A cloud-based identity and access management service for securing user authentication and resource access
Hi Cathy,A custom domain can only be verified in one Microsoft Entra tenant at a time. If progrezo.com is already verified in another tenant, adding the TXT record in your current tenant will prove DNS ownership, but it will not automatically release the domain from the other tenant.
The next step is to determine whether the tenant currently holding the domain is managed or unmanaged.
- Check whether the existing tenant is managed or unmanaged
You can try the following Microsoft sign-in realm lookup, replacing the username with any value:
https://login.microsoftonline.com/getuserrealm.srf?login=******@progrezo.com&xml=1
Check the NameSpaceType value.
- Managed or Federated generally indicates that the domain is associated with a normal managed Entra tenant.
- If the domain belongs to a self-service or "shadow" tenant, it may be possible to perform an administrative takeover.
The Tenant ID alone is not enough to determine whether the tenant is managed or unmanaged.
- If it is an unmanaged tenant
An unmanaged tenant can sometimes be created when somebody signs up for a Microsoft cloud service, such as Power BI, using an email address from the company domain.
In this situation, Microsoft supports an admin takeover process.
There are generally two approaches:
- External admin takeover: You verify ownership of the domain through DNS and use the domain verification process with the force-takeover option from your existing tenant.
- Internal admin takeover: You join the unmanaged directory and use Microsoft's takeover process to become its administrator, then remove the domain from that tenant before adding it to your intended tenant.
Microsoft documents this under "Take over an unmanaged directory as administrator in Microsoft Entra ID."
- If it is a managed tenant
A force takeover is normally not applicable to a managed tenant.
In that case, the domain must be removed from the existing tenant before it can be verified in your current tenant.
I would first check whether the tenant was created or managed by:
- A previous IT administrator
- A Microsoft 365 reseller or CSP
- A previous IT service provider
- A former employee who configured Microsoft 365/Azure services
If you cannot identify or access the administrator, I recommend opening a Microsoft Support case and providing:
- Domain name: progrezo.com
- Current/Destination Tenant ID: 858d74e4-4298-434e-9d10-2154a19b8f47
- Tenant currently holding the domain: b6e580c4-3566-431e-9844-c0fd05c0ea79
- The Entra verification error
- The TXT verification record
- Evidence that you control the public DNS for the domain
Ask Microsoft specifically to confirm whether the source tenant is managed or unmanaged and assist with releasing the domain if the tenant is orphaned or inaccessible.
Also confirm that the Microsoft TXT record is publicly resolvable, just to exclude DNS propagation as a separate issue.
Most importantly, do not delete your current tenant or your current user account. That should not be required to resolve the domain association.