Microsoft Certified: Azure Administrator AssociateImplement and manage hybrid identitiesHard

A company is using Azure AD Connect to synchronize user identities from their on-premises Active Directory. They need to ensure that the userPrincipalName (UPN) used for signing into Azure AD matches the user's primary email address, which is stored in the 'mail' attribute in on-premises AD. The default UPN suffix in on-premises AD is 'internal.local', but their verified custom domain in Azure AD is 'contoso.com'. Which action should they take in Azure AD Connect to achieve this?

  1. AConfigure a custom synchronization rule to map 'mail' to 'userPrincipalName'.
  2. BAdd 'contoso.com' as an alternative UPN suffix in on-premises Active Directory.
  3. CDisable UPN suffix validation in Azure AD.
  4. DEnable Password Hash Synchronization.
Show answer & explanation

Correct answer: A. Configure a custom synchronization rule to map 'mail' to 'userPrincipalName'.

To ensure the UPN in Azure AD matches the 'mail' attribute and uses the 'contoso.com' suffix, a custom synchronization rule is required. This rule would take the value from the 'mail' attribute (e.g., user@contoso.com) and map it to the 'userPrincipalName' attribute for Azure AD provisioning.

Why the other options are wrong

  • B. Adding 'contoso.com' as an alternative UPN suffix on-premises allows users to have UPNs ending in 'contoso.com' in on-premises AD, but doesn't automatically make the UPN match the 'mail' attribute if they are different in on-premises AD.
  • C. Disabling UPN suffix validation is not recommended for security and manageability, and it doesn't solve the problem of making the UPN match the mail attribute; it only allows unverified UPNs.
  • D. PHS is an authentication method and does not directly control UPN mapping or attribute flow.

Azure AD Connect Custom UPN Mapping

Configuring Azure AD Connect synchronization rules to use a specific on-premises attribute (e.g., 'mail') as the source for the userPrincipalName (UPN) in Azure AD.

  • Crucial when on-premises UPNs do not match desired Azure AD UPNs or primary email addresses.
  • Requires creating or modifying synchronization rules in the Synchronization Rules Editor.
  • Ensures consistent sign-in experience and proper identity representation in Azure AD.

Memory trick: To make the 'sign-in name' echo the 'email', 'map' it with a 'custom rule'.

More Implement and manage hybrid identities questions