AFAIK, when I authenticate my users via ntlm_auth (samba AD bnind, etc..., not the LDAP module, as suggested by the docu), account names in SAM are used instead of UPN (please, correct me if I'm wrong) Is it possible to use UPN instead? What drawbacks can we have if we do this? Thanks