# Best practice for moving users away from institutional email domains while avoiding duplicate/impersonation accounts

**URL:** https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143
**Category:** SSO
**Tags:** email, 365-oauth, login
**Created:** [12 ביוני,‏ 2026,‏ 8:41am UTC](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143 "2026-06-12T08:41:00Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![Ethsim2](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ethsim2/32/522255_2.png) [@Ethsim2](https://meta.discourse.org/u/Ethsim2)
#### Post date: [12 ביוני,‏ 2026,‏ 8:41am UTC](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143/1 "2026-06-12T08:41:01Z")

</div>

I run an independent Discourse community [https://physicswithethan.discourse.diy](https://physicswithethan.discourse.diy) which previously allowed institutional email addresses and external SSO.

I now want to move toward ordinary local Discourse accounts using personal email addresses, and avoid relying on institutional SSO or institutional email domains for new registrations.

The issue I am trying to handle safely is account continuity and impersonation risk:

- many existing users have an institutional email address as their primary email;
- I would like new users to use personal email addresses instead;
- I want to avoid people registering accounts using someone else’s name or institutional email address;
- I also want to avoid unsafe or manual account merges unless there is clear evidence the same person controls the relevant accounts/emails.

What is the recommended Discourse-native approach here?

For example, is the best pattern:

1. re-enable local logins;
2. disable the external SSO provider;
3. add the institutional domain to blocked email domains for new registrations;
4. add a site notice asking existing users to update their primary email to a personal address;
5. use manual approval / review for suspicious new accounts;
6. only merge accounts where the user has verified control of both accounts or email addresses?

I am especially interested in avoiding a setup where a user can trigger emails to someone else’s institutional mailbox, or create a misleading account in another person’s name.

Are there existing settings or workflows that people recommend for this kind of transition?

---

_[View the full topic](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143)._
