logo
search
Security Policy Errors

How to Restrict Google SSO Sign-In Identifiers in Microsoft Entra ID

Maira MehtabMaira Mehtab Sep 28, 2026 869 views

Question details

The user needs to restrict sign-in identifiers in a Google single sign-on (SSO) integration with Microsoft Entra ID to prevent the acceptance of both user principal names and email addresses.

Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Configuring Google single sign-on integration with Microsoft Entra ID to tighten identity exposure.
Observed behavior
The current SSO integration accepts both user principal names (UPNs) and email addresses, causing security concerns regarding the unnecessary exposure of staff identifiers.
Before you start

Ensure you have Global Administrator or Security Administrator privileges in your Microsoft Entra ID tenant before reviewing or modifying your enterprise SSO and identity settings.

Solution 1Recommended

Review Configuration and Consult Microsoft Entra ID Specialists

Since altering sign-in identifiers impacts authentication flows, it is highly recommended to have Microsoft specialists review your specific domain and application setup.

Restricting sign-in identifiers in a federated or SSO environment requires careful mapping of SAML claims. Misconfiguring these parameters can lead to tenant-wide lockouts or failed user authentications. Engaging with Microsoft Entra ID experts ensures your solution is fully supported.

1
Document current configuration

Gather your current Google SSO settings, including domain configurations, SAML claims mapping, and user identifier formats in Microsoft Entra ID.

2
Access Microsoft Q&A community

Navigate to the official Microsoft Entra ID community forums where verified Microsoft specialists and cloud identity architects provide technical guidance.

3
Post your query

Submit a detailed question outlining your objective to restrict sign-in identifiers to either UPN or email only. Include your non-sensitive configuration data for context.

4
Apply tailored guidance

Review the customized solution provided by the specialists and carefully apply the suggested claims mapping or conditional access policies to your Entra ID tenant.

Test in a Staging Environment: Always test SSO configuration changes with a small pilot group of users before rolling out the restriction to your entire organization.
Free Microsoft Office alternative

Document Your IT Policies Securely with WPS Office

While resolving complex identity configurations in Microsoft Entra ID, use WPS Office to seamlessly document your IT security policies, SSO setups, and SAML mappings. It is a lightweight, highly compatible alternative to Microsoft Office.

  1. 1. Install WPS Office: Download and install the free WPS Office suite on your local workstation.
  2. 2. Create technical documentation: Open WPS Writer to draft your Google SSO integration procedures and identity management policies.
  3. 3. Save in standard formats: Export your documents in universally accepted .docx or .pdf formats to easily share with your administrative team.
Fully compatible with Microsoft Word, Excel, and PowerPoint document formats.Securely draft, edit, and share complex IT configuration documentation.Lightweight software suite featuring a familiar, intuitive user interface.Free to use, allowing for cost-effective software deployment across your organization.
microsoft office alternative - wps office

Frequently Asked Questions

Why does Microsoft Entra ID accept both UPN and email for Google SSO?

By default, Microsoft Entra ID attempts to match users based on standard claims provided during the SAML assertion, which often checks both the User Principal Name (UPN) and primary email address attributes to ensure a seamless authentication experience.

Can I restrict SSO sign-ins to specific external domains in Entra ID?

Yes, you can utilize cross-tenant access settings and tenant restrictions within Microsoft Entra ID to control which external domains and cloud applications your users are permitted to authenticate against.

Where can I get official support for customizing Entra ID SAML claims?

Official support is available through the Microsoft 365 admin center by opening a support ticket, or by engaging directly with cloud identity specialists on the Microsoft Q&A community forums under the Entra ID tags.