Unable to associate MPNID to App

Martin Destagnol 0 Reputation points
2026-10-03T00:43:45.15+00:00

Hi–

I'm unable to associate the MPN ID to a new app we created.

We have 2 tenants, the one that we used until now, linked to domain1.com. domain1.com is also the domain we used for the Partner Center vetting process for our email verification.

Then we created a second tenant, linked to domain2.com. We added that tenant to the same partner center and we made sure to allow a user from that tenant 2 as Global Admin in partner center.

Now I see that one requirement to link the MPNID to an app in tenant 2 is that the domain2.com must have been used in the partner center vetting process. How is it possible in this case to have more than one tenant and domain linked to the same Partner Center?

Thank you so much for your help

–Martin

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-03T00:44:04.6633333+00:00

    Yes, a single Partner Center account can have multiple Microsoft Entra tenants associated with it, but publisher verification for an app still has a separate domain-matching requirement.

    What is happening:

    • Partner Center supports associating multiple Microsoft Entra tenants to one account.
    • However, when adding the Partner ID/MPN ID to an app for publisher verification, the app’s Publisher Domain or one of the verified custom domains in that same tenant must match the domain used for Partner Center email verification.
    • If Partner Center vetting was completed with domain1.com, then an app in tenant 2 cannot be publisher-verified unless domain1.com is verified in tenant 2, or the app is moved to the tenant where domain1.com is already verified.
    • A custom domain can only be verified in one Microsoft Entra directory at a time.

    In the scenario described, that is why multi-tenant association in Partner Center works, but MPN ID association to the app in tenant 2 fails. Tenant association and publisher verification are different requirements.

    Supported paths:

    1. Register and verify the app in the tenant that already contains domain1.com
      • This works because the Partner Center verified domain and the app tenant domain alignment requirement is satisfied there.
    2. Use a different verified domain in tenant 2 and obtain Partner Center/MPN verification aligned to that domain
      • If tenant 2 uses domain2.com, then the domain used in Partner Center verification must match domain2.com for publisher verification in that tenant.
    3. Move domain1.com verification to tenant 2
      • This is only possible by removing/unverifying it from the current tenant first. This is disruptive because a custom domain can only exist as verified in one directory at a time.

    Checks to perform in tenant 2:

    1. In Microsoft Entra admin center, confirm whether domain1.com or the Partner Center verified domain exists under custom domains.
    2. In App registrations > the app > Branding and Properties, check the Publisher Domain.
    3. Compare that value with the domain used for the Partner Center primary contact email verification.
    4. If they do not match, publisher verification will fail with the domain mismatch condition.

    Role requirements called out in the documentation:

    • To associate tenants in Partner Center, a Manager role in Partner Center can do that in some Partner Center flows.
    • For the multi-tenant account flow, the documented role is Global admin.
    • For publisher-domain remediation in Entra, sign in as at least Cloud Application Administrator.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.