If you utilize the UserPrincipalName parameter, you don't need to make use of the AzureADAuthorizationEndpointUri parameter for MFA or federated buyers in environments that normally call for it (UserPrincipalName or AzureADAuthorizationEndpointUri is needed; Alright to implement both of those). Stage in time restoration of mailbox things is out of scope https://hamidz108kym4.plpwiki.com/user