Forum Discussion
The Unnecessary Complexity of Microsoft 365 & Outlook Classic: A UX Admin Nightmare for BYOD
I recently needed to remove a corporate Exchange account from a personal device running Microsoft 365. What should have been a one-click action exposed a deeply flawed and convoluted architecture:
Primary Account Lock: Outlook Classic fundamentally prevents the removal of a "Primary Account" from its GUI. The only functional workaround is completely destroying the Outlook profile via the Control Panel or Registry.
MDM Overreach on BYOD: When adding a work account, MDM and Entra ID policies immediately override local user control. There is zero clear exit strategy or automated cleanup for the end-user when that corporate relationship ends.
Monolithic Click-To-Run Architecture: Attempting to simply uninstall the obsolete Outlook Classic application is impossible through standard Windows settings. It required deploying the Office Deployment Tool (ODT) and executing a custom XML configuration script just to exclude a single application from the Microsoft 365 suite.
This forced integration and lack of modularity is a highly anti-user experience. Microsoft must separate corporate security enforcement from personal device ownership and provide standard, modular uninstallation options for its desktop applications. Forcing users to use PowerShell and ODT for basic software management is an unacceptable standard for modern UX.
1 Reply
Just to clear some confusion;
In this scenario, there is a "work" part of the computer and a "personal" part of the computer.
The "work" part isn't intended to be managed by the end-user so the "highly anti-user experience" is expected as it is to be operated by corporate admins. If the user is expected to customize XML-files and use PowerShell to install Office or manage their computer for the "work" part, the admin isn't doing its job.
There is no "MDM overreach on BYOD" but just the settings of the "work" part being enforced when joining your own computer to their network. It's your choice to add your own personal device and you accept that they are enforcing their policies by joining. You can ask which settings they enforce before joining and then decide whether you still want to use your own computer for that.
Note that it is perfectly possible to add an Exchange account of another company to your own personal computer without enrolling your computer into their MDM systems. Whether or not the company allows that is another thing, but it is not an Outlook nor an MDM restriction or overreach.
If the license for Office is part of the "work" part, then so is its deployment of components and its configuration. When changes need to be made to this, it has to be requested by the user to the company which owns the license and manages the "work" part.
If the relationship with the company ends, the software needs to be removed as well since there is no longer a license for it. The user can choose to reinstall/reactivate it again with its own license. Installing Office with or without Classic Outlook doesn't make (much of) a difference installation footprint wise as all Office applications are basically based on the same shared libraries and components.
Not being able to remove the primary account is a general limitation of Outlook unrelated to whether the computer is Work joined. This limitation doesn't exist in New Outlook but they can enforce that they are the primary account to make sure that their corporate (security) policies and application restrictions are applied.
Just like in Classic Outlook, in these cases it is recommended to separate your work accounts from your private accounts by using multiple Mail Profiles in New Outlook.Removing a Mail Profile for Classic Outlook via the Registry isn't recommended nor supported as a Mail Profile consists of a combination of Registry settings and files. Deleting it via the Registry will orphan the files and could lead to other issues later on.