Single Lable AD Domain and Microsoft Entra ID connect

Fiorenza Meini 0 Reputation points
2026-08-06T08:43:02.0266667+00:00

Hi there,

I understand that using a single-label domain isn't supported by the Entra ID sync connector, but I can't consider migrating to another domain at this time. Please, is there a way to make it work?

This is the error displayed:

User's image

Thank you

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-08-06T08:43:27.62+00:00

    Yes, but only in a limited sense.

    A single-label domain is supported by Microsoft Entra Connect Sync only if the network configuration for that single-label domain is functioning correctly. However, Microsoft strongly recommends against single-label domains.

    There is one important unsupported case: if the Active Directory NetBIOS domain name differs from the FQDN domain name, installing Microsoft Entra Connect is unsupported.

    For sign-in to Microsoft Entra ID, the larger constraint is that Microsoft Entra Connect can sync only to a verified domain in Microsoft Entra ID. Single-label and other nonroutable domains can't be verified in Microsoft Entra ID. In that situation, the supported path is to use custom settings in Microsoft Entra Connect and configure a routable, verified sign-in domain instead of relying on the single-label domain suffix.

    If the on-premises UPN suffix is nonroutable, the documented options are:

    1. Add a new UPN suffix in AD DS that matches a domain verified in Microsoft Entra ID.
    2. Update user UPNs to use that verified suffix.
    3. Run Microsoft Entra Connect using custom installation so the sign-in configuration uses the verified domain.

    If changing every user UPN is not possible immediately, Microsoft Entra Connect custom installation also supports selecting another attribute as the sign-in ID when userPrincipalName is nonroutable. This is the alternate ID option. That attribute must follow RFC 822 format, and in Active Directory it can't be multivalued.

    So the practical answer is:

    • Keeping the single-label AD domain itself may be possible if the environment is otherwise valid.
    • Using that single-label name as the Microsoft Entra sign-in domain is not supported, because Microsoft Entra ID requires a verified routable domain.
    • The supported workaround is to keep the existing AD domain, but add and use a verified routable UPN suffix or configure an alternate ID during custom setup.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.