User principal name, the user@domain sign-in name of a user. Only domain suffixes verified in the tenant can be used.
Also called user principal name.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-200SC-300AZ-802DP-600DP-700PL-300SC-401MD-102ALZ
Each book explains UPN in context, with comparison tables and the common traps.
Terms in this definition
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Domain
A way of grouping workspaces by area of the business, in support of a data mesh approach. Items take on their workspace's domain, letting you filter the OneLake catalog by it, and certain tenant settings can be passed to domain admins; domains have no effect on access permissions.
- organization
VCF Automation's top-level tenant, completely isolated, owning separate users, networks and resources. Three kinds exist: All Apps, VM Apps and Provider Consumption.
Related terms
- Custom domain
A DNS name of your own attached to a service. In an Entra tenant it is verified through a TXT or MX record, and every on-premises UPN suffix used to sign in must be one (.local can't be); for App Service it is bound with CNAME or TXT validation.
- Delegated Login Identity
When single sign-on uses Kerberos Constrained Delegation through application proxy and a user's cloud name doesn't match their on-premises name, this option picks the identity the connector requests a Kerberos ticket for. Choices include the UPN and the on-premises SAM account name.
- Duplicate attribute resiliency
If two objects claim the same UPN or SMTP proxy address, Microsoft Entra sync doesn't fail the export; it parks the clashing value and gives the object a stand-in onmicrosoft.com UPN. Once someone sorts out the clash, the original value returns without any manual step. This behaviour can't be switched off.
- Guest user
Entra account whose
UserTypeis Guest, created when a B2B invitation is accepted; its UPN takes the #EXT# form, but that is not what the person signs in with. - Hard match
When syncing, an on-premises object is first paired with one already in the cloud using sourceAnchor and immutableId. Only when that pairing doesn't work does sync fall back to a soft match on UPN or primary SMTP address.
- Name suffix routing
Decides, on a forest trust, which DNS, SPN and UPN suffixes have their authentication traffic directed across to the other forest.
- Reset redemption status
Sends a fresh invitation to a guest, for instance when their sign-in email has changed, while preserving their object ID, group memberships and app assignments. Their UPN stays the same.
- USERNAME
Desktop shows
DOMAIN\user; once published to Power BI's service, a UPN comes back instead. Either way, it identifies whoever is currently viewing.