- Mastering Identity and Access Management with Microsoft Azure
- Jochen Nickel
- 279字
- 2021-07-02 12:57:20
Configuring a custom domain
Under the Azure Active Directory | Custom domain section, click Add custom domain and complete the verification process to prove that you are the owner of the domain:
data:image/s3,"s3://crabby-images/bb2d4/bb2d4ce1e1dc34f1405f65a4aa7cd7b4cabe5c34" alt=""
Add the TXT entry shown to your DNS zone to verify the domain:
data:image/s3,"s3://crabby-images/8e42f/8e42f8c76ab0b96dfe01df4ad67e8c5160b2d39f" alt=""
Click the Verify button on your Azure portal, and after successful verification, the new DOMAIN NAME will appear under DOMAINS. Choose the Make primary option:
data:image/s3,"s3://crabby-images/338d8/338d8da2d0d5942cbe8f06111cfb531348219b95" alt=""
Open https://portal.office.com to complete the domain setup process under the admin section:
data:image/s3,"s3://crabby-images/3d619/3d61925b9bc3257e2e02f595547ff99e921082a5" alt=""
Choose the custom domain to be used for email addresses:
data:image/s3,"s3://crabby-images/6380a/6380a9958e95ce6dd04e7585d1a9f8c15730e928" alt=""
The last step we need to take is to set the new UserPrincipalNames to the existing users. We do this with a small example scripting solution:
- Connect to your Azure AD with your global administrator credentials:
Connect-AzureAD
- Export the existing users to a CSV file with the following cmdlet:
Get-AzureADUser -All $True | Where { $_.UserPrincipalName.ToLower().EndsWith("onmicrosoft.com")} | Export-Csv C:\Office365Users.csv
- Remove all accounts you don't want to modify and make the change with the following cmdlets:
$domain = "inovitlabs.ch"
Import-Csv 'C:\Office365Users.csv' | ForEach-Object {
$newupn = $_.UserPrincipalName.Split("@")[0] + "@" + $domain
Write-Host "Changing UPN value from: "$_.UserPrincipalName" to: " $newupn -ForegroundColor Green
Set-AzureADUser -ObjectId $_.UserPrincipalName -UserPrincipalName $newupn
}
- You should get a result similar to this:
data:image/s3,"s3://crabby-images/dde30/dde3066bade758ef6fe57e0cc94f2ab03828900b" alt=""
The primary email will also be changed to the custom domain.
Next, we will configure the Azure AD Domain services to provide a transition scenario for a Kerberos-based application that is normally provided in on-premises infrastructure.