How to Restrict Google SSO Sign-In Identifiers in Microsoft Entra ID
Question details
The user needs to restrict sign-in identifiers in a Google single sign-on (SSO) integration with Microsoft Entra ID to prevent the acceptance of both user principal names and email addresses.
- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Configuring Google single sign-on integration with Microsoft Entra ID to tighten identity exposure.
- Observed behavior
- The current SSO integration accepts both user principal names (UPNs) and email addresses, causing security concerns regarding the unnecessary exposure of staff identifiers.
Ensure you have Global Administrator or Security Administrator privileges in your Microsoft Entra ID tenant before reviewing or modifying your enterprise SSO and identity settings.
Review Configuration and Consult Microsoft Entra ID Specialists
Since altering sign-in identifiers impacts authentication flows, it is highly recommended to have Microsoft specialists review your specific domain and application setup.
Restricting sign-in identifiers in a federated or SSO environment requires careful mapping of SAML claims. Misconfiguring these parameters can lead to tenant-wide lockouts or failed user authentications. Engaging with Microsoft Entra ID experts ensures your solution is fully supported.
Gather your current Google SSO settings, including domain configurations, SAML claims mapping, and user identifier formats in Microsoft Entra ID.
Navigate to the official Microsoft Entra ID community forums where verified Microsoft specialists and cloud identity architects provide technical guidance.
Submit a detailed question outlining your objective to restrict sign-in identifiers to either UPN or email only. Include your non-sensitive configuration data for context.
Review the customized solution provided by the specialists and carefully apply the suggested claims mapping or conditional access policies to your Entra ID tenant.
Document Your IT Policies Securely with WPS Office
While resolving complex identity configurations in Microsoft Entra ID, use WPS Office to seamlessly document your IT security policies, SSO setups, and SAML mappings. It is a lightweight, highly compatible alternative to Microsoft Office.
- 1. Install WPS Office: Download and install the free WPS Office suite on your local workstation.
- 2. Create technical documentation: Open WPS Writer to draft your Google SSO integration procedures and identity management policies.
- 3. Save in standard formats: Export your documents in universally accepted .docx or .pdf formats to easily share with your administrative team.

Frequently Asked Questions
Why does Microsoft Entra ID accept both UPN and email for Google SSO?
By default, Microsoft Entra ID attempts to match users based on standard claims provided during the SAML assertion, which often checks both the User Principal Name (UPN) and primary email address attributes to ensure a seamless authentication experience.
Can I restrict SSO sign-ins to specific external domains in Entra ID?
Yes, you can utilize cross-tenant access settings and tenant restrictions within Microsoft Entra ID to control which external domains and cloud applications your users are permitted to authenticate against.
Where can I get official support for customizing Entra ID SAML claims?
Official support is available through the Microsoft 365 admin center by opening a support ticket, or by engaging directly with cloud identity specialists on the Microsoft Q&A community forums under the Entra ID tags.




