# Best practice for moving users away from institutional email domains while avoiding duplicate/impersonation accounts

**URL:** https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143
**Category:** SSO
**Tags:** email, 365-oauth, login
**Created:** [June 12, 2026, 8:41am UTC](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143 "2026-06-12T08:41:00Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [June 17, 2026, 10:47am UTC](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143/2 "2026-06-17T10:47:39Z")

</div>

Do you mean that you have SSO with one particular institution (e.g., `whatever.edu`) and you want people to stop using that email address?

> [@Ethsim2](#):
>
> I am especially interested in avoiding a setup where a user can trigger emails to someone else’s institutional mailbox, or create a misleading account in another person’s name.

There isn’t any way to trigger emails to an institutional account (other than an email validation request) in any scenario.

Isn’t the best way to keep people from impersonating someone to require them to use their instutional email address? There’s nothing to stop anyone from creating [albert.einstein123@gmail.com](mailto:albert.einstein123@gmail.com) and look like they are that person.

---

_[View the full topic](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143)._
