Microsoft Entra ID: Custom domain held in inaccessible managed tenant, forceTakeover returns Invalid cross-cloud verification code

Himanshu Arora 5 Reputation points
2026-09-21T09:39:56.71+00:00

Summary

I administer IT for a small manufacturing business. The business's custom domain is verified in an old, dormant Microsoft Entra tenant, and I need it released so it can be verified in the business's current tenant, where I am Global Administrator.

I do not have administrative access to the source tenant.

Environment

  • Service: Microsoft Entra ID, custom domain verification
  • Cloud: both tenants appear to be in the worldwide commercial cloud
  • Tooling: Microsoft Graph PowerShell SDK and the Graph v1.0 domain verify API
  • Documentation followed: Admin takeover of an unmanaged directory, including the external takeover sequence using Invoke-MgGraphRequest

What I have already confirmed

  • The source tenant is managed, not unmanaged. When I add the domain in the destination tenant, Microsoft names a masked Global Administrator for the source tenant, so self-service internal and external admin takeover do not apply.
  • DNS ownership is proven. The TXT verification record expected by the destination tenant is live in public DNS and matches exactly. Microsoft accepts it as valid proof of ownership, but the add is blocked because the domain remains verified in the source tenant.
  • External admin takeover was attempted and rejected. Called from the destination tenant through the Graph domain verify API with forceTakeover set to true.

Error returned

HTTP 400 Bad Request
Code:              Request_BadRequest
Message:           Invalid cross-cloud verification code.
request-id:        40a9fea7-3999-41df-8723-19bd16f5664e
client-request-id: fea88b6b-8c7f-49e2-9688-6c957105cd56

Since both tenants appear to be in the same cloud, the cross-cloud wording is unexpected. I have not found this error documented anywhere.

Support history

  • Five case numbers have been created on this issue since 9 September 2026.
  • Each time the case has reached the Data Protection team, it has been classified as an MFA or Global Administrator account issue, even though the request is a domain release. The earlier cases were closed on that basis without the domain being released.
  • The current case was classified correctly as a domain release by the front-line engineer, who transferred it to the Data Protection team with a written note stating that it is a domain release and not account recovery.
  • On receipt, the Data Protection team again logged the issue description as MFA.

My question

How can this domain be released from the source tenant?

Given that external admin takeover returns Invalid cross-cloud verification code, and that the support case keeps being reclassified as an MFA or account recovery issue, I would be grateful if a moderator could help ensure the current case is handled by the Data Protection team as a domain release, and stays open until the domain is actually released. If the cross-cloud error indicates anything that changes how the release must be handled, that would also help.

Deadline

Web hosting and email for this domain expire on 25 October 2026.

I can share the domain name, both tenant IDs and the case number by private message, and I will publish any additional TXT token requested within fifteen minutes.

Microsoft Security | Microsoft Entra | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.