Using alternate login ID and ADAL
In special scenarios, you need to work with the alternate login ID concept. In this case, you use another attribute than the UPN, for example, the e-mail address. Be aware that this way is usually the last option (in our opinion). Normally, we always try to work out our solutions with the usage of the UPN.
This section will cover the following topics:
- Disassociation of AAD UPN from AD DS UPN and trade-offs
- What does modern authentication mean?
- How does Outlook authentication work today?
- How authentication happens with Word and SharePoint Online
Disassociation of AAD UPN from AD DS UPN and trade-offs
In case you choose the alternate login ID, your AAD instance will still require a username in the UPN format, such as jnick@inovit.ch
. To provide this solution, you need to customize your AAD Connect, or other synchronization solutions, and your federation options. The following figure gives you an idea of the solution design and the different authentication flows...