Need to block Set-MsolUserPrincipalName command

ShashankSaxena-2458 131 Reputation points
2022-05-06T10:56:07.147+00:00

Hello Team,

I hope you all are doing good.

As we know when we need to change the UPN of Synced User from Azure AD, we can change it through the command Set-MsolUserPrincipalName but can we block this command to change the UPN of synced users only i.e. admin should change the UPN from on-premises only for synced users, is it possible?

Regards,
Shashank Saxena

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,210 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,369 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,664 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 142.3K Reputation points MVP
    2022-05-06T13:03:00.747+00:00

    You wont be able to prevent an admin with the correct permissions from running that command. If there is a reason you do want that ability you will just have to make a policy but no real way to enforce other than removing accounts from the elevated roles that have the permission to make that change