logo
search
Others

How to Convert a Federated Microsoft Entra Domain to Managed

Tauseeq MagsiTauseeq Magsi Sep 29, 2026 868 views

Question details

The user is unable to convert a federated Microsoft Entra domain to a managed domain due to FederationExceptions, Microsoft Graph 400 errors, and strict MFA policies blocking PowerShell access.

How to Convert a Federated Microsoft Entra Domain to Managed
Product
Microsoft Entra ID
Device & OS
not provided
Scenario
Attempting to change a domain's authentication type from Federated to Managed using PowerShell or Microsoft Graph.
Observed behavior
Running Convert-MsolDomainToStandard returns a FederationException, and Microsoft Graph returns a 400 Domain operation is not allowed error. Additionally, phishing-resistant MFA prevents the user from running Connect-MsolService.
Before you start

Ensure you have Global Administrator privileges and verify that your AD FS services are accessible and operating correctly before attempting the domain conversion.

Solution 1Recommended

Force Conversion via Set-MsolDomainAuthentication

Bypasses the standard conversion tool by explicitly setting the domain authentication type to Managed via PowerShell.

When the standard Convert-MsolDomainToStandard command fails due to stale federation metadata, explicitly forcing the authentication state can resolve the issue.

1
Open PowerShell as Administrator

Launch Windows PowerShell with elevated Administrator privileges on your system.

2
Connect to Microsoft Online

Type Connect-MsolService and press Enter to authenticate with your Microsoft Entra Global Administrator credentials.

3
Execute the conversion command

Run the command Set-MsolDomainAuthentication -DomainName "yourdomain.com" -Authentication Managed, replacing yourdomain.com with your actual domain.

4
Verify domain status

Run Get-MsolDomain to confirm that the Authentication column for your domain now displays 'Managed'.

Force Conversion via Set-MsolDomainAuthentication
Free Microsoft Office alternative

Manage Your Business Documents Seamlessly with WPS Office

While Microsoft Entra handles your domain identities, WPS Office provides a lightweight, highly compatible alternative for your team's document productivity without the complex administrative overhead of Microsoft 365 apps.

Free, lightweight, and fast deployment across enterprise networks.Excellent compatibility with Microsoft Word, Excel, and PowerPoint formats.Familiar user interface reduces training time and ensures seamless migration for employees.Robust PDF editing and conversion tools built-in to handle all business needs.
microsoft office alternative - wps office

Frequently Asked Questions

Why does Convert-MsolDomainToStandard return a FederationException?

This error typically occurs when there is stale or corrupted AD FS federation metadata lingering in Microsoft Entra, which prevents the automated service from executing a smooth transition to managed authentication.

What should I do if a 400 Domain operation is not allowed error occurs?

A 400 error from Microsoft Graph indicates that backend configurations or lingering federation trusts are explicitly blocking the change. You should try forcing the change using the Set-MsolDomainAuthentication PowerShell command. If that fails, contact Microsoft Support to clear the backend block.

How do I manage a domain if Conditional Access blocks PowerShell?

If phishing-resistant MFA blocks your Connect-MsolService access, you must use a Break-Glass (emergency access) Global Administrator account that is temporarily excluded from the Conditional Access policy to run the necessary PowerShell commands.

Can I convert a domain back to Federated later?

Yes, you can convert a Managed domain back to Federated by using your AD FS configuration tools or running the Set-MsolDomainAuthentication -Authentication Federated command, provided your federation infrastructure is properly configured.