Thunderbird (OAuth) blocked for one Workspace, interfering with a second — Error 400: admin_policy_enforced
Hello, We need help with Mozilla Thunderbird and OAuth2 access to Google Workspace accounts. This worked for years and recently started failing. Setup — two SEPARATE Goog… (read more)
Hello,
We need help with Mozilla Thunderbird and OAuth2 access to Google Workspace accounts. This worked for years and recently started failing.
Setup — two SEPARATE Google Workspace organizations, in the same Thunderbird profile:
Workspace A — egkt.hu (separately administered) → does NOT block Thunderbird. Works fine on a clean machine where it is the only account. Workspace B — egyensulyintezet.hu (a different organization, different admin) → blocks Thunderbird with admin_policy_enforced.
Already tested / ruled out (NOT a client, machine or network issue): - A personal @gmail.com account (no Workspace policy) sends perfectly from the same Thunderbird. - egkt.hu works standalone on a clean macOS machine. - No antivirus/TLS interception (Defender scan clean, hosts file default, certificate valid), no proxy (system + Thunderbird), TCP to smtp.gmail.com:465 succeeds, fails on both office network and mobile hotspot, ports 465 and 587.
Our questions: For Workspace B (egyensulyintezet.hu): please confirm this is the API controls → App access control policy blocking third-party apps, and advise how to mark the Thunderbird OAuth client ID (above) as Trusted so users can use Thunderbird. Is it expected that a blocked account from one Workspace can interfere with the OAuth login of an account from a separate Workspace in the same Thunderbird profile? If so, how do we prevent that?
Thank you, Sebastian