Managing external identities to enable secure access for partners, customers, and other non-employees
Custom domain is verified in an unknown Entra tenant that I can't access. How do I reclaim it as the domain owner?
I own a company domain and have full access to its DNS at the registrar.
I created a new Microsoft Entra tenant and tried to add the domain as a custom domain. I added the TXT record Azure asked for, and it resolves publicly (checked against several public DNS resolvers and the domain's authoritative nameservers). Verification still fails with:
"Unable to verify domain name. Ensure you have added the record above at the registrar for '[domain]', and try again in a little while."
After investigating, I found that the domain is already verified in another tenant:
- The domain's OpenID configuration endpoint (
login.microsoftonline.com/<domain>/.well-known/openid-configuration) returns an issuer with a different tenant ID. -
getuserrealm.srfreturnsNameSpaceType: Managed(not viral/unmanaged), so admin takeover doesn't seem to apply.
Nobody in the company has admin access to that tenant, and we don't know who created it. It was probably a former employee or vendor.
Questions:
- What is the process to regain Global Administrator access to that tenant, or to have the domain released, when I can prove domain ownership through DNS?
- Should I open a support request from my new tenant, and if so, under which service and problem type?
- Is there anything I should keep or avoid changing in DNS during the process? For example, an older Microsoft verification TXT record (
MS=ms...) is still published.I own a company domain and have full access to its DNS at the registrar. I created a new Microsoft Entra tenant and tried to add the domain as a custom domain. I added the TXT record Azure asked for, and it resolves publicly (checked against several public DNS resolvers and the domain's authoritative nameservers). Verification still fails with: "Unable to verify domain name. Ensure you have added the record above at the registrar for '[domain]', and try again in a little while." After investigating, I found that the domain is already verified in another tenant:- The domain's OpenID configuration endpoint (
login.microsoftonline.com/<domain>/.well-known/openid-configuration) returns an issuer with a different tenant ID. -
getuserrealm.srfreturnsNameSpaceType: Managed(not viral/unmanaged), so admin takeover doesn't seem to apply.
- What is the process to regain Global Administrator access to that tenant, or to have the domain released, when I can prove domain ownership through DNS?
- Should I open a support request from my new tenant, and if so, under which service and problem type?
- Is there anything I should keep or avoid changing in DNS during the process? For example, an older Microsoft verification TXT record (
MS=ms...) is still published.
- The domain's OpenID configuration endpoint (