Azure Active Directory

Welcome to the Azure Active Directory suggestions and feedback site! We love hearing from you. If you have suggestions, please submit an idea or vote up an idea. We are monitoring the site actively.

Thank you for joining our community and helping improve Azure AD!

Wehave a new log in experience integrated with Azure AD, and we stronglyrecommend you log in with your Azure AD (Office 365) account. If yourUserVoice account is the same email address as your Azure AD account, yourprevious activities will be automatically mapped to your Azure AD account.  You can read more here for details: https://techcommunity.microsoft.com/t5/Azure-Active-Directory-Identity/Putting-customers-first-for-f...

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Removing different tenants/directories if I am the owner of the company

    Is it possible if you are company owner and you have employs to have access to remove the tenants or directories that are created under you / under your account

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  2. Show at the portal the quota that is being used by the tenant

    Please add at the portal the quota that is being used by the tenant to be able to request to Microsoft to increase the limit prior to have affectation and impact on the sync, b2b invites, app creations etc.

    Current limit is 1 million, and when reach we will need to create a ticket with MS to increase the limit.

    There's no way to know the value of the total currently in use.

    The advice from MS was to run a:

    Azure PS
    (Get-AzureADUser -All $true).Count
    (Get-AzureADGroup -All $true).Count
    (Get-AzureADContact -All $true).Count
    (Get-AzureADDevice -All $true).Count
    MSOL PS
    (Get-MsolUser -All -ReturnDeletedUsers).Count

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  3. Consider providing Group settings to be accessed when creating a group in Active Directory

    When creating a group in AD the settings to deliver messages to a users inbox are turned off. When a group is created in the Office 365 Admin portal these setting seem to default to On. It would be helpful to have access to these settings in AD. This would facilitate creating a group with the proper settings while allowing users to recognize that there are setting that need to be considered for a new group.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  4. Add authentication logging for Azure Active Directory Domain Service

    Currently if I want to gain additional insight on why a user may be unable to login to our AADDS we have to file a support ticket.

    We are able to manage our AADDS with the classic AD management tools - a similar experience would be ideal for log review. Although we would still be happy to have access through the Azure portal as well.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  5. Get rid of all the security that will ultimately keep the computer owners out.

    Give the user the option to select security, not force it on them with complexity that will ultimately lock them out.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  6. Provide the ability to remove disabled subscriptions.

    If you have a subscription that entered disabled state, Let's say it was a sponsorship provided by Microsoft itself for training purposes, once it is disabled at the current moment you have to live with it forever. There is no way of removing it from your AAD directory. You have to filter it out so that you do not see it when browsing resources. That is dumb. We should be able to say we do not need this anymore, so remove it delete it whatever. "Hiding it" is not the right answer.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  7. Guest Access - Limited AzureAD contact information only via Role

    Add a method to allow Guest user to access only basic contact information of a select number of AzureAD user info without setting Restrict Guest User access to “no” and Restrict User access to azuread to “no”.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  8. Allow Custom Domains to have service principals in Azure AD

    Currently, if I want to use my own certificate for a custom domain in Azure CDN, I have to grant Azure CDN access to my KeyVault. That means anyone in the organization can potentially set up a custom domain using my KeyVault certificate. Instead, move the level of access policy down to the custom domain so that I can grant a specific custom domain access to the KeyVault and limit access that way.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  9. Synchronizing Managed Service Accounts from OnPremise to Azure ActiveDirectory

    I wish there is a way to synchronize managed service accounts(MSA) from onpremise to Azure Active Directory, There are many third party applications where we are using the MSA's auth for the apps on-premise . Now we have needs to connect to Azure SQL Database and they can't connect it using the existing auth. I think currently there is no way to sync the MSA's from onpremise to Azure Active Directory.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  10. Provide ability to unlink Azure from Office 365

    My company has an Office365 subscription and we use the AD to manage internal staff roles, system access, etc. We also have entirely separate external data centres running systems and services for external customers and financial partners. We are now engaging in a migration exercise to move our data centres to the cloud. I created an Azure account using my company email address (naturally), and it automatically pulled in all settings and staff and who knows what else from our Office365 AD. This has already caused many issues in just a few days. Through multiple calls and emails with MS…

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  11. This is not an idea but a feedback

    I find the idea of entering the OTP everytime I login ,very absurd. atleast you should not ask for OTP on the same system which I was logged

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  12. I work for BP Shipping. We do not have normal phone link. Why not use what's app?

    Use what's app for ship's who are sometimes 1 month away from land and normal mobile link un-available.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  13. Keeping guest account in the inviting AAD updated with changes made in the user's home AD

    We're collaborating with an external party on a project and have invited around a 100 users of theirs as guest users in our AAD. The external party recently migration to another email domain. The good news is that this change didn't impact their ability to SSO into SharePoint and other O365 products. The only downside we found is that the user name filed of the guest account in the inviting AAD still had the original email.

    In summary, users added pre-migration have the old email domain suffix and users added post-migration have the new email domain suffix. I would be…

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  14. Introduce the functionality to add PDLs/DDLs into application's user and group assignment.Right now only security group could be added.

    Introduce the functionality to add PDLs/DDLs into application's user and group assignment.Right now only security group could be added.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  15. Stop use the function

    How can i stop use the function to log in my account! It's really inconvinience to me! tell me how stop use it that is my right.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  16. inconvinience; limited ;

    If international students come bake to their home country and take online courses how they receive their verify code from their US phone #?
    Now, I really want to know how I can stop use the verify code to log in my account. I am not stay with my cell-phone all the time. Each time I log in my account that I must find where my cell-phone is which really inconvenience for me. On the other hand, I don't believe that such any bored person would steal and log into a student's mailbox and blackboard unless their motivation is interstress…

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  17. Disable Add subscription outside home directory

    Currently it is not possible to add a subscription to a directory that is not your home directory. However, the "Add" button is still shown and active under subscriptions when logged in to a non-home directory. Creating a subscription this way confusingly adds it to the user's home directory without regard for the directory where you wanted to add it. This should either be clarified when initiating the create subscription wizard, or the Add button should be removed/disabled when not in the home directory.
    Situation: User belongs to one directory and is added to another with sufficient permissions to create…

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  18. WHFB is not working with Server 2019 Domaincontrollers

    We had Windows Hello for Business working fine.
    We created a new ad forest with only servers 2019, now WHFB is not working anymore.

    "This option is temporarily unavailable. For now, please use a different method to sign in." and KRB Error: KDC_ERR_CLIENT_NAME_MISMATCH

    please fix

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  19. Stop asking me to add security questions. I don't want them on my account. I'm not adding them. Stop trying to force it.

    Stop trying to force me to add security questions. I have too many possible answers. I just want to access my account quickly so I can get back to work. If I add them, I'll second guess what the answer is and possibly get it wrong and then be locked out of my account longer. It's happened before. Security questions are rubbish and you are affecting my ability to treat my patients in a negative fashion by slowing me down by hitting to decline 3 times to log into my work account and another two times to check me email.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  20. Azure AD Account Initials

    The initials circle that is generated in Azure AD and propagated to other workloads seems to parse the DisplayName attribute which does not always render the correct initials. For example, if the CX uses "BusinessUnit-FirstName LastName (Contractor)" as a naming convention then everyone gets the exact same "BC" initials. This has been a complaint for way too long and is easily resolved by using the FirstName and LastName attributes to generate the correct initials and fall-back to DisplayName only if they are not populated.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  End user experiences  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base