How to Retire an Old Microsoft 365 Domain and Move Users
Question details
The user needs to retire an old domain and transition users to a new domain within the same Microsoft 365 and Azure tenant.
- Product
- Microsoft 365 / Active Directory
- Device & OS
- not provided
- Scenario
- A company is changing domains but keeping the same tenant, with user identities synchronized from an on-premises Active Directory.
- Observed behavior
- There are concerns about potential duplicate identities, User Principal Name (UPN) changes, and mailbox migration issues during the domain transition.
Before initiating any domain transitions, verify that you have administrative access to both your on-premises Active Directory and the Microsoft 365 admin center, and ensure a full backup of your current AD state is available.
Update UPNs via On-Premises Active Directory
Because user accounts are synchronized from an on-premises Active Directory, all identity and UPN modifications must be made locally and then synced to Microsoft 365.
When managing a hybrid environment via Microsoft Entra Connect (formerly Azure AD Connect), your on-premises Active Directory serves as the source of authority. Attempting to change user domains directly in the Microsoft 365 admin center will result in synchronization errors.
Since this process involves complex mailbox routing and identity matching, it requires specialized knowledge to prevent downtime or duplicate accounts.
Open Active Directory Users and Computers (ADUC) on your domain controller. Select the affected users, open their Properties, navigate to the Account tab, and change their UPN suffix to the new domain.
In the Attribute Editor tab, ensure the new domain email address is set as the primary SMTP address (SMTP:user@newdomain.com) and retain the old address as a secondary proxy address (smtp:user@olddomain.com) to prevent lost emails.
Open PowerShell on your Entra Connect server and run the command 'Start-ADSyncSyncCycle -PolicyType Delta' to immediately push the identity changes to Microsoft 365.
If you encounter duplicate identities or mailbox migration issues, post your specific scenario in the Microsoft Entra Connect synchronization section of Microsoft Q&A for specialized support.
Ensure Uninterrupted Productivity with WPS Office
While your IT team manages complex Active Directory synchronizations and Microsoft 365 domain migrations, you can keep your organization's daily work running smoothly. WPS Office is a lightweight, robust office suite that serves as an excellent alternative to Microsoft Office during tenant transitions.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the setup file and follow the on-screen instructions to deploy the lightweight suite on your device.
- 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Word, Excel, and PowerPoint files without formatting loss.

Frequently Asked Questions
Can I change the domain for synchronized users directly in the Microsoft 365 Admin Center?
No. When users are synced from an on-premises Active Directory using Microsoft Entra Connect, the local AD is the source of authority. You must make the UPN changes in your local AD and allow them to synchronize to the cloud.
What happens to a user's emails when their UPN is changed to a new domain?
The user's mailbox data remains intact during a UPN change. However, you should ensure that their old email address is kept as a secondary alias (proxy address) in Active Directory so they continue to receive emails sent to the old domain.
How do I prevent duplicate accounts when migrating to a new domain?
Duplicate accounts can be avoided by modifying the existing user objects in your on-premises Active Directory rather than creating new ones. Microsoft Entra Connect uses the ImmutableID to match local AD accounts with their corresponding Microsoft 365 cloud accounts.




