Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Cathy_Cheng
Participant

Remote Access VPN - identity sources- username format

We use Remote Access VPN as one of our identity sources, where usernames are presented in the format username@domain (via SAML authentication). However, LDAP searches require the username (sAMAccountName) format. As a result, Active Directory group and role retrieval fails.

Is there a way to strip the @Domain portion from the username?

 
 

 

0 Kudos
2 Replies
simonemantovani
MVP Silver
MVP Silver

Hello

How did you configure the authentication?

In the authentication tab for Remote Access VPN, unde Mulitple Login Option you should be able to set the gateway to use UPN (UserPrincipalName) instead of sAMAccountName; UPN is usually in the format username@domain.

0 Kudos
Cathy_Cheng
Participant

Finally sorted this out by changing the Entra ID side SSO Attributes & Claims. 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 07 May 2026 @ 01:30 PM (AEST)

    CheckMates Live Sydney

    Tue 02 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Aarhus

    Wed 03 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Copenhagen
    CheckMates Events