Custom domain <pii removed> locked in inaccessible tenant - cannot verify in Entra ID

Abdul Wahab Qazi 0 Reputation points
2026-05-12T05:16:21.17+00:00

Hi,

I am trying to add a custom domain <PII REMOVED> to

my Microsoft Entra ID tenant but verification keeps failing.

After investigation I found the domain is already registered

in another tenant:

Tenant ID: <PII REMOVED>

I confirmed this by running:

Invoke-RestMethod -Uri "https://login.microsoftonline.com/

choosycloud.com/.well-known/openid-configuration"

This old tenant belongs to a previous Azure account which

is now blocked and inaccessible to me.

I am the verified owner of <PII REMOVED> on Namecheap

(domain registrar). The TXT record MS=ms27855831 is live

and fully propagated globally (verified on dnschecker.org).

Questions:

  1. How can I release<PII REMOVED> from tenant <PII REMOVED>
  2. Is there a self-service way to reclaim a domain from an old inaccessible tenant?

Thank you

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-12T05:16:36.22+00:00
    1. Releasing choosycloud.com from tenant 54df3c1e-4150-422f-a1ab-480be335ea3d

    Microsoft Entra does not allow the same custom domain to be verified in more than one tenant at a time. As long as choosycloud.com is verified in tenant 54df3c1e-4150-422f-a1ab-480be335ea3d, verification in the new tenant will fail.

    The only supported way to release the domain is to have it deleted from the old tenant. Because that tenant is blocked/inaccessible, this cannot be done self‑service and requires Microsoft support intervention:

    1. Confirm that choosycloud.com is still present as a custom domain in the old tenant (which you effectively did by discovering the tenant ID and OpenID configuration).
    2. Open a support case with Microsoft (Azure/Microsoft Entra support) and provide:
      • The domain name choosycloud.com.
      • Proof of ownership from Namecheap (registrar account screenshots, WHOIS, etc.).
      • The old tenant ID 54df3c1e-4150-422f-a1ab-480be335ea3d and the fact that it is blocked/inactive.
    3. Request that support either:
      • Reactivate the old tenant long enough for the domain to be removed, or
      • Perform a domain removal/domain takeover operation on the backend, based on proof of domain ownership.

    Microsoft’s platform enforces that a domain can be verified in only one directory at a time:

    “A domain name can only be verified in one directory. If your domain name is currently verified in another directory, it can't also be verified in the new directory. To fix this duplication problem, you must delete the domain name from the old directory.”

    Until support removes the domain from the old tenant, verification in the new tenant will not succeed.

    1. Self‑service reclaim options

    There is no fully self‑service way to reclaim a custom domain from an old tenant that is blocked and cannot be accessed.

    The normal self‑service options are:

    • Sign in to the old tenant as a Global/Domain Name Administrator and delete the custom domain.
    • If the tenant is only in an “inactive” state and still within the reactivation window, request tenant reactivation and then remove the domain.

    However, once the tenant is blocked and inaccessible to the admin, and especially if it is past the supported reactivation window, only Microsoft support can intervene. The domain cannot be re‑verified in another tenant until it is removed from the old one.

    After Microsoft removes the domain from the old tenant and you add it to the new tenant:

    1. Add choosycloud.com as a custom domain in the new tenant.
    2. Create the TXT (or MX) record provided by Entra at Namecheap with TTL 3600 seconds.
    3. Wait for DNS propagation and then select Verify in Entra ID → Domain names.

    If planning to use subdomains (for example, for custom URL domains), each subdomain that will be used for sign‑in must also be verified individually.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.