Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium

A company policy dictates that all users must have their user principal name (UPN) match their primary email address. The company uses Azure AD Connect to synchronize identities from an on-premises Active Directory Domain Services (AD DS) forest. Some users currently have a UPN suffix that does not match their email domain, and these users are experiencing issues signing in to Azure AD applications. What is the most effective solution to resolve this issue and align with company policy?

  1. AModify the UPN suffix on-premises to match the email domain and ensure it's a verified custom domain in Azure AD.
  2. BImplement Azure AD Pass-through Authentication (PTA) to handle the UPN mismatch.
  3. CSet the `AlternateLoginId` attribute in Azure AD Connect synchronization rules.
  4. DConfigure a custom domain in Azure AD that matches the email domain and set it as verified.
Show answer & explanation

Correct answer: A. Modify the UPN suffix on-premises to match the email domain and ensure it's a verified custom domain in Azure AD.

To resolve sign-in issues and align UPN with email, the UPN suffix must be a verified custom domain in Azure AD. The most effective solution is to correct the UPN suffix in the on-premises Active Directory to match the email domain, ensuring it is also a verified custom domain in Azure AD. Azure AD Connect will then synchronize the corrected UPN.

Why the other options are wrong

  • B. PTA is an authentication method and does not resolve UPN mismatch issues; it relies on the UPN being correctly configured for authentication.
  • C. AlternateLoginId is used when the UPN cannot be used as the sign-in ID, typically for a different attribute like email address. While it could allow sign-in, the policy explicitly states that 'all users must have their UPN match their primary email address', requiring a UPN correction, not an alternate login ID.
  • D. Configuring a custom domain in Azure AD is necessary, but it doesn't automatically correct the on-premises UPN suffix or resolve the sign-in issues stemming from the mismatch if the on-premises UPN isn't updated.

UPN Suffix Management (Hybrid Identity)

In a hybrid identity environment, for users synchronized from on-premises AD DS, their User Principal Name (UPN) suffix must correspond to a verified custom domain in Azure AD. Mismatched UPNs can lead to sign-in failures for cloud applications.

  • On-premises UPN suffix must be added as a custom domain in Azure AD.
  • The custom domain must be verified in Azure AD.
  • Changing the UPN on-premises will synchronize to Azure AD via Azure AD Connect.

Memory trick: UPN mismatch is like a wrong address on your ID – fix it at the source, then verify the domain.

More Implement an authentication and access management solution questions