This would let Azure AD skip asking which identity to use, when the user has logged in to Azure AD with an identity from our company and also with an identity from a partner company. The Azure app registration for the Jenkins instance has already been configured as supporting accounts from “My organization only”, so if the user chooses the other identity, then the login fails (“Selected user account does not exist in tenant”).