You wont be able to prevent an admin with the correct permissions from running that command. If there is a reason you do want that ability you will just have to make a policy but no real way to enforce other than removing accounts from the elevated roles that have the permission to make that change
Need to block Set-MsolUserPrincipalName command
ShashankSaxena-2458
131
Reputation points
Hello Team,
I hope you all are doing good.
As we know when we need to change the UPN of Synced User from Azure AD, we can change it through the command Set-MsolUserPrincipalName but can we block this command to change the UPN of synced users only i.e. admin should change the UPN from on-premises only for synced users, is it possible?
Regards,
Shashank Saxena