Try removing all the error codes from your question, jsut type text in the question until one of the System Administrator experts reply to your question, sometimes the filter on that forum blocks an initial question that contains code.
Does changing Microsoft Users Domain Break Entra or Intune Connection?
I recently moved my domain from a 3rd party provider (GoDaddy) to my Microsoft tenant. This gave users our custom domain name instead of the previous ******@CompanyLLC.onmicrosoft.com type login. Since then, I have had users randomly locked out of their accounts in which I cannot reset the password to allow them back in. Working with Microsoft support, I remade the user's Windows profile and tried to move as much data as I can
Users are also getting the message "Work or school account problem - To fix this, select this notification to sign in again. Or, go to Settings > Accounts > Access work or school settings, and select Sign in again to fix your work or school account" Here they select "Sign in" the box comes up, spins, seems to sign them in, then the notification will show again in a few hours.
I've also noticed that since our LLC account changed to our custom domain, we have three accounts showing here now under the Work and School area. I couldn't add a picture but there is:
-Connected by ******@CompanyLLC.onmicrosoft.com (Connected to Company LLC MDM)
-Connected by ******@customdomain.com (Connected to Company LLC's Entra ID)
-Connected by ******@customdomain.com (Connected to Company LLC's Entra ID)
*The second two are identical and there is no way to tell if they are both to the same tenant or different*
I am trying to get ahead of this issue instead of just waiting for these Windows profiles to randomly stop working mid-day. I ran dsregcmd /status remotely on all of my PCs and I found two different issues.
Almost all users registered their devices with our Microsoft tenant, so they have the right TenantID and have this error:
| Attempt Status : 0xc000006d | |||
|---|---|---|---|
| WamDefaultSet : ERROR (0x80070520) | |||
| Error : AADSTS50034: The user account {EUII Hidden} does not exist in the 8ceb6589-b164-45dX-XXXX-X | |||
| b65135105d0 directory. To sign into this application, the account must be added to the directory. Trace ID: d8be9a3c-a0f | |||
| 6-4efb-acf5-XXXXXX792e00 Correlation ID: 5845e906-XXXX-410c-a953-XXXX9798057 Timestamp: 2024-10-22 17:13:37Z |
However, some users seemed to have registered their devices with the GoDaddy tenant and have this error:
| Attempt Status : 0xc000023c | |||
|---|---|---|---|
| WamDefaultSet : ERROR (0x80070520) | |||
| AADSTS130004: UserPrincipal doesn't have the NGC key configured. Trace ID: 3ff78ec9-XXXX-XX | |||
| 3a-bd5e-8beba858XX00 Correlation ID: 261586f8-c395-XXXd-b508-XXX03943bb8 Timestamp: 2024-10-22 16:43:14Z |
Please Note I through so "X"s in the identifier strings because I'm not sure if I'm meant to keep those private.
If you have any solutions for this, I would be extremely grateful!
Windows for home | Windows 11 | Accounts, profiles, and login
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
3 answers
Sort by: Most helpful
-
Anonymous
2024-10-23T15:23:52+00:00 Hi Dave,
I tried to post there but I get a "Violation of Code of Conduct" each time I try to post my post above there....
Thanks!
-
DaveM121 868.4K Reputation points Independent Advisor2024-10-23T14:01:04+00:00 Hi, I am Dave, I will help you with this.
I apologize, Community is just a home consumer forum, due to the scope of your question can you please post this question to our sister forum on Microsoft Q&A (The System Administrators and IT Pro Forum).
Over there you will have access to a host of System Administrators, Entra ID and InTune experts and will get a knowledgeable and quick answer to this question.