Re: DSMOD -UPN

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



%username%@xxxxxxxxxxxxxxxxxxx
Thanks
Steve

"Jorge de Almeida Pinto [MVP - DS]" wrote:

I was just saying there is no need to configure a UPN unless you want to use
another UPN other than the default available

let's say your AD domain is called ADDOMAIN.COM and we are talking about
your user account (samaccountname) which is for example YOURUSER. Let's say
your name is "Your Special User"

what do you want the UPN to be?

YOURUSER@xxxxxxxxxxxx or something else?

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Identity & Access - Directory Services #

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* How to ask a question --> http://support.microsoft.com/?id=555375
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test ANY suggestion in a test environment before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Steve Audus, Chaucer BEC, Sheffield UK"
<SteveAudusChaucerBECSheffieldUK@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8929C809-91F7-413A-9FA6-532021DDB3FF@xxxxxxxxxxxxxxxx
Jorge,

Thank for the reply,
I have used "csvde -f" command to output a file of our 1000+ users,
and many do not have "userPrincipalName" a value, some do.

When I look at the Account Properties in AD Users and Computers for these
users either thier "User logon name:" is blank or/and the domain is not
selected in the drop down list.

It is the EXPLICIT userPrincipalName attribute that our Internet filter
displays.

So I do need to create a batch or command to edit this attribute for
muliple
users.

Any other suggestions?

Thank you
Steve


"Jorge de Almeida Pinto [MVP - DS]" wrote:

although you do not see a UPN configured in ADUC, each user in AD has a
UPN
whether or not you configure it.

* each user in AD by default has an IMPLICIT UPN which always matches
<sAMAccountName>@<AD DOMAIN>. The implicit UPN is just there!
* additionally you can configure an EXPLICIT UPN which can basically be
anything like for example the e-mail address <My Name>@<My Comapnies
Domain>. The explicit UPN for a user is stored in the userPrincipalName
attribute

whether or not you use the explicit UPN, authentication will always
revert
to and use the implicit UPN. The ability to configure another UPN is just
accomodate admins to configure another UPN

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Identity & Access - Directory Services #

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* How to ask a question --> http://support.microsoft.com/?id=555375
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test ANY suggestion in a test environment before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Steve Audus, Chaucer BEC, Sheffield UK"
<SteveAudusChaucerBECSheffieldUK@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message
news:B85FB8B8-D057-43A9-A193-EDEB71FB0621@xxxxxxxxxxxxxxxx
We have a large selection of users without userPrinicipalName, which is
required for the authentication for our internet filter. I'd like to
quickly
do a dsquery and dsmod script to correct this problem, but am stuck
with
the
syntax.

Can anyone help? the UPN should be %username%@xxxxxxxxxxxxxxxxxxx

Any suggestions?

Thank you




.



Relevant Pages

  • Re: DSMOD -UPN
    ... It is the EXPLICIT userPrincipalName attribute that our Internet filter ... * additionally you can configure an EXPLICIT UPN which can basically be ... The explicit UPN for a user is stored in the userPrincipalName ... Always test ANY suggestion in a test environment before implementing! ...
    (microsoft.public.windows.server.active_directory)
  • Re: NT domain users missing username@domain entries
    ... you could still use the IMPLICIT UPN which is there automatically.... ... the explicit UPN COULD BE: MY.SPECIAL.USER@xxxxxxxxxxxxxxxxx ... Always test ANY suggestion in a test environment before implementing! ...
    (microsoft.public.windows.server.active_directory)
  • Re: DSMOD -UPN
    ... I was just saying there is no need to configure a UPN unless you want to use another UPN other than the default available ... Always test ANY suggestion in a test environment before implementing! ... It is the EXPLICIT userPrincipalName attribute that our Internet filter ... The explicit UPN for a user is stored in the userPrincipalName ...
    (microsoft.public.windows.server.active_directory)
  • Re: Modify UPN Prefix on existing user accounts
    ... like ILM can generate a unique sAMAccountName, it should also be able to generate a unique UPN of the user ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Always test ANY suggestion in a test environment before implementing! ... them if AD was authoritative for UPN and they replied yes. ...
    (microsoft.public.windows.server.active_directory)
  • Re: UPN Suffixes
    ... the total UPN MUST be unique throughout the forest! ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ...
    (microsoft.public.windows.server.active_directory)