A cloud-based identity and access management service for securing user authentication and resource access
Yes, a single Partner Center account can have multiple Microsoft Entra tenants associated with it, but publisher verification for an app still has a separate domain-matching requirement.
What is happening:
- Partner Center supports associating multiple Microsoft Entra tenants to one account.
- However, when adding the Partner ID/MPN ID to an app for publisher verification, the app’s Publisher Domain or one of the verified custom domains in that same tenant must match the domain used for Partner Center email verification.
- If Partner Center vetting was completed with domain1.com, then an app in tenant 2 cannot be publisher-verified unless domain1.com is verified in tenant 2, or the app is moved to the tenant where domain1.com is already verified.
- A custom domain can only be verified in one Microsoft Entra directory at a time.
In the scenario described, that is why multi-tenant association in Partner Center works, but MPN ID association to the app in tenant 2 fails. Tenant association and publisher verification are different requirements.
Supported paths:
- Register and verify the app in the tenant that already contains domain1.com
- This works because the Partner Center verified domain and the app tenant domain alignment requirement is satisfied there.
- Use a different verified domain in tenant 2 and obtain Partner Center/MPN verification aligned to that domain
- If tenant 2 uses domain2.com, then the domain used in Partner Center verification must match domain2.com for publisher verification in that tenant.
- Move domain1.com verification to tenant 2
- This is only possible by removing/unverifying it from the current tenant first. This is disruptive because a custom domain can only exist as verified in one directory at a time.
Checks to perform in tenant 2:
- In Microsoft Entra admin center, confirm whether domain1.com or the Partner Center verified domain exists under custom domains.
- In App registrations > the app > Branding and Properties, check the Publisher Domain.
- Compare that value with the domain used for the Partner Center primary contact email verification.
- If they do not match, publisher verification will fail with the domain mismatch condition.
Role requirements called out in the documentation:
- To associate tenants in Partner Center, a Manager role in Partner Center can do that in some Partner Center flows.
- For the multi-tenant account flow, the documented role is Global admin.
- For publisher-domain remediation in Entra, sign in as at least Cloud Application Administrator.
- Add and manage multiple tenants in your Partner Center account
- Associate an existing Microsoft Entra ID tenant in Partner Center
- Troubleshoot publisher verification
- Unable to verify Custom Domain in Azure Active Directory albeit the TXT is valid. - Microsoft Q&A
- How to Verify Publisher on a subsidiary tenant - Microsoft Q&A