question

ShaunJohnson-0311 avatar image
0 Votes"
ShaunJohnson-0311 asked ·

UPNs Change After Adding New Federated Domain to Azure

Morning,

I wonder if anyone here has seen this behaviour before, I'm trying to understand how something happened for a client and 365 support basically told me they cant tell me anything useful and we have to pay for Azure support - which obviously no one wants to do.

We have a federated domain that we use for Office 365. A new subdomain of that domain was added using powershell. At the next AD Sync, it seems that every user account was touched, which I suppose is expected as it checks for the presence of the new domain. However, for a few accounts, changes were made that we cannot explain. One account ended up with an entirely new UPN, which was a breaking change for a customers process. A few other accounts either lost of gained a proxy address, although these were non breaking changes.

Is anyone able to explain why this happens?

azure-ad-connectazure-ad-domain-servicesazure-ad-user-provisioning
· 4
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@ShaunJohnson-0311
Thank you for your post and I apologize for the delayed response!

  • When it comes to the changes to the one user's UPN was there anything that could've caused it?

  • Did it happen to any other users or just this one?

  • Was there anything special about this one user compared to the others?

  • As for the proxy address, can you share some details regarding it? Some accounts either lost or gained a proxy address?

Any additional details or screenshots would be greatly appreciated!


I've also added the azure-ad-connect and azure-ad-domain-services tag to this thread to see if anyone in these communities have experienced anything similar.

If you have any other questions, please let me know.
Thank you!

0 Votes 0 ·

When it comes to the changes to the one user's UPN was there anything that could've caused it?
No changes were made to the user, but a new ADFS domain was added

Did it happen to any other users or just this one?
jJust this one. Although proxy addresses changed for 4 other users

Was there anything special about this one user compared to the others?
Not that I can see.

As for the proxy address, can you share some details regarding it? Some accounts either lost or gained a proxy address?
Yes, some lost, some gained and one had its default change, about one of each - I forget the specifics

0 Votes 0 ·

@ShaunJohnson-0311
Have you already looked at the AAD Connect synchronization service logs?
Normally you should be able to track the changes to Azure AD and on-premises AD objects there.

0 Votes 0 ·

Yes, but nothing jumped out at me

0 Votes 0 ·

0 Answers