5
There is one thing which we found out last week when clients/customers invites our employees within teams for a channel used by their teams or share files from sharepoint. At this point a guest user is created within AAD within the clients/customer tenant.

When you login then as a Delegated Admin we don’t have enough rights. (because it’s finding a local user)

We discussed this last week with MS and they heared this before (“Teams adding users as guests”). But unfortunately it does conflict with the design – guest users are considered local users and therefore don’t get the same access as DA. This works as designed. MS relies on the delegated admin relationship when assigning DA rights. They cannot validate if a local guest user is also a DA – AAD does not provide an API for that, and we cannot provide any guest user with full access to BC, as that can be easily abused (free access to BC).
STATUS DETAILS
Declined
Ideas Administrator

Thank you for this suggestion! The issue is external to BC team. We've reached out to the AAD team, as the issue originates from that stack and they are looking into solving this for us (and other workloads experiencing the same issue). 

Best regards,
Dmitry Chadayev
Business Central Team