Imagine the scene:
A cold November day, a hard working (?) developer is finalizing his Onboarding application, when bugs arise ....
A user joins an org, is added to Azure AD and given a PowerApps license, let's say the AAD UPN is a.b@myorg.co.uk.
They will then come to exist in DataVerse as a user with internal email address of a.b@myorg.co.uk.
They leave the org completely, and their account is deleted in Azure.
It remains in DataVerse as a disabled user.
Some time passes (over 30 days to ignore the recover AAD account for now).
A user joins the org, is added to Azure AD and given a PowerApps license, let's say they have the same name and hence given the AAD UPN of a.b@myorg.co.uk.
PowerApps license given.
Created in DataVerse.
To my mind, this 'new' user should not be related to any user in DataVerse (they may or may not be the same person, who knows?)
Now I am seeing 2 different results at this point.
The user in DataVerse may have kept the internal email address of a.b@myorg.co.uk.
Or their email in DataVerse may have become AAD_OLD_IDa.b@myorg.co.uk.
This seems to be ...
There's a DataVerse User field called Azure State.
If it is 'Not found or hard deleted', or 'Soft Deleted' (last 30 days) the internal email address is randomized.
But a lot of users who left a few months back and more show as 'Exists' for azure State (when they do not exist in Azure), and these have the original email address. (Also for users added as stub users).
There must have been a change in something in somewhere at sometime. I guess my questions are:
1. Was this a platform change ( I see around the start of August on 2 tenancies the same things happening).
2. Is there some underlying linkage between Azure I don't know about. If a user has been hard deleted, and a person with the same UPN is created, would they get the same Azure ID? Seems very unlikely.
3. Isn't it dangerous for the platform to assume a new UPN in Azure is a match for an email address in DataVerse, which could make them owners of records they should not see?
A user who is soft deleted keeps their old Azure ID on restoring.

Report
All responses (
Answers (