logo
search
Others

How to Find Microsoft Entra ID Users by UPN or Email Using Microsoft Graph

Emma BrownEmma Brown Sep 30, 2026 869 views

Question details

Determine if a single Microsoft Graph API request can find a Microsoft Entra ID user by checking the userPrincipalName, mail, or otherMails attributes simultaneously without calling separate APIs.

Find Microsoft Entra ID Users by UPN or Email with Microsoft Graph
Product
Microsoft Graph API
Device & OS
not provided
Scenario
A developer needs to optimize API calls by querying multiple email-related fields at once to locate a specific user account in Microsoft Entra ID.
Observed behavior
Looking for the correct syntax or method to combine UPN, primary email, and alternate email filters into one unified API request.
Before you start

Ensure you have an active access token with the appropriate Microsoft Graph permissions (such as User.Read.All or Directory.Read.All) before running queries against your directory.

Solution 1Recommended

Use OData $filter with Logical Operators

Combine conditions using the OData 'or' logical operator in your Microsoft Graph API request to evaluate multiple user attributes at once.

Microsoft Graph API supports the $filter query parameter, allowing you to chain multiple attribute checks. To filter on string collections like otherMails, you will need to use lambda operators (any) and may be required to pass the 'ConsistencyLevel: eventual' header depending on the complexity of the query.

1
Open your API testing tool

Launch Microsoft Graph Explorer, Postman, or your custom application code where you construct HTTP GET requests.

2
Construct the API request URL

Set the endpoint to 'https://graph.microsoft.com/v1.0/users'.

3
Append the $filter query

Add the query string to check multiple fields. For example: '?$filter=userPrincipalName eq 'user@domain.com' or mail eq 'user@domain.com' or otherMails/any(id:id eq 'user@domain.com')'.

4
Add advanced query headers

If you receive an error regarding complex queries, add the header 'ConsistencyLevel: eventual' and append '&$count=true' to your request URL.

Use OData $filter with Logical Operators
Advanced Query Capabilities: Filtering on the 'otherMails' collection requires advanced query capabilities in Microsoft Graph. Always test your queries in Graph Explorer first.
Free Microsoft Office alternative

Looking for a Free, Lightweight Office Suite?

While you manage your Microsoft Entra ID environment and API integrations, you might need a reliable tool for documenting architecture or generating reports. WPS Office is a highly compatible, free alternative to Microsoft Office that is perfect for tech professionals.

  1. 1. Visit the WPS website: Go to the official WPS Office website.
  2. 2. Download the software: Click the free download button to get the appropriate version for your operating system.
  3. 3. Install and use: Run the installer, open WPS Office, and start managing your documents right away.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight design ensuring fast installation and smooth performance without heavy system resource usage.Familiar user interface for seamless migration with almost zero learning curve.Built-in PDF editing tools for managing technical documentation efficiently.
microsoft office alternative - wps office

Frequently Asked Questions

What permissions are needed to search users in Microsoft Graph API?

To search and read user profiles across the tenant, your app typically requires the 'User.Read.All' or 'Directory.Read.All' delegated or application permissions granted by an administrator.

Can I use the $search parameter instead of $filter for Microsoft Entra ID users?

Yes, you can use the $search query parameter on the users endpoint to search against displayName, mail, and userPrincipalName. However, it requires the 'ConsistencyLevel: eventual' header and evaluates as a 'starts with' search rather than an exact match.

Why am I getting an error when filtering the otherMails attribute?

The 'otherMails' attribute is a collection of strings, not a single string. Filtering a collection in OData requires the lambda 'any()' operator (e.g., otherMails/any(x:x eq 'email@domain.com')) and advanced query capabilities enabled via request headers.