Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

ఇంకా తెలుసుకోండి
Open

Thunderbird (OAuth) blocked for one Workspace, interfering with a second — Error 400: admin_policy_enforced

Szebasztián Ollári

Hello,

We need help with Mozilla Thunderbird and OAuth2 access to Google Workspace accounts. This worked for years and recently started failing.

Setup — two SEPARATE Google Workspace organizations, in the same Thunderbird profile:

Workspace A — egkt.hu (separately administered) → does NOT block Thunderbird. Works fine on a clean machine where it is the only account. Workspace B — egyensulyintezet.hu (a different organization, different admin) → blocks Thunderbird with admin_policy_enforced.

Already tested / ruled out (NOT a client, machine or network issue): - A personal @gmail.com account (no Workspace policy) sends perfectly from the same Thunderbird. - egkt.hu works standalone on a clean macOS machine. - No antivirus/TLS interception (Defender scan clean, hosts file default, certificate valid), no proxy (system + Thunderbird), TCP to smtp.gmail.com:465 succeeds, fails on both office network and mobile hotspot, ports 465 and 587.

Our questions: For Workspace B (egyensulyintezet.hu): please confirm this is the API controls → App access control policy blocking third-party apps, and advise how to mark the Thunderbird OAuth client ID (above) as Trusted so users can use Thunderbird. Is it expected that a blocked account from one Workspace can interfere with the OAuth login of an account from a separate Workspace in the same Thunderbird profile? If so, how do we prevent that?

Thank you, Sebastian

Hello, We need help with Mozilla Thunderbird and OAuth2 access to Google Workspace accounts. This worked for years and recently started failing. Setup — two SEPARATE Google Workspace organizations, in the same Thunderbird profile: Workspace A — egkt.hu (separately administered) → does NOT block Thunderbird. Works fine on a clean machine where it is the only account. Workspace B — egyensulyintezet.hu (a different organization, different admin) → blocks Thunderbird with admin_policy_enforced. Already tested / ruled out (NOT a client, machine or network issue): - A personal @gmail.com account (no Workspace policy) sends perfectly from the same Thunderbird. - egkt.hu works standalone on a clean macOS machine. - No antivirus/TLS interception (Defender scan clean, hosts file default, certificate valid), no proxy (system + Thunderbird), TCP to smtp.gmail.com:465 succeeds, fails on both office network and mobile hotspot, ports 465 and 587. Our questions: For Workspace B (egyensulyintezet.hu): please confirm this is the API controls → App access control policy blocking third-party apps, and advise how to mark the Thunderbird OAuth client ID (above) as Trusted so users can use Thunderbird. Is it expected that a blocked account from one Workspace can interfere with the OAuth login of an account from a separate Workspace in the same Thunderbird profile? If so, how do we prevent that? Thank you, Sebastian

You must log in to your account to reply to posts. Please start a new question, if you do not have an account yet.