UPN in multiforrest ADFS

M

Max Kaiser

Is my understanding to multi forest ADFS authentication correct?
We will use contoso.com as Office 365 federated domain.
Contoso.com is the domain from a resource forest.
The account domain is adatum.com.
Users use Exchange mailboxes in the contoso domain, their accounts are disabled there.


Linked Mailbox / Disabled Account <-> Active User Account
UPN: x@contoso.com UPN: x@adatum.com
Primary SMTP: x@contoso.com <-> Email: x@contoso.com


  • The login to Office 365 is done with the UPN of the linked mailbox, this must correspond to the primary SMTP of the user?
  • The login with x@contoso.com uses the password of the adatum domain account?
  • The adatum UPN is not relevant and does not need to be changed?
  • In adatum, the Active Directory Mail field must also be set to the contoso.com address, or does it pull itself from the Linked account automatically?


Thanks a lot for your help.

Best regards

Max Kaiser

Continue reading...
 
Back
Top Bottom