Step 1: Open the SAML Claims Configuration
Sign in to the Microsoft Entra admin center.
Navigate to Enterprise applications.
Select your Automox SAML application.
Go to Single sign-on.
Under Attributes & Claims, click Edit.
Step 2: Set the Email Address Claim to UPN
In the Additional claims section, locate the claim:
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddressClick Edit (or Add new claim if it does not exist).
Configure the claim with the following values:
Name:
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddressSource attribute:
user.userprincipalname
Select Save.
Step 3: Validate the Configuration
Assign a test user that does not currently exist within Automox to the application in Entra.
Initiate a test SAML sign-in from My Apps in Entra.
Confirm the new user account within Automox possesses the email address as the user’s UPN.
Result
The SAML assertion now sends the user’s UPN as the value for the emailaddress claim, ensuring consistent identity and email mapping in the service provider.