Skip to main content
Participant
October 30, 2019
Answered

Using User Principal Name instead of email address for MS ADFS federation SSO

  • October 30, 2019
  • 1 reply
  • 2103 views

We have two AD groups, Staff and Students, one, Staff has on-prem email and the Active Directory emailaddress field is populated; the other, Students, has O365 email addresses and consequently they emailaddress field in AD is not populated. Therefore, to add Students to the Adobe Admin Console as users and use MS ADFS, we want to change the settings for authenticaiton from "emailaddress => emailaddress" to "User Principal Name => emailaddress" . Both AD groups have values that match the email format and will work but we are not getting any help from Chat not Expert sessions: they state why it is not working with Students not how to reconfigure it to use UPNs.

Does anyone have any experience with this? 

 

This topic has been closed for replies.
Correct answer alisterblack

Hi,

Yes, this can be done by creating a custom Rule to set username instead of email as the login method in the directory config. Steps can be found in this document. See also https://helpx.adobe.com/ie/enterprise/kb/configure-microsoft-ad-fs-with-sso.html

 

 

 

1 reply

alisterblack
alisterblackCorrect answer
Inspiring
November 4, 2019

Hi,

Yes, this can be done by creating a custom Rule to set username instead of email as the login method in the directory config. Steps can be found in this document. See also https://helpx.adobe.com/ie/enterprise/kb/configure-microsoft-ad-fs-with-sso.html

 

 

 

WayneSD43Author
Participant
November 7, 2019

Alister, thank  you for your how-to it was just what we needed. Why, pray tell, were the Adobe support staff unable to provide guidance when asked? ( rhetorical question, no answer expected)