troubleshooting Question

Should userPrincipalName in Active Directory match external email domain or the internal AD domain

Avatar of Ian Gooding
Ian GoodingFlag for United Kingdom of Great Britain and Northern Ireland asked on
ExchangeOutlookActive Directory
5 Comments1 Solution110 ViewsLast Modified:
I've got an active directory domain (2008 level) which predates our email moving to Exchange, so the domain names are different. The AD one is a ".local" created in the days before the best practice was to match external domain names. This means that email addresses (using our external domain) differ from internal identifiers. We now have an on-premise Exchange 2016 server. I've implemented autodiscover which was fine before Outlook 2016 came along as we could always specify the domain name in setting up. Now with Outlook 2016 the option to set this are so hard to discover that I decided to find out why I couldn't login to Outlook with just the external facing email address. It seems to work with setting up Outlook inside the domain, but I've got some external email users who don't have this option.

After much investigation, I found that the AD field userPrincipalName is set to user@internal.local instead of and that this governs whether you can login with the external email address on OWA. Here's the link that gave me the clue:

So if I reset the field in the user's record in AD to the external email domain, I can then login with just the email address, and set up new Outlook 2016 profiles again with just the email address. So far this seems to work.

The question is whether this is good practice, or whether I should change my AD to use the external domain name, or some combination perhaps involving having both internal and external domains defined. Are there any gotchas if I simply change the userPrincipalName to match the email address in all cases?

I'm intending to migrate some of our mailboxes to Office 365 in the next month or two, so it would be good if there's a best practice to make this migration easier.
timgreen7077Exchange Engineer
Join our community to see this answer!
Unlock 1 Answer and 5 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 5 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros