Article ID: 2523192 - View products that this article applies to.
Expand all | Collapse all

PROBLEM

When you run the Azure Active Directory Sync tool, you notice that the user name of a user in Office 365, Azure, or Windows Intune doesn't match the user's on-premises user principal name (UPN) or alternate login ID. The UPN or alternate login ID could be the user's user name, email address, or some other attribute. 

CAUSE

There are three possible causes of this issue:
  • Your company domain is not yet verified. The domain of the on-premises UPN or alternate login ID is a domain that is not yet verified in your organizational account.
  • The cloud-managed user has a license. The user in your organizational account is not federated and was assigned a license.
  • The domain suffix of the UPN or alternate login ID has changed from one federated domain to another federated domain. 

SOLUTION

Scenario 1: Your company domain is not yet verified

Make sure that the domain suffix of the UPN or alternate login ID is verified in your organization. If you sync users before you verify the domain, the user name of the user is changed accordingly.
How to determine the domain suffix for a UPN
On a domain controller or on a computer on which the Windows Server Administration Toolkit is installed, follow these steps:
  1. Open Active Directory Users and Computers. To do this, click Start, click Run, type dsa.msc, and then click OK.
  2. Right-click the domain, and then click Find.
  3. In the Name box, type the user's display name, and then click Find Now.
  4. Double-click the user name in the search results, and then click the Account tab.
  5. Under User logon name, note the domain part of user logon name. This is known as the UPN suffix.

    Collapse this imageExpand this image
    User properties dialog box showing the user logon name
How to determine the domain suffix for an alternate login ID
On a domain controller or on a computer on which the Windows Server Administration Toolkit is installed, you can use Active Directory Service Interfaces Editor (ADSI Edit) to determine the domain suffix for an alternate login ID. To learn more about how to do this, see Using ADSI Edit to Edit Active Directory Attributes.

Note If the domain suffix isn't a registered domain, you must either register the domain by using a domain registrar or change the domain suffix of the user to a domain that's registered. This domain suffix must be registered by using a domain registrar before you can verify the domain in your organizational account.

Scenario 2: The cloud-managed user has a license

To update the UPN of a cloud-managed user who was assigned a license, follow these steps:
  1. Start the Azure Active Directory Module for Windows PowerShell, and then connect to Azure Active Directory (Azure AD). For more information about how to do this, go to the following Microsoft website:
    Connect to Azure AD Using Windows PowerShell
  2. Run the following Windows PowerShell cmdlet:

    Set-MsolUserPrincipalName -UserPrincipalName [CurrentUPN] -NewUserPrincipalName [NewUPN]

Scenario 3: The domain suffix of the UPN or alternate login ID changed from one federated domain to another federated domain

Follow the steps in the following Microsoft Knowledge Base article:
2669550 Changes aren't synced to Azure AD after you change the UPN of an on-premises user account to use a different SSO-enabled domain suffix

MORE INFORMATION

The Windows PowerShell commands in this article require the Azure Active Directory Module for Windows PowerShell. For more information, go to the following Microsoft website: For more information about how to add and verify a domain in Office 365, go to the following Microsoft website:
Add your domain to Office 365
For more information about how to update other synced attributes, click the following article number to view the article in the Microsoft Knowledge Base:
2643629 Individual Active Directory Domain Services objects don't sync to Windows Azure AD
Still need help? Go to the Office 365 Community website or the Azure Active Directory website.

Properties

Article ID: 2523192 - Last Review: April 19, 2014 - Revision: 46.0
Applies to
  • Windows Azure
  • Microsoft Office 365
  • Microsoft Office 365 for enterprises (pre-upgrade)
  • Microsoft Office 365 for education  (pre-upgrade)
  • CRM Online via Office 365 E Plans
  • Windows Azure Recovery Services
Keywords: 
o365 o365a o365e kbgraphxlink o365m o365022013 after upgrade o365062011 pre-upgrade kbgraphic KB2523192

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com