Blog Post

Microsoft Entra Blog
1 MIN READ

Enable user-friendly sign-in to Azure AD with email as an alternate login ID

Alex_Simons's avatar
Alex_Simons
Icon for Microsoft rankMicrosoft
Jul 13, 2020

Howdy folks,

 

Today we’re announcing the public preview of the ability to sign-in to Azure AD with email in addition to UPN (UserPrincipalName). In organizations where email and UPN are not the same, it can be confusing for users when they can't use their familiar email address to sign-in. With this preview capability, you can enable your users to sign in with either their UPN or their email address, helping them avoid this confusion.

 

This feature can be enabled by setting the AlternateIdLogin attribute in the HomeRealmDiscoveryPolicy. Please use the instructions in our documentation to set this up in your organization.

 

Some customers are using capabilities in Azure Active Directory (Azure AD) Connect to achieve this today, but that requires them to set the email address as the UPN in Azure AD. With this preview capability, you can now use the same UPN across on-premises Active Directory and Azure AD to achieve the best compatibility across Office 365 and other workloads, while still allowing your users to sign in with either their UPN or email, further simplifying their experience.

 

We hope this change simplifies the sign-in experience for your end users.

 

As always, we’d love to hear any feedback or suggestions you may have. Please let us know what you think in the comments below or on the Azure AD feedback forum. 


Stay safe and be well,

Alex Simons (@Alex_A_Simons)

Corporate VP of Program Management

Microsoft Identity Division

Updated Aug 03, 2020
Version 17.0

48 Comments

  • pmahlmann's avatar
    pmahlmann
    Copper Contributor

    we need this as we are doing a domain migration but are affected by duplicate UPNs in both domains which blocks domain trust routing.  This feature will allow us to change the UPN in one domain and then use email to log into Azure/Office365.  when will this be GA.

     

  • hobbycat's avatar
    hobbycat
    Copper Contributor

    @Alex

     

    This is great news and will benefit many of us.

     

    I implemented this in a non-production environment yesterday, on the whole it went well. However, it uncovered something that I would like clarity on, if there is contention between a UPN (cloud only account) and a proxy/email address on a sync'd account for example - which will take precedence? This is not a situation that I was expecting to encounter but it existed. From some the limited testing, it appears the account with email address wins, whereas I would have expected the UPN to take precedence.

     

    There was also a delay of upwards 20 minutes from creating the policy to seeing the change in behaviour. If this is expected then it would be helpful if the documentation reflected this.

  • Thanks for releasing this AAD Team! It is huge for companies that do not have matching UPNs and email addresses.

  • belaie's avatar
    belaie
    Brass Contributor

    This is nice feature, but in our azuread , our primary email addresses on users are very long and are generated based on user full names for users its more convenient to login with UPN which is based on users' usernames. It would be cool if all Microsoft login screen text should say "username" not an email address to log in, which would help users following company's internal username policy  (email or UPN) to login to the cloud services.

  • patrick410's avatar
    patrick410
    Copper Contributor

    Hello Alex, does this function work when logging in O365 connected workstations?

  • diogocatossi's avatar
    diogocatossi
    Copper Contributor

    Great news! It's always good to make user's lives easier and simplified! 

  • Alex

    Cool!!! much awaited feature...

     

    So I f I use UPN to sync my users but their SMTP is different, still my users can login to azure/office 365 with their SMTP email id, right?

     

    Do I must sync my email domain to accomplish this or just verify the domain in office 365 ?