Custom domain is verified in an unknown Entra tenant that I can't access. How do I reclaim it as the domain owner?

Ahmad AlDrarga 0 Reputation points
2026-09-27T07:55:33.8833333+00:00

I own a company domain and have full access to its DNS at the registrar.

I created a new Microsoft Entra tenant and tried to add the domain as a custom domain. I added the TXT record Azure asked for, and it resolves publicly (checked against several public DNS resolvers and the domain's authoritative nameservers). Verification still fails with:

"Unable to verify domain name. Ensure you have added the record above at the registrar for '[domain]', and try again in a little while."

After investigating, I found that the domain is already verified in another tenant:

  • The domain's OpenID configuration endpoint (login.microsoftonline.com/<domain>/.well-known/openid-configuration) returns an issuer with a different tenant ID.
  • getuserrealm.srf returns NameSpaceType: Managed (not viral/unmanaged), so admin takeover doesn't seem to apply.

Nobody in the company has admin access to that tenant, and we don't know who created it. It was probably a former employee or vendor.

Questions:

  1. What is the process to regain Global Administrator access to that tenant, or to have the domain released, when I can prove domain ownership through DNS?
  2. Should I open a support request from my new tenant, and if so, under which service and problem type?
  3. Is there anything I should keep or avoid changing in DNS during the process? For example, an older Microsoft verification TXT record (MS=ms...) is still published.I own a company domain and have full access to its DNS at the registrar. I created a new Microsoft Entra tenant and tried to add the domain as a custom domain. I added the TXT record Azure asked for, and it resolves publicly (checked against several public DNS resolvers and the domain's authoritative nameservers). Verification still fails with: "Unable to verify domain name. Ensure you have added the record above at the registrar for '[domain]', and try again in a little while." After investigating, I found that the domain is already verified in another tenant:
    • The domain's OpenID configuration endpoint (login.microsoftonline.com/<domain>/.well-known/openid-configuration) returns an issuer with a different tenant ID.
    • getuserrealm.srf returns NameSpaceType: Managed (not viral/unmanaged), so admin takeover doesn't seem to apply.
    Nobody in the company has admin access to that tenant, and we don't know who created it. It was probably a former employee or vendor. Questions:
    1. What is the process to regain Global Administrator access to that tenant, or to have the domain released, when I can prove domain ownership through DNS?
    2. Should I open a support request from my new tenant, and if so, under which service and problem type?
    3. Is there anything I should keep or avoid changing in DNS during the process? For example, an older Microsoft verification TXT record (MS=ms...) is still published.
Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.