Make sure that you have added the profile
scope, as "upn" requires the profile scope. You can add the profile scope under API Permissions (Type = delegated).
The type name is
I assume you are using regular Azure AD, but if by some chance you are using B2C, the unique name is stored in the signInNames
attribute and upn
is not used.