We do use Office 365. The federated domain uses country.domain.com, our UPN uses domain.country and email addresses domain.com.
Changing the UPN to domain.com means when logging into office 365 we don't present the domain.com user with the AD FS login screen - so for this point, can I add an additional claim somehow for the domain.com upn users within the Office 365 relying party
trust?