Impact of Removing a Domain from an Intune Tenant
Question details
An administrator needs to know whether devices will be blocked if a domain name is removed from a Microsoft 365 tenant containing Intune-enrolled or Microsoft Entra joined devices.

- Product
- Microsoft Intune
- Device & OS
- not provided
- Scenario
- Planning to remove a domain name from a Microsoft 365 tenant with active managed devices.
- Observed behavior
- Concerns about potential disruptions to device management, user sign-in processes, and Microsoft 365 service access.
Before attempting to remove any domain, ensure you have Global Administrator access to the Microsoft 365 Admin Center and have thoroughly mapped out all active user accounts, certificates, and devices tied to the target domain.
Review Dependencies and Open a Microsoft Support Request
Removing a domain from an Intune tenant can significantly disrupt access and device management. Follow these steps to verify dependencies and engage support before making changes.
Removing or changing a domain can prevent users from signing in, severely affect device management, and disrupt access to Microsoft 365 services. The exact impact depends heavily on your organization's specific configuration. Do not remove the domain until all dependencies are reviewed.
Navigate to the Active Users section in the Microsoft 365 Admin Center. Ensure no user accounts are actively using the domain you plan to remove as their User Principal Name (UPN).
Check your Microsoft Entra ID and Intune administration portals to identify any devices joined or enrolled using credentials tied to the target domain.
Review your tenant's certificates, registered enterprise applications, and custom authentication settings that might rely on the domain's DNS records.
Go to the Microsoft 365 admin center, open the Help & support pane, and create a ticket specifically for Microsoft Intune or Microsoft Entra to safely plan your domain removal without blocking existing devices.

Deploy WPS Office to Your Managed Devices
Managing Microsoft 365 domains and Intune device policies can be a complex task. When outfitting your workforce with productivity software, consider WPS Office as a free, lightweight, and user-friendly alternative to Microsoft Office that is fully compatible with standard document formats and easy to deploy across your organization's managed devices.
- 1. Download the Installer: Obtain the official WPS Office installation package for your desired operating system.
- 2. Deploy via MDM: Use your mobile device management (MDM) solution, such as Intune, to distribute the software to your endpoints.
- 3. Open Office Files: Users can instantly open, edit, and save their existing Microsoft Office files without formatting issues.

Frequently Asked Questions
Can I change the primary domain in Microsoft 365 without affecting Intune devices?
Changing the primary domain can still affect user UPNs. If a user's UPN changes, they may need to re-authenticate on their Intune-enrolled or Entra-joined devices to restore full service access.
What happens to users if their domain is removed abruptly?
Removing a domain tied to active users will prevent them from signing into Microsoft 365 services and will disrupt authentication on their Microsoft Entra joined devices.
How do I open a support request for Intune domain removal?
Sign in to the Microsoft 365 Admin Center, click on 'Support' and then 'Help & support' in the left navigation pane. Briefly describe your domain removal scenario to request guidance from the Intune or Entra support team.




