Score:0

Create new user in Azure AD (custom domain), if the email address and an associated Azure Account both exist

ng flag
VRA

I have mapped my custom domain (mycompany.com) with my Azure Active Directory. My domain and email account is managed by Google Workspace. My co-founder has an existing email address e.g. ([email protected]), and an existing (but unused) Azure account (with an example password, mycurrentpassword) associated with that email address. I want to add her to the mycompany.com active directory, so that she can create resources using the same subscription. I used this as a reference.

When I start creating a new user, I can see 2 options, Create User and Invite User. I understand that Invite User is for guest users, so that is not relevant. The Create User blurb says Create a new user in your organization. This user will have a user name like [email protected]. In the form that follows I am able to enter founder2 in the user field so that her user name would be [email protected]. The form also lets me auto-generate a password or enter a custom password.

My questions:

  1. Is Create User the correct way of adding her to my AZ AD so that she can use our common subscription?
  2. Is it a problem that that her email address exists and is not managed by Microsoft?
  3. Is it a problem that her email address already has an associated Azure account?
  4. Let's assume I create a user this way, and autogenerate a password (e.g. mynewpassword).
    • Does it create a new Azure account?
    • What happens to the existing azure account?
    • Am I right to assume that she would be able to log on to portal.azure.com using [email protected] and mynewpassword?
    • What happens to the account associated with [email protected] and mycurrentpassword? FWIW, I don't need to retain the existing account, since it does not have any associated resources.
Score:0
ng flag
  1. Yes you need to add them as a user. Guest users are to invite users from other Azure AD tenants
  2. No this is not a problem
  3. I am guessing that this other Azure account is associated with the email via a Microsoft/Live/Hotmail etc. account, not an Azure AD account. You would not have been able to associate your domain with your Azure AD tenant if it was in use elsewhere. As such, this is a completely separate account that just happens to have the same email. It is no longer possible to create a Microsoft account with the same email as an Azure AD tenant, but older ones still exist.
  4. When you create the account and autogenerate the passsword is a completely new account that has no relation with any other account with the same email. They would login to the Azure portal with the new account you created. The old account would still exist and have no access to your Azure tenant. It could be deleted if you want.
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.