Free tools Windows power users keep installed
One-click scans. No signup required.
UPN (userPrincipalName) is an Internet-style user logon name, usually written as user@domain. sAMAccountName is a separate, legacy-compatible account name commonly used in the down-level format DOMAINuser. Active Directory can use either for on-premises sign-in, but they have different formats, purposes, and uniqueness scopes—and a UPN is not necessarily the user’s email address.
UPN and sAMAccountName at a glance
| Attribute | Typical sign-in form | Primary role | Uniqueness and limits |
|---|---|---|---|
userPrincipalName (UPN) |
user@DNS-domain |
Internet-style logon name; Microsoft describes it as the most common Windows user logon name. | Microsoft documents forest-wide uniqueness for supported Active Directory conditions; enforcement depends on the deployment. The general schema lists a 1,024-character rangeUpper, while Microsoft 365 synchronization guidance sets narrower limits. |
sAMAccountName |
DOMAINuser (the attribute is only user) |
Supports earlier Windows clients and down-level logon use. | Unique among security principals in its domain; 20 characters maximum, with specified punctuation excluded. |
These are distinct attributes, not two spellings of one value. The logon syntax combines an account name with a domain in different ways: a UPN uses an @ suffix, while down-level credentials use a domain name, a backslash, and the account-name portion. See Microsoft’s User Naming Attributes and User Name Formats.
What is a UPN?
A UPN is the value of the userPrincipalName attribute. Microsoft defines its usual structure as a prefix (the user account name), followed by @ and a suffix that is a DNS domain name—for example, alex@contoso.com. The suffix may be a domain in the forest or an alternate suffix configured for the forest; it does not have to match the domain where the user object is stored.
In the documented Active Directory logon flow, a UPN is searched locally and then in the global catalog. Microsoft recommends checking the local domain and global catalog when choosing a UPN. It is independent of the user object’s distinguished name: moving or renaming the object does not itself change the UPN, although an administrator can change the attribute. A UPN can be assigned when an account is created, but the cited Active Directory guidance does not make it mandatory. See Microsoft’s naming-attribute guidance and the Set-ADUser reference.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
What is sAMAccountName?
sAMAccountName is the LDAP display name for the SAM-Account-Name schema attribute. Microsoft describes its purpose as supporting clients and servers from earlier Windows versions, including Windows NT 4.0, Windows 95, Windows 98, and LAN Manager.
The attribute stores the account-name portion, not the full down-level credential. For example, in CONTOSOalex, CONTOSO is the NetBIOS domain name and alex is the sAMAccountName. Microsoft’s schema reference limits that value to 20 characters and disallows these characters: / [ ] : ; | = , + * ? < >. The value must be unique among security principals in its domain; when omitted during user creation, the server can generate a random value. See the SAM-Account-Name schema reference and Creating a User.
Are UPN and email address the same?
No—not automatically. A UPN often looks like an email address, and Microsoft says it conventionally maps to the user’s email name. But the UPN and the primary email address can differ. In synchronized directories, the primary email is represented separately in the proxyAddresses attribute. Check the user’s UPN and mail-related attributes independently rather than assuming that changing one changes the other. Aligning them can make sign-in details less confusing, but it is not a requirement that they match. Microsoft discusses this distinction in its Microsoft 365 directory synchronization guidance.
How uniqueness works
The attributes have different uniqueness scopes. Microsoft documents UPN uniqueness across security principals in a forest, while sAMAccountName must be unique within its domain. For UPNs, the Active Directory technical specification qualifies enforcement: behavior depends on functional level, updates, configuration, and the type of operation. Administrators should verify the rules for the actual deployment instead of assuming every historical or unusual forest enforces uniqueness identically. See Microsoft’s UPN uniqueness constraints and naming-attribute documentation.
Rank #3
What changes in Microsoft Entra ID and Microsoft 365?
On-premises Active Directory supports sign-in with either sAMAccountName or UPN. Microsoft Entra ID uses the UPN as the work or school sign-in identifier. During directory synchronization, the on-premises UPN is used as a basis for the cloud identity, but tenant and service rules apply; do not assume the synchronized result will always be identical in every configuration.
Keep the general Active Directory schema separate from Microsoft 365 service constraints. The Open Specifications schema gives userPrincipalName a rangeUpper of 1,024 characters. Microsoft’s directory synchronization guidance instead specifies a maximum UPN length of 113 characters, with no more than 64 before @ and 48 after it. Those are Microsoft 365 synchronization limits, not replacements for the general schema value. Cloud sign-in also requires an eligible domain namespace, and service guidance sets character restrictions. Check the current Microsoft documentation and tenant configuration before changing UPNs or planning a migration: Prepare for directory synchronization to Microsoft 365 and Microsoft Entra UPN population.
Quick Recap
Best Value
- Used Book in Good Condition
Which name should you use?
- For a modern-style sign-in: use the user’s UPN, such as
alex@contoso.com, where the application accepts it. - For down-level Windows credentials or older integrations: use the domain-qualified format
DOMAINalex; the sAMAccountName itself is onlyalex. - When troubleshooting sign-in or synchronization: verify the actual
userPrincipalName,sAMAccountName, email attributes, and tenant/domain configuration separately. Similar-looking values are not proof that the attributes match.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

