Jump to content

Recommended Posts

Posted

Hi.

 

We're an RM CC4 school with a schoolname.local AD/DNS but with @myschool.net email addresses and (existing but barely unused) Microsoft tenancy.

 

Looking to sync with Azure ready for MFA and the conditional features - we have P1 etc.

 

Query is about adding an additional UPN suffix and changing it for our users; are there any issues doing this?

Equally, if I just changed the UPN suffix would that break anything - would our domain logins still be schoolname/username whilst our UPN became @myschool.net?

 

I've added the UPN suffix and changed one test user, and they can log in ok to Azure and to the domain, but I don't know what else I might be breaking/have broken in the process!

 

Peter

Posted (edited)

There should not be any issues with doing this at all. I've done twice now.

 

https://docs.microsoft.com/en-us/microsoft-365/enterprise/prepare-a-non-routable-domain-for-directory-synchronization?view=o365-worldwide

 

I'd also consider in future changing your local AD to a subdomain of a public domain your org owns rather than a .local . It might be easier to consider that now before setting up AD Sync, depending on your current setup it might be quite a task but worth considering.

 

https://techcommunity.microsoft.com/t5/office-365/same-users-but-new-domain-with-ad-connect/m-p/218706

Edited by Davit2005
  • Thanks 1
Posted

UPN and Teams Address/ Primary email address can be different

 

It’s a fairly low drama thing to do assuming azure ad connect on a newish version, same with windows and office. I have seen inexplicable need to re-login teams/ outlook /etc so bear that in mind and don’t do everyone at once.. And assuming you don’t use the login name on-prem, most people use Samaccountname. If you do login to a PC with a UPN the user will need to know to change it, although their profile will continue to work.

 

You can actually configure Azure AD to allow login with email address if you so desire, which might be a good idea even if just for people who type the old address in, but you really needs password hash sync for that the be straightforward.

Posted

Thank you, i've changed it for our Year 7 (about to be Year 8) students and had a play.

 

Do you know (whilst i'm here) - I can turn on MFA per-user in the "Users" section of Azure, and I can create and apply Conditional Access (we have P1) in the "Security" section.

 

But if you have a Conditional policy for a user, but haven't turned on MFA in their Per-User entry, it doesn't apply - is there a global/group based "enable MFA for everyone/this group" somewhere that i'm missing?

 

Peter

Posted
My advise would be not to turn on the per use setting and rely on Conditional Access. There is no group like you mention. If you're not triggering a CA rule requiring MFA it's because on an exclusion somewhere - logging should help pick this out.
Posted

Thank you.

 

It turns out that if you set Trusted IPs in the 'old' bit of Azure (https://account.activedirectory.windowsazure.com/UserManagement/MfaSettings.aspx) then those apply regardless of Conditional Access - so when I disabled my conditional access policy, the trusted IPs were overruling it and therefore I thought MFA wasn't applying.

 

I've now moved the trusted IPs to a Named Location in the 'new' bit of Azure (within 'Security'), then adjusted the policy accordingly.

 

Peter

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...