Share via

Blocking onmicrosoft subdomains

Cameron Carter 0 Reputation points
2025-09-24T16:42:59.1233333+00:00

What is the impact of blocking 'onmicrosft.com' in the external access settings.

Given this is the default for tenants when created will this have any impact other than preventing communications from those that have not moved to a custom domain?

Additionally, will adding 'onmicrosoft.com' by default include subdomains or is this configured elsewhere?

Microsoft Teams | Microsoft Teams for business | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Vy Nguyen 11,485 Reputation points Microsoft External Staff Moderator
    2025-09-24T18:01:59.4366667+00:00

    Hi @Cameron Carter

    Thank you for posting your question in the Microsoft Q&A forum.  

    Based on your description, I appreciate your interest in understanding how the onmicrosoft.com domain works within Microsoft 365. I’d be happy to explain this in a way that suits your situation and helps you move forward confidently. 

    When you create a new Microsoft 365 tenant, Microsoft automatically assigns a default domain in the format yourdomain.onmicrosoft.com. This domain is essential for system-level operations and cannot be deleted or blocked. It serves as the foundation for your tenant’s identity and is used behind the scenes for various services. 

    However, once you have your own domain (for example, yourcompany.com), you can add it to your tenant and set it as the default for your organization. This allows you to personalize your users’ email addresses and usernames with your custom domain, while still keeping the original onmicrosoft.com domain for internal system use. 

    Here’s how you can add and set up your custom domain: 

    1. Sign in to the Microsoft 365 admin center using your admin credentials. 
    2. Go to the Settings > Domains section.  User's image
    3. Click on Add domain.  User's image
    4. Enter the domain name you want to use (e.g., yourcompany.com) and click Continue.  User's image
    5. Click on the “>” icon to expand the detail records.  User's image
    6. Follow the prompts to verify ownership of the domain. This usually involves adding a TXT record to your DNS settings. Copy the expected records of MX, CNAME, TXT records and paste that at your domain registrar's site.  User's image
    7. Once verified, you can begin creating user accounts and assigning email addresses using your custom domain. 

    Now that you've added the record at your domain registrar's site, you'll go back to Microsoft and search for the record. When Microsoft finds the correct records, your domain is verified.  

    Typically, it takes about 15 minutes for DNS changes to take effect. However, it can occasionally take longer for a change you've made to update across the Internet's DNS system. 

    For your references: Add a domain to Microsoft 365 - Microsoft 365 admin | Microsoft Learn 

    After this setup, any new users you create can use the custom domain by default. You can also update existing users to use the custom domain in their usernames and email addresses. 

    In short, while the onmicrosoft.com domain is permanent and cannot be removed, you have full flexibility to use your own domain for day-to-day communication and branding. This setup ensures your organization maintains a professional identity while still benefiting from Microsoft’s infrastructure. 

    I hope this information is helpful. Please follow these steps and let me know if it works for you. If not, we can work together to resolve this.  

    Thank you for your patience and your understanding. If you have any questions, please feel free to reach out.  

    I'm looking forward for your reply.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  User's image

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.