Unable to verify custom domain in Entra — domain appears associated with another tenant

Cathy Wood 20 Reputation points
2026-10-06T12:23:17.03+00:00

I own and control the DNS for progrezo.com through GoDaddy and am trying to verify the domain in my Microsoft Entra tenant.

My current Entra tenant is: 858d74e4-4298-434e-9d10-2154a19b8f47

Microsoft gave me the TXT verification value: MS=ms90590531

The TXT record has been added at the root of progrezo.com, but Entra continues to report: “Unable to verify domain name.”

The domain lookup I performed indicates that progrezo.com is associated with another Entra tenant: b6e580c4-3566-431e-9844-c0fd05c0ea79

I cannot access or switch to that tenant. My Entra Manage tenants page shows only my current Default Directory.

Question: Can someone determine whether the other tenant is managed or unmanaged, and advise how I can release progrezo.com from that tenant so I can verify it in my current tenant?

I have not deleted my current tenant or user and do not want to do so unless Microsoft confirms it is necessary.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Answer accepted by question author
Mohamed Kabesh 81 Reputation points
2026-10-06T13:02:41.2+00:00

Hi Cathy,A custom domain can only be verified in one Microsoft Entra tenant at a time. If progrezo.com is already verified in another tenant, adding the TXT record in your current tenant will prove DNS ownership, but it will not automatically release the domain from the other tenant.

The next step is to determine whether the tenant currently holding the domain is managed or unmanaged.

  1. Check whether the existing tenant is managed or unmanaged

You can try the following Microsoft sign-in realm lookup, replacing the username with any value:

https://login.microsoftonline.com/getuserrealm.srf?login=******@progrezo.com&xml=1

Check the NameSpaceType value.

  • Managed or Federated generally indicates that the domain is associated with a normal managed Entra tenant.
  • If the domain belongs to a self-service or "shadow" tenant, it may be possible to perform an administrative takeover.

The Tenant ID alone is not enough to determine whether the tenant is managed or unmanaged.

  1. If it is an unmanaged tenant

An unmanaged tenant can sometimes be created when somebody signs up for a Microsoft cloud service, such as Power BI, using an email address from the company domain.

In this situation, Microsoft supports an admin takeover process.

There are generally two approaches:

  • External admin takeover: You verify ownership of the domain through DNS and use the domain verification process with the force-takeover option from your existing tenant.
  • Internal admin takeover: You join the unmanaged directory and use Microsoft's takeover process to become its administrator, then remove the domain from that tenant before adding it to your intended tenant.

Microsoft documents this under "Take over an unmanaged directory as administrator in Microsoft Entra ID."

  1. If it is a managed tenant

A force takeover is normally not applicable to a managed tenant.

In that case, the domain must be removed from the existing tenant before it can be verified in your current tenant.

I would first check whether the tenant was created or managed by:

  • A previous IT administrator
  • A Microsoft 365 reseller or CSP
  • A previous IT service provider
  • A former employee who configured Microsoft 365/Azure services

If you cannot identify or access the administrator, I recommend opening a Microsoft Support case and providing:

  • Domain name: progrezo.com
  • Current/Destination Tenant ID: 858d74e4-4298-434e-9d10-2154a19b8f47
  • Tenant currently holding the domain: b6e580c4-3566-431e-9844-c0fd05c0ea79
  • The Entra verification error
  • The TXT verification record
  • Evidence that you control the public DNS for the domain

Ask Microsoft specifically to confirm whether the source tenant is managed or unmanaged and assist with releasing the domain if the tenant is orphaned or inaccessible.

Also confirm that the Microsoft TXT record is publicly resolvable, just to exclude DNS propagation as a separate issue.

Most importantly, do not delete your current tenant or your current user account. That should not be required to resolve the domain association.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.