A cloud-based identity and access management service for securing user authentication and resource access
The orphaned or failed Microsoft Entra Domain Services (Azure AD DS) managed domain cannot be fixed or deleted from the client side when:
- The resource no longer exists at the ARM/subscription level (all ARM operations return 404, subscription-level list is empty), and
- The managed domain is still present in the Entra/Domain Services backend and reports a failed state with instructions to contact support.
In this state, the only supported remediation is direct intervention by Microsoft support. The documented guidance for unrecoverable or invalid Domain Services states:
- When resources are in an unrecoverable or invalid state (for example, AADDS100, AADDS110, AADDS113, AADDS114), the resolution is to either:
- Delete the managed domain and recreate it, or
- Open an Azure support request so Microsoft can repair or clean up the instance.
- If the platform cannot automatically recreate or repair required resources, the environment is considered unsupported and must be fixed by Microsoft support.
Because the ARM resource is already gone and the backend object is stuck, self-service delete is no longer possible. The required action is:
- Open an Azure support request specifically for Microsoft Entra Domain Services, providing:
- Microsoft Entra tenant ID.
- Managed domain name.
- Subscription ID and resource group where the domain was originally deployed.
- Ask support to:
- Clean up the orphaned Domain Services instance in the Microsoft Entra backend, or
- Restore the instance from backup and then delete it cleanly.
If the portal blocks ticket creation under the current support plan, use the documented path to contact Azure support (including the global support phone numbers or the generic “get support” entry point) and reference that the managed domain is in an unrecoverable/failed state and cannot be deleted via ARM.
There is no documented CLI, PowerShell, or ARM-based workaround for this scenario once the service is in an unrecoverable failed state and the resource is missing at the subscription level. Backend cleanup by Microsoft support is required.
References:
- Common errors and troubleshooting steps for Microsoft Entra Domain Services
- Known issues: Common alerts and resolutions in Microsoft Entra Domain Services
- 7 Day Old Azure Account: AADSTS5000225: This tenant has been blocked due to inactivity. - Microsoft Q&A
- Severity A Situation - Locked out of global admin account (MFA) - business down - Microsoft Q&A