How to Find Microsoft Entra ID Users by UPN or Email Using Microsoft Graph
Question details
Determine if a single Microsoft Graph API request can find a Microsoft Entra ID user by checking the userPrincipalName, mail, or otherMails attributes simultaneously without calling separate APIs.

- Product
- Microsoft Graph API
- Device & OS
- not provided
- Scenario
- A developer needs to optimize API calls by querying multiple email-related fields at once to locate a specific user account in Microsoft Entra ID.
- Observed behavior
- Looking for the correct syntax or method to combine UPN, primary email, and alternate email filters into one unified API request.
Ensure you have an active access token with the appropriate Microsoft Graph permissions (such as User.Read.All or Directory.Read.All) before running queries against your directory.
Use OData $filter with Logical Operators
Combine conditions using the OData 'or' logical operator in your Microsoft Graph API request to evaluate multiple user attributes at once.
Microsoft Graph API supports the $filter query parameter, allowing you to chain multiple attribute checks. To filter on string collections like otherMails, you will need to use lambda operators (any) and may be required to pass the 'ConsistencyLevel: eventual' header depending on the complexity of the query.
Launch Microsoft Graph Explorer, Postman, or your custom application code where you construct HTTP GET requests.
Set the endpoint to 'https://graph.microsoft.com/v1.0/users'.
Add the query string to check multiple fields. For example: '?$filter=userPrincipalName eq 'user@domain.com' or mail eq 'user@domain.com' or otherMails/any(id:id eq 'user@domain.com')'.
If you receive an error regarding complex queries, add the header 'ConsistencyLevel: eventual' and append '&$count=true' to your request URL.

Consult the Microsoft Entra ID Q&A Forum
For highly specific developer issues or complex filter errors, seek expert guidance directly from Microsoft engineers and the developer community.
Looking for a Free, Lightweight Office Suite?
While you manage your Microsoft Entra ID environment and API integrations, you might need a reliable tool for documenting architecture or generating reports. WPS Office is a highly compatible, free alternative to Microsoft Office that is perfect for tech professionals.
- 1. Visit the WPS website: Go to the official WPS Office website.
- 2. Download the software: Click the free download button to get the appropriate version for your operating system.
- 3. Install and use: Run the installer, open WPS Office, and start managing your documents right away.

Frequently Asked Questions
What permissions are needed to search users in Microsoft Graph API?
To search and read user profiles across the tenant, your app typically requires the 'User.Read.All' or 'Directory.Read.All' delegated or application permissions granted by an administrator.
Can I use the $search parameter instead of $filter for Microsoft Entra ID users?
Yes, you can use the $search query parameter on the users endpoint to search against displayName, mail, and userPrincipalName. However, it requires the 'ConsistencyLevel: eventual' header and evaluates as a 'starts with' search rather than an exact match.
Why am I getting an error when filtering the otherMails attribute?
The 'otherMails' attribute is a collection of strings, not a single string. Filtering a collection in OData requires the lambda 'any()' operator (e.g., otherMails/any(x:x eq 'email@domain.com')) and advanced query capabilities enabled via request headers.




