Forum Discussion

The-messenger_1's avatar
The-messenger_1
Icon for Nimbostratus rankNimbostratus
Feb 21, 2017

Add UPN to existing policy

I have an existing access policy - login page ---- ad auth --- sso. I need to add userprincipalname as a username option.

 

Do I add ad query before ad auth or add a branch rule to the login page?

 

2 Replies

  • In our AD, UPN and samaccountname do not contain the same user or domain. Our upn is our email address using a different formant for the name portion than we use for our ad user name.

     

    as an example userprincipalname/emailaddress = lastinitialfirstname@domain.com samaccountname = first-two-initialslastname

     

  • I did this changing to LDAP. With LDAP I can use the mail attribute and leave UPN alone, at this point.