-| | `replace_unverified_email_with_upn` (Preview) | This is a public preview feature of Azure Active Directory. </br></br> In scenarios where email ownership is not verified, the `email` claim will return the user's home tenant UPN instead, unless otherwise stated below. </br></br> For managed users, email is verified if the home tenant owns the email's domain as a custom domain name. For guest users, email is verified if either the home or resource tenants own the email's domain. If the user authenticates using Email OTP, MSA, or Google federation, the `email` claim will remain the same. If the user authenticates using Facebook or SAML/WS-Fed IdP federation, the `email` claim will not be returned.</br></br> The `email` claim is not guaranteed to be mailbox addressable, regardless of whether it is verified. |
0 commit comments