How to sync UPN in AD Domain Services and UPN that is already available/created using Microsoft 365 AD Portal?

M Hafiz Kamaruzaman 0 Reputation points
2023-10-11T15:55:51.3733333+00:00

Hi,
My company is migrating to Microsoft 365 and merging all on-premises AD into Microsoft Entra. Initially we have created users in Microsoft 365 Identity Portal (manually) for Microsoft PowerBI access. Problem occurs when we try to merge the UPN with UPN as per on-premise AD to UPN in Identity Portal, the user lost all his access to the PowerBI workspaces and all PowerBI attributes, even though the same UPN is used.
We suspected that event though the same UPN is used, but the objectID stored in PowerBI service is different, hence the updated UPN is treated as new account in PowerBI Service.

My question is, is there a way to merge this two accounts (same UPN) and merge all the attributes that PowerBI services stored?

Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,087 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2023-10-11T15:55:51.3766667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    To merge an on-premises Active Directory UPN with a UPN created in the Microsoft 365 Identity Portal, you can use UPN matching. UPN matching is a process that uses the user principal name (UPN) to match the on-premises user account to a work or school account in Azure AD. To start the UPN matching process, you need to obtain the UPN from the user account in Azure AD, create a user account or update an existing user account in Active Directory Users and Computers with a user name/UPN that matches the target user account in Azure AD, and force directory synchronization.

    However, it's important to note that UPN matching has technical limitations, such as only being able to run when SMTP matching fails and being able to use UPN matching only one time for user accounts that were originally authored by using Office 365 management tools. Additionally, the cloud user's UPN can't be updated during the UPN matching process, and UPNs are considered unique values, so you need to make sure that no two users have the same UPN.

    If the UPN matching process doesn't work for your situation, you may need to contact Microsoft support for further assistance.


    References:

    0 comments No comments