User names of users in your organizational account such as Office 365, Windows Azure, or Windows Intune don't match the on-premises UPNs

Article translations Article translations
Article ID: 2523192 - View products that this article applies to.
Expand all | Collapse all

PROBLEM

When you run the Windows Azure Active Directory Sync tool, you notice that the user name of a user in your organizational account such as Office 365, Windows Azure, or Windows Intune doesn't match the user's on-premises user principal name (UPN).

CAUSE

There are two possible causes of this issue:
  • Your company domain is not yet verified. The UPN suffix of the on-premises user is a domain that is not yet verified in your organizational account.
  • The cloud-managed user has a license. The user in your organizational account is not federated and was assigned a license.

SOLUTION

Scenario 1: Your company domain is not yet verified

Make sure that the UPN suffix domain is verified in your organization. If you sync users before you verify the domain, the user name of the user is changed accordingly.
How to determine the UPN suffix for a user
On a domain controller or on a computer on which the Windows Server Administration Toolkit is installed, follow these steps:
  1. Open Active Directory Users and Computers. To do this, click Start, click Run, type dsa.msc, and then click OK.
  2. Right-click the domain, and then click Find.
  3. In the Name box, type the user's display name, and then click Find Now.
  4. Double-click the user name in the search results, and then click the Account tab.
  5. Under User logon name, notice the domain part of user logon name. This is known as the UPN suffix.

    Collapse this imageExpand this image
    User properties dialog box showing the user logon name
Note If the UPN suffix isn't a registered domain, you must either register the domain with a domain registrar or change the UPN suffix of the user to a domain that's registered. This UPN suffix must be registered with a domain registrar before you can verify the domain in your organizational account.

Scenario 2: The cloud-managed user has a license

To update the UPN of a cloud-managed user who was assigned a license, follow these steps:
  1. Start the Windows Azure Active Directory Module for Windows PowerShell, and then connect to Windows Azure Active Directory (Windows Azure AD). For more information about how to do this, go to the following Microsoft website:
    Connect to Windows Azure AD Using Windows PowerShell
  2. Run the following Windows PowerShell cmdlet:

    Set-MsolUserPrincipalName -UserPrincipalName [CurrentUPN] -NewUserPrincipalName [NewUPN]

MORE INFORMATION

The Windows PowerShell commands in this article require the Windows Azure Active Directory Module for Windows PowerShell. For more information, go to the following Microsoft website: For more information about how to add and verify a domain in Office 365, go to the following Microsoft website:
Add and verify a domain name
For more information about how to update other synced attributes, click the following article number to view the article in the Microsoft Knowledge Base:
2643629 Individual Active Directory Domain Services objects don't sync to Windows Azure AD
Still need help? Go to the Office 365 Community website or the Windows Azure Active Directory website.

Properties

Article ID: 2523192 - Last Review: October 31, 2013 - Revision: 44.0
Applies to
  • Windows Azure
  • Microsoft Office 365
  • Microsoft Office 365 for enterprises (pre-upgrade)
  • Microsoft Office 365 for education  (pre-upgrade)
  • CRM Online via Office 365 E Plans
  • Windows Azure Recovery Services
Keywords: 
o365 o365a o365e kbgraphxlink o365m o365022013 after upgrade o365062011 pre-upgrade kbgraphic KB2523192

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com