AAD Claims UPN vs On-Premise AD UPN

540 Views Asked by At

I thought UserPrincipalName (UPN) are single valued per user in the Directory, but when I run an LDAP query for a specific user, I get the UPN: [email protected],

And when running an OAuth (OpenId Connect) authorization against Azure AD (which is synced using AD Connect), I see that the claims UPN for the same user: [email protected]

What am I missing here?

1

There are 1 best solutions below

4
On BEST ANSWER

You are missing the concept of Alternate login id.

It seems your Azure AD connect is configured with alternate login id. Thus the difference.