Can I add UPN suffixes to AAD DS?

Ali S 1 Reputation point
2020-08-13T11:11:28.067+00:00

Hi folks,

When using Active Directory Domains and Trusts to add UPN suffixes I see the following error message:

"Windows cannot update the UPN suffixes. Insufficient access rights to perform the operation"

I am signed into a AAD DS joined server and using an AAD DS administrator account in the group "AAD DC Administrators".

The domain names I would like to add as UPN Suffixes are verified as Custom Domains in Azure AD.

Are elevated privileges required to perform this operation?

Microsoft Entra
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,831 Reputation points
    2020-08-13T20:30:40.683+00:00

    Hi,

    You have to use a account member of enterprise Admins and domain admins to perform this action.

    *****************Please don't forget to mark this reply as answer if it help you to resolve your issue********************

    0 comments No comments

  2. Ali S 1 Reputation point
    2020-08-14T08:43:43.433+00:00

    Thanks @ThameurBOURBITA,

    The only account who is a member of both those groups is dcaasadmin which I did not configure so I don't have the password to. I can't find much information on that account but it seems I cannot elevate the privilege of my AAD DC Admin account without it?

    0 comments No comments

  3. Thameur-BOURBITA 32,831 Reputation points
    2020-08-14T09:20:20.04+00:00

    Hi,

    If know a password of a account member of domain admins in the root domain, you can use it to add another account in enterprise admins group.

    Please don't forget to mark this reply as answer if it help you to resolve your issue

    0 comments No comments

  4. James Hamil 24,311 Reputation points Microsoft Employee
    2020-08-31T19:03:54.303+00:00

    Hi, are there any updates with this case? If not, please select the appropriate response as "Answered." Otherwise please let us know how we can assist you.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.