StudyToCert

All certifications / SC-300 / Lessons

Microsoft Certified: Identity and Access Administrator Associate SC-300 (skills outline of April 27, 2026) · Domain 1: Implement and manage user identities

Tenant setup: custom domain names and DNS verification, company branding, tenant properties and user settings

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

A Microsoft Entra tenant is the dedicated instance of Microsoft Entra ID (the cloud identity service formerly called Azure Active Directory) that holds your organization's users, groups, devices and applications. Every tenant starts with an initial domain ending in onmicrosoft.com. That domain is permanent: you can't delete it, and it stays useful as a fallback sign-in name for emergency accounts. Most organizations then add a custom domain such as contoso.com so people sign in with a familiar user principal name (UPN) like ana@contoso.com.

Adding a custom domain is a two-step process. First you add the name in the Microsoft Entra admin center under Domain names. Entra then gives you a verification value (it looks like MS=ms12345678) that you publish as a TXT record, or alternatively an MX record, at your public DNS host. When you select Verify, Entra looks up the record; only someone who controls the domain's DNS could have created it, so this proves ownership. DNS changes can take time to propagate, so a failed first attempt usually just means waiting. A domain can be verified in only one tenant at a time, and you can later make a verified domain the primary domain, which becomes the default suffix for new users. To remove a custom domain you must first move or delete every user, group and app that still uses it.

Company branding customizes the sign-in experience: background image, banner logo, square logo, background color, sign-in page text, and links for self-service password reset or a privacy statement. You configure a default sign-in experience and can add language-specific versions for users whose browser requests another language. Branding appears after the user types a username in your domain, which is also a quiet anti-phishing signal: users learn what the real page looks like. Branding requires a paid license tier, not the free edition.

Tenant properties hold organization-level details: the tenant name, the tenant ID (a GUID that apps and scripts use to identify the directory), the country or region chosen at creation (which cannot be changed later and determines data location), the technical contact, and the global privacy contact and privacy statement URL that guest users see.

User settings are tenant-wide switches that shape what ordinary members may do. Examples include whether users can register applications, whether non-administrators are restricted from browsing the Microsoft Entra admin center, whether users can create security groups or Microsoft 365 groups, whether users may connect LinkedIn accounts, and whether they can read other users' profiles. Tightening these defaults is a quick least-privilege win in a new tenant, because the out-of-the-box settings favor collaboration over control.

Key terms

Initial domain
The permanent tenantname.onmicrosoft.com domain created with every tenant; it cannot be removed.
Domain verification
Proving you own a custom domain by publishing a TXT or MX record with an Entra-supplied value in public DNS.
Primary domain
The verified domain used as the default UPN suffix when you create new users.
Tenant ID
The GUID that uniquely identifies a Microsoft Entra tenant, used by apps, scripts and federation settings.
Company branding
Customization of the sign-in page with your logos, background, colors and text, with optional per-language versions.
Real-world example

Fabrikam buys fabrikam.com and wants staff to sign in as name@fabrikam.com. The admin adds the domain in Entra, copies the MS=ms value into a TXT record at the registrar, waits for DNS to update, selects Verify and sets it as primary. She then uploads the corporate logo and background as company branding and turns off the user setting that lets members register applications.

Exam tip: Remember that verification uses a TXT (or MX) record, not a CNAME, and that the onmicrosoft.com domain can never be deleted. If a question asks why a domain can't be removed, look for users, groups or apps still using it.

Check yourself

What DNS record types can you use to verify a custom domain in Microsoft Entra ID?

A TXT record (most common) or an MX record containing the MS=ms verification value that Entra gives you.

Why might an administrator be unable to delete a custom domain from the tenant?

Objects such as users, groups or applications still reference the domain in their names or URIs; they must be renamed or removed first.

Which tenant property is fixed at creation and cannot be changed?

The country or region, which also determines where the tenant's data is located.

Study SC-300 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-300 study plan