tenant A’s outgoing policy |
The policies don’t blend. The correct policy applies only when using that account’s data. Cross-account interactions are evaluated under the originating account’s rules, preventing data leakage between tenants.
Outlook is classified as a “mixed view app” — it displays both organizational and personal data in a unified interface — but the MAM framework handles the segregation and protection per identity behind the scenes.
Admin Considerations: What to Plan For
1. Policy Design Across Tenants
Since policies are per-account, not per-app, you can safely configure different PIN requirements, data protection rules, and access settings for each tenant — even though the same Outlook binary is used. If Tenant A requires a 6-digit PIN and biometrics and Tenant B only requires a 4-digit PIN, both policies coexist independently.
2. Conditional Launch Behavior
Jailbreak/root checks, device health requirements, and other conditional launch controls are independently evaluated per account. A device might be allowed for one tenant but blocked for another, resulting in partial functionality — one mailbox accessible, the other not. Plan for this scenario in your support documentation.
3. MAM-Only vs. MDM+MAM Targeting
MMA applies to MAM-managed accounts, including MAM-only (without full MDM enrollment). Ensure that MAM-only user groups are correctly targeted in each tenant so there are no gaps where one tenant’s account has no APP policy while another is fully protected.
4. User Education
Users need to understand that behavior may differ depending on which mailbox they’re using. Copy/paste, save, and open-in behaviors can change based on the active account’s policy. This is especially important for users who work across tenants with different security postures.
5. Rollout Timing
Microsoft notes that this feature is rolling out gradually and may not yet be available in your tenant. Don’t assume all users will see multiple managed account support immediately. Test with a pilot group first.
Known Limitations
- iOS/iPadOS only — Android support is coming but has no ETA
- Outlook v5.2626.0 or later required — verify users are on the minimum version
- Intune SDK integration required — wrapped apps are not supported
- Gradual rollout — some tenants may not see the feature yet
- Two apps supported so far — Teams and Outlook; additional apps and platforms are “coming soon”
What Apps Might Get MMA Next?
Microsoft hasn’t published a definitive roadmap, but the logical candidates based on multi-identity scenarios include:
- OneDrive — multi-tenant file access
- Microsoft 365 mobile app — unified Office experience
- Planner / Microsoft To Do — cross-tenant task management
- Android platform support — the most requested expansion
Given that MMA is a generic Intune SDK capability, any Microsoft 365 mobile app that already integrates with Intune MAM is a candidate. Watch the Intune What’s New page for each service release.
Recommended Actions
- Verify Outlook version — ensure targeted users are on iOS/iPadOS Outlook v5.2626.0 or later
- Review APP policies per tenant — confirm each tenant’s app protection policies are correctly scoped and don’t conflict with each other in ways that would confuse users
- Pilot with multi-tenant users — identify consultants or MSP staff who manage multiple tenants and test the experience before broad communication
- Update user documentation — explain that copy/paste, save, and sharing behavior may differ between accounts
- Monitor rollout status — check the Intune admin center for feature availability in your tenant
- Plan for Android — if you have multi-tenant users on Android, they’ll need to wait for platform support
Summary
The extension of Multiple Managed Accounts to Outlook on iOS/iPadOS is a focused but meaningful update for multi-tenant organizations. It eliminates one of the most persistent friction points in Intune MAM — the inability to protect multiple work accounts in the same email app — and brings Outlook in line with what Teams already offered.
For MSPs, consultants, and IT staff juggling multiple organizations, this means fewer devices, less context switching, and consistent DLP protection across all managed identities. It’s not a headline-grabbing feature, but it’s the kind of practical improvement that makes day-to-day work significantly easier.
As Microsoft continues to expand MMA to additional apps and platforms, expect multi-identity management to become a standard expectation rather than a nice-to-have. Plan your policies now so you’re ready when the next app gets support.
Follow Kevin on X/Twitter at https://x.com/kkaminski for more Intune and endpoint management content.