The user principal name (UPN) claim is enabled by default because you selected the Federated Web SSO with Forest Trust scenario. ...