entra ID connect MSOL accounts - no UPN

John Curtiss 66 Reputation points
2025-01-08T20:25:56.54+00:00

i have a couple of Entra ID connect servers, formerly known as Azure AD connect servers. each of the servers has an "MSOL_GiBbErIsh123" account associated with it. i assume these are created automatically when azuread connect is installed. i inherited this, and it has been working fine.

in the "account" tab on the properties for both of these accounts, there is no UPN. that is, the top "User Logon Name" is blank, with no domain selected, but the bottom "User Logon Name (pre-windows 2000:) is populated. (samaccountname exists but userprincipalname is blank)

it seems wildly inconsequential to add the upn, but the idea that microsoft created them this way purposely instead of accidentally makes me hesitant to just drop it in there. does anybody know why the MSOL accounts don't have UPNs?

(i have a procurement/security software that I believe is having trouble reading these accounts because of the missing UPN)

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,751 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Marcin Policht 39,685 Reputation points MVP
    2025-01-08T20:32:43.4733333+00:00

    If an AD DS user account does not have an explicitly assigned UPN, it is automatically assigned the UPN associated with the AD DS forest - so every account has the UPN set (even though it might not appear in GUI-based tools)

    If you have software that requires an explicitly assigned UPN, you can simply assign it directly to the user account by ADUC/ADAC/etc...


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin


  2. Akhilesh Vallamkonda 13,060 Reputation points Microsoft External Staff
    2025-01-09T20:55:30.84+00:00

    Hi @John Curtiss

    Thank you for reaching Microsoft Q&A Forum!

    Generally, the UPN is typically used for user logon purposes. The absence of a User Principal Name (UPN) for these accounts is intentional, because these service accounts don't require a UPN because they are not used for interactive logon, Instead, they rely on the SAMAccountName.
    The MSOL accounts are created by Entra Connect and are used for synchronization purposes only between your on-premises Active Directory and Entra ID.
    It is not necessary to add a UPN to the MSOL accounts and could potentially cause issues with the synchronization service.

    Hope this helps. Do let us know if you any further queries by responding in the comments section.

    Thanks,

    Akhilesh V.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.