How to delete default domain in Entra ID B2C?
Could you please advise on the appropriate steps to request the blocking of the default domain (<tenant-name>.b2clogin.com
) in Entra ID B2C, as recommended in the official documentation?
We have already configured a custom domain for our B2C tenant, and per Microsoft’s guidance, access to the default domain should be blocked to help prevent potential misuse or attacks. However, it appears that this action can only be performed by Microsoft via a support request.
Given that I do not currently have a support plan and do not wish to purchase one solely for this process, I would appreciate your guidance on how to proceed under the current support structure. Specifically:
What is the correct process to follow in this scenario?
Is there a specific support ticket type or contact channel that allows for this type of security-related request without a paid support plan?
For reference, here is the relevant excerpt from Microsoft documentation:
“After you configure custom domains, users will still be able to access the Azure AD B2C default domain name
<tenant-name>.b2clogin.com
. You need to block access to the default domain so that attackers can't use it to access your apps or run distributed denial-of-service (DDoS) attacks. Submit a support ticket to request for the blocking of access to the default domain.”
Thank you in advance for your support and guidance on this.
Best