# Best practice for moving users away from institutional email domains while avoiding duplicate/impersonation accounts

**URL:** https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143
**Category:** SSO
**Tags:** email, 365-oauth, login
**Created:** [June 12, 2026, 8:41am UTC](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143 "2026-06-12T08:41:00Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![Ethsim2](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ethsim2/32/522255_2.png) [@Ethsim2](https://meta.discourse.org/u/Ethsim2)
#### Post date: [June 17, 2026, 1:54pm UTC](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143/3 "2026-06-17T13:54:10Z")

</div>

Yes, that is the tension I am trying to handle.

Technically I agree that an institutional email address is stronger identity assurance than a personal email address. My reason for moving away from institutional email/SSO is not that personal email is better proof of identity, but that I want the community to be clearly independent and not rely on an institution’s identity system or email domain for ongoing access.

Since my opening post I have made the current transition state clearer on the site itself:

- the splash/login page now states that Physics with Ethan is independent and not affiliated with or endorsed by any university, school, or department;
- it also explains that sign-in currently uses Microsoft work or school account verification for onboarding;
- existing users can now add a personal email address after logging in, via Profile → Preferences → Emails;
- I have also added wording asking users not to register using another person’s name, email address, or identity.

So I think the current position is a transitional one:

- Microsoft work/school verification is still useful for reducing impersonation risk during onboarding;
- but I would like existing users to add personal email addresses;
- and I want to avoid making institutional email/SSO the long-term dependency of the community.

The practical Discourse question I am still trying to answer is:

For a community that wants to move from institutional email/SSO toward local accounts and personal email addresses, is the safest pattern to keep the transition manual/admin-reviewed rather than attempting automatic account merging?

For example:

1. allow existing users to add a personal email while logged in;
2. keep the splash page clear about the current onboarding method;
3. discourage misleading registrations/impersonation;
4. avoid automatic account merges;
5. only merge accounts where there is clear evidence the same person controls the relevant accounts/emails.

Does that sound like the right Discourse-native direction?

---

_[View the full topic](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143)._
