How to Convert a Federated Microsoft Entra Domain to Managed
Question details
The user is unable to convert a federated Microsoft Entra domain to a managed domain due to FederationExceptions, Microsoft Graph 400 errors, and strict MFA policies blocking PowerShell access.

- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Attempting to change a domain's authentication type from Federated to Managed using PowerShell or Microsoft Graph.
- Observed behavior
- Running Convert-MsolDomainToStandard returns a FederationException, and Microsoft Graph returns a 400 Domain operation is not allowed error. Additionally, phishing-resistant MFA prevents the user from running Connect-MsolService.
Ensure you have Global Administrator privileges and verify that your AD FS services are accessible and operating correctly before attempting the domain conversion.
Force Conversion via Set-MsolDomainAuthentication
Bypasses the standard conversion tool by explicitly setting the domain authentication type to Managed via PowerShell.
When the standard Convert-MsolDomainToStandard command fails due to stale federation metadata, explicitly forcing the authentication state can resolve the issue.
Launch Windows PowerShell with elevated Administrator privileges on your system.
Type Connect-MsolService and press Enter to authenticate with your Microsoft Entra Global Administrator credentials.
Run the command Set-MsolDomainAuthentication -DomainName "yourdomain.com" -Authentication Managed, replacing yourdomain.com with your actual domain.
Run Get-MsolDomain to confirm that the Authentication column for your domain now displays 'Managed'.

Bypass Phishing-Resistant MFA for PowerShell Connections
Resolves connection issues when strict Conditional Access policies prevent Global Administrators from running Connect-MsolService.
Review AD FS Metadata and Escalate to Support
Necessary when backend federation metadata is corrupted and the Microsoft Graph API consistently returns a 400 error.
Manage Your Business Documents Seamlessly with WPS Office
While Microsoft Entra handles your domain identities, WPS Office provides a lightweight, highly compatible alternative for your team's document productivity without the complex administrative overhead of Microsoft 365 apps.

Frequently Asked Questions
Why does Convert-MsolDomainToStandard return a FederationException?
This error typically occurs when there is stale or corrupted AD FS federation metadata lingering in Microsoft Entra, which prevents the automated service from executing a smooth transition to managed authentication.
What should I do if a 400 Domain operation is not allowed error occurs?
A 400 error from Microsoft Graph indicates that backend configurations or lingering federation trusts are explicitly blocking the change. You should try forcing the change using the Set-MsolDomainAuthentication PowerShell command. If that fails, contact Microsoft Support to clear the backend block.
How do I manage a domain if Conditional Access blocks PowerShell?
If phishing-resistant MFA blocks your Connect-MsolService access, you must use a Break-Glass (emergency access) Global Administrator account that is temporarily excluded from the Conditional Access policy to run the necessary PowerShell commands.
Can I convert a domain back to Federated later?
Yes, you can convert a Managed domain back to Federated by using your AD FS configuration tools or running the Set-MsolDomainAuthentication -Authentication Federated command, provided your federation infrastructure is properly configured.




