Converting "Federated user accounts" to "Managed user accounts"

Oatlhotse Gaborone 20 Reputation points
2025-04-16T15:47:22.9466667+00:00

Hello

I am using "Microsoft Entra ID Free Subscription." I want to convert "Federated user accounts" to "Managed user accounts." I tried to follow these instructions in Power Shell to no Avail:
Install-Module MSOnline -Force

Install-PackageProvider -Name NuGet -Force

Connect-MsolService

Set-MsolDomainAuthentication -DomainName  -Authentication Managed

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Answer accepted by question author
  1. Anonymous
    2025-04-21T19:09:23.77+00:00

    Hello Oatlhotse Gaborone

    Reference:https://learn.microsoft.com/en-us/entra/fundamentals/add-custom-domain?context=azure%2Factive-directory%2Fusers-groups-roles%2Fcontext%2Fugr-context

    To verify your custom domain name, follow these steps:

    1. Sign in to the Microsoft Entra admin center as at least a Domain Name Administrator.
    2. Browse to Identity > Settings > Domain names.
    3. In Custom domain names, select the custom domain name. In this example, select contoso.com. Screenshot of Fabrikam - Custom domain names page, with Contoso highlighted.
    4. The unverified domain is added. The contoso.com page appears showing the DNS information needed to validate your domain ownership. Save this information. Screenshot of Contoso page with DNS entry information. 5.On the contoso.com page, select Verify to make sure your custom domain is properly registered and is valid If this answers your query, do click `Accept Answer` and `Yes`
      Screenshot of Contoso page with DNS entry information and the Verify button.

1 additional answer

Sort by: Most helpful
  1. Ariel Alarcon 0 Reputation points
    2025-05-22T14:42:35.07+00:00

    I need migrate my domain from federated to managed, i have entra connect sync ok with PHS. The Stage rollout running ok, but ... on ADFS server with global admins rights,

    Set-MsolDomainAuthentication -DomainName "intranet.domain.com.ar" -Authentication Managed

    Set-MsolDomainAuthentication : Access Denied. You do not have permissions to call this cmdlet. At line:1 char:1 + Set-MsolDomainAuthentication -DomainName "intranet.domain.com.ar" - ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~     + CategoryInfo          : OperationStopped: (:) [Set-MsolDomainAuthentication], MicrosoftOnlineException     + FullyQualifiedErrorId : Microsoft.Online.Administration.Automation.AccessDeniedException,Microsoft.Online.Administration.Automation.SetDomainAuthentication


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.