Set up a SAML-based sign-on using both default user.userprincipalname OR email aliases/domains

Ryan Voloch 0 Reputation points
2023-11-24T21:52:11.99+00:00

Hi,

I have custom Enterprise Applications SAML SSO with apps working for users who previously set up accounts within the app using the email address that matches their user.userprincipalname. (see screenshot example below)

My challenge is that users have created accounts in apps using different domains/email aliases making SSO migration difficult. When we go to enable SAML SSO, it's a challenge to get users to change their email address/user account in the app to match their user.userprincipalname. Users have no idea how to find it, the app doesn't support changes, the app only supports one SAML connection, etc...

The good news is that all usernames in our environment are typical ******@domain.com standard with about 5 possible email domains that are all managed within via exchange online of the same tenant.

My question is, is it possible to configure SAML SSO to utilize one of a user's email aliases or a listing of domains?

I think the answer to my question lies within this article but I don't know how to best apply it:

https://learn.microsoft.com/en-us/entra/identity-platform/saml-claims-customization

Example of custom enterprise app SAML claim setup working with userprinciplename but does not allow login via other email aliases/domains:

Screenshot 2023-11-24 at 4.33.40 PM

Thank you in advance!

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.