If you use the UserPrincipalName parameter, you need not make use of the AzureADAuthorizationEndpointUri parameter for MFA or federated customers in environments that Ordinarily have to have it (UserPrincipalName or AzureADAuthorizationEndpointUri is required; OK to work with the two).bonuses: rotation, removal and alternative of figures are includ