-| | `replace_unverified_email_with_upn` (Preview) | This is a public preview feature of Azure Active Directory. </br></br> In scenarios where email ownership is not verified, the `email` claim will return the user's home tenant UPN instead, unless otherwise stated below. </br></br> For managed users, email is verified if the home tenant owns the email's domain as a custom domain name. </br></br> For guest users, email is verified if either the home or resource tenants own the email's domain. If the user authenticates using Email OTP, MSA, or Google federation, the `email` claim will be unchanged and continue to return email. If the user authenticates using Facebook or SAML/WS-Fed IdP federation, the `email` claim will not be returned. |
0 commit comments