question

shashanksaxena-6941 avatar image
0 Votes"
shashanksaxena-6941 asked shashanksaxena-6941 commented

Need to block Set-MsolUserPrincipalName command

Hello Team,

I hope you all are doing good.

As we know when we need to change the UPN of Synced User from Azure AD, we can change it through the command Set-MsolUserPrincipalName but can we block this command to change the UPN of synced users only i.e. admin should change the UPN from on-premises only for synced users, is it possible?

Regards,
Shashank Saxena

office-exchange-server-administrationoffice-exchange-online-itproazure-ad-connect
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi @shashanksaxena-6941

Do suggestions above help?
If you have any questions or needed further help on this issue, please feel free to post back.

0 Votes 0 ·

1 Answer

AndyDavid avatar image
0 Votes"
AndyDavid answered shashanksaxena-6941 commented

You wont be able to prevent an admin with the correct permissions from running that command. If there is a reason you do want that ability you will just have to make a policy but no real way to enforce other than removing accounts from the elevated roles that have the permission to make that change

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks @AndyDavid for the response and sorry for the delayed response.

Don't we have anything through RBAC to limit those changes?

0 Votes 0 ·