Home

Changing UPN userPrincipalName attribute

%3CLINGO-SUB%20id%3D%22lingo-sub-182761%22%20slang%3D%22en-US%22%3EChanging%20UPN%20userPrincipalName%20attribute%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-182761%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EWe%20have%20a%20AD%20forest%20with%20multiple%20domains%20but%20for%20the%20most%20part%20all%20or%20most%20of%20our%20resources%20are%20managed%20in%20one%20of%20the%20primary%20or%20corp%20ad%20domain%2C%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3EWe%20now%20are%20in%20process%20of%20syncing%20user%20ID's%20to%20Office%20365%2C%20we%20have%20our%20internal%20domain%20verified%20on%20our%20tenant%20and%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3Ewe%20also%20have%20federation%20setup%20using%20PingFederate%20with%20Office%20365%20and%20we%20will%20change%20value%20of%20upn%20attribute%20on%20the%20account%20from%20its%20current%20value%20to%20users'%20primary%20email%20address%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3EWe%20have%20many%20users%20who%20have%20upn%20matching%20to%20samaccountname%20%2B%20domain%20suffix%20that%20is%20iUPN%20and%20eUPN%20concept%20by%20the%20way%20we%20dont%20have%20any%20additional%20domain%20suffixes%20in%20the%20environment%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3ESo%20coming%20back%20to%20my%20query%20we%20have%20tried%20our%20best%20to%20identify%20or%20find%20out%20if%20there%20is%20anyone%20application%20%2F%20user%20using%20upn%20for%20authentication%20so%20far%20none%20of%20our%20investigation%20has%20shown%20upn%20is%20being%20used%2C%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3EThere%20could%20be%20users%20who%20are%20used%20to%20or%20are%20habitual%20to%20use%20upn%20to%20sign%20in%20into%20devices%20and%20applications%20for%20e.g.%20desktop%20%E2%80%93%20laptop%20devices%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3EWhen%20the%20machine%20is%20at%20Ctrl%20%2B%20Alt%20%2B%20Del%20and%20user%20is%20used%20to%20sign%20in%20using%20UPN%20which%20is%20by%20default%20samAccountName%20%2B%20domain%20suffix%20which%20might%20not%20be%20equal%20to%20email%20of%20user%20then%20what%20%3F%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3EOther%20scenarios%20which%20we%20are%20not%20aware%20of%20legacy%20devices%20like%20windows%20xp%20or%20manufacturing%20application%20%2F%20device%20%3F%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3Eand%20As%20per%20iUPN-eUPN%20concept%20mentioned%20above%20it%20says%20if%20your%20tracking%20kerberos%20tickets%20to%20find%20out%20kerberos%20tickets%20are%20always%20with%20iUPN%20which%20is%20samAccountName%20%2B%20domain%20suffix%20and%20not%20against%20the%20name%20or%20value%20you%20see%20in%20upn%20attribute%20of%20the%20user%20or%20account%20for%20that%20matter%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3ESo%20I%20need%20to%20know%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%3E1.%20the%20right%20way%20of%20tracking%20and%20finding%20out%20who%20(Appr%20or%20any%20user)%20is%20using%20UPN%20for%20logon%2Flogin%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3E2.%20What%20are%20the%20know%20issues%20or%20impacts%20of%20changing%20the%20UPN%20in%20Active-Directory%20for%20AD%20Accounts%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-182761%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EUPN%20userPrincipalName%20attribute%20implicit%20explicit%20upn%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Frequent Contributor

We have a AD forest with multiple domains but for the most part all or most of our resources are managed in one of the primary or corp ad domain,

We now are in process of syncing user ID's to Office 365, we have our internal domain verified on our tenant and
we also have federation setup using PingFederate with Office 365 and we will change value of upn attribute on the account from its current value to users' primary email address

We have many users who have upn matching to samaccountname + domain suffix that is iUPN and eUPN concept by the way we dont have any additional domain suffixes in the environment

So coming back to my query we have tried our best to identify or find out if there is anyone application / user using upn for authentication so far none of our investigation has shown upn is being used,
There could be users who are used to or are habitual to use upn to sign in into devices and applications for e.g. desktop – laptop devices
When the machine is at Ctrl + Alt + Del and user is used to sign in using UPN which is by default samAccountName + domain suffix which might not be equal to email of user then what ?
Other scenarios which we are not aware of legacy devices like windows xp or manufacturing application / device ?

and As per iUPN-eUPN concept mentioned above it says if your tracking kerberos tickets to find out kerberos tickets are always with iUPN which is samAccountName + domain suffix and not against the name or value you see in upn attribute of the user or account for that matter

So I need to know

1. the right way of tracking and finding out who (Appr or any user) is using UPN for logon/login
2. What are the know issues or impacts of changing the UPN in Active-Directory for AD Accounts

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
30 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies