What account identifiers should I include in a provider request?¶
Include every verified identifier needed to distinguish the relevant account, tenant and service, while excluding unrelated personal data. A display name or email address may be useful context, but neither is necessarily a stable or unique account key.
Build an identifier set¶
Depending on the provider and question, useful values may include:
- provider account, user-object and tenant IDs;
- username, email address, domain, telephone number and known aliases;
- subscription, application or guest-object IDs;
- resource, folder or version IDs for relevant content; and
- event, session, request or correlation IDs for known activity.
State the exact product because one provider may operate several independent identity systems. For federated or guest access, preserve both the home identity and the object created in the host tenant.
Show where each value came from¶
Record the source of every identifier and preserve its original formatting. A value copied from a user interface may be a changeable label; a value from an audit export may be a stable internal ID. Do not guess missing characters or silently “correct” a provider value.
Include previous names or aliases with the dates they were in use where an account was renamed, transferred or migrated. If only a display name is known, supply supporting organisation and date context while making the uncertainty clear.
Tenant identifiers distinguish the organisational environment. The accompanying time information narrows where the provider should search within it.
The point to remember
Give the provider a sourced set of stable IDs, tenant context and historical aliases so the intended account can be found without relying on a changeable display name.