SSO Login When UPN and Email Address Are Different
Issue Summary
SSO integration identifies the user based on the email address registered in the FleetAI/Trakzee platform.
If the user's Azure UPN (User Principal Name) and registered email address are different, the user can still log in successfully, provided the email address used for SSO identification matches the email address registered in the platform.
Example Questions
-
- Can I use SSO if my Azure UPN and email address are different?
- Does the UPN need to match the email address in the platform?
- Which email address is used for SSO user identification?
- Will SSO work if the Azure login email differs from the UPN?
- What email address should be registered in the FleetAI platform for SSO?
- Why is the SSO gateway using the registered email address?
Symptoms / How to Identify
The issue may arise when:
- The user's Azure UPN and email address are different.
- The user is unsure which identifier is used for SSO authentication.
- There is concern that a UPN mismatch may prevent SSO login.
- The email address registered in the platform differs from the identifier used during Azure authentication.
Information Required Before Troubleshooting
Verify the following:
- User's Azure login email address.
- User's Azure UPN.
- Email address registered for the user in the FleetAI/Trakzee platform.
- SSO configuration details.
- Whether the user is able to authenticate successfully through Azure.
Troubleshooting Steps
- Verify the email address registered for the user in the FleetAI/Trakzee platform.
- Verify the user's Azure login email address.
- Check whether the email address registered in the platform is the same email address used for user identification during the SSO process.
- Verify the Azure UPN if it is different from the email address.
- Confirm that the user can successfully authenticate through Azure.
- If the email address is correctly registered and the user still cannot log in, provide the SSO configuration details and error information to the support team for further investigation.
Possible Cause
A mismatch between the Azure UPN and the email address may cause confusion when configuring SSO.
However, UPN and email address do not necessarily need to be the same. The SSO integration uses the registered email address for user identification in the platform.
Resolution / Action
The user should ensure that the email address used for SSO identification is registered correctly in the FleetAI/Trakzee platform.
The Azure UPN does not need to match the registered email address. Once Azure successfully authenticates the user, the SSO gateway uses the registered email address to identify the corresponding platform user and log them in.
Note: The SSO integration is based on the user's registered email address, not necessarily the Azure UPN. Therefore, having different UPN and email values is not, by itself, an issue.