🌐
Microsoft Learn
learn.microsoft.com › en-us › entra › identity › domain-services › administration-concepts
Management concepts for Microsoft Entra Domain Services - Microsoft Entra ID | Microsoft Learn
User accounts can be created in a managed domain in multiple ways. Most user accounts are synchronized in from Microsoft Entra ID, which can also include user account synchronized from an on-premises AD DS environment. You can also manually create accounts directly in the managed domain.
🌐
Microsoft Learn
learn.microsoft.com › en-us › microsoft-365 › admin › get-help-with-domains › create-dns-records-at-any-dns-hosting-provider
Add DNS records to connect your domain - Microsoft 365 admin | Microsoft Learn
Sign in to the Microsoft 365 admin center and select Show all > Settings > Domains. In a new browser tab or window, sign in to your DNS hosting provider, and then find where you manage your DNS settings (for example, Zone File Settings, Manage ...
🌐
N-able
documentation.n-able.com › covedataprotection › USERGUIDE › documentation › Content › service-management › console-new › Microsoft365 › 365-manage-domain-new-dash.htm
Manage Microsoft 365 domains
You can view only Microsoft 365 domains on any dashboard, if you click Microsoft 365 domain. ... Use the Type shortcode of AT and the value of 2 to search for devices with the Account Type of Microsoft 365 · Full details on Advanced searching and the syntax and column codes to use can be found on Searching in Management Console
🌐
Wikipedia
en.wikipedia.org › wiki › Active_Directory
Active Directory - Wikipedia
August 16, 2025 - Active Directory (AD) is a directory service developed by Microsoft for Windows domain networks. Windows Server operating systems include it as a set of processes and services. Originally, only centralized domain management used Active Directory. However, it ultimately became an umbrella title ...
🌐
Microsoft Learn
learn.microsoft.com › en-us › entra › identity › domain-services › overview
Overview of Microsoft Entra Domain Services - Microsoft Entra ID | Microsoft Learn
A managed domain is configured to perform a one-way synchronization from Microsoft Entra ID to provide access to a central set of users, groups, and credentials. You can create resources directly in the managed domain, but they aren't synchronized ...
Find elsewhere
🌐
Microsoft Learn
learn.microsoft.com › en-us › entra › identity › domain-services › tutorial-create-management-vm
Tutorial - Create a management VM for Microsoft Entra Domain Services - Microsoft Entra ID | Microsoft Learn
Microsoft Entra Domain Services provides managed domain services such as domain join, group policy, LDAP, and Kerberos/NTLM authentication that is fully compatible with Windows Server Active Directory.
🌐
Microsoft Azure
azure.microsoft.com › en-ca › products › microsoft-entra-ds
Microsoft Entra Domain Services (Azure AD DS) | Microsoft Azure
Streamline management of all applications from your legacy, directory-aware apps alongside your modern cloud apps with a single identity solution. Domain Services includes multiple domain controllers to provide high availability for your managed domain.
🌐
Microsoft Learn
learn.microsoft.com › en-us › purview › how-to-create-and-manage-domains-collections
Manage domains and collections in Data Map | Microsoft Learn
Domain admin (domain level only) - Can assign permissions within a domain and manage its resources. Collection administrator - a role for users that will need to assign roles to other users in the Microsoft Purview governance portal or manage collections. Collection admins can add users to roles on collections where they're admins.
🌐
Olive & Lake
oliveandlake.com › knowledge base › emails › how to add a domain to microsoft 365 admin center
How to add a domain to Microsoft 365 Admin Center - Olive & Lake
Click on the “manage” button for the relevant domain. Select the Dropdown arrow next to “Add Record”. Copy the TXT Value from your Microsoft 365 Admin Center which should start with MS=ms and paste that into the “Record” section in ...
🌐
Microsoft Learn
learn.microsoft.com › en-us › exchange › mail-flow-best-practices › manage-accepted-domains › manage-accepted-domains
Manage accepted domains in Exchange Online | Microsoft Learn
Download Microsoft Edge More info about Internet Explorer and Microsoft Edge ... Access to this page requires authorization. You can try signing in or changing directories. Access to this page requires authorization. You can try changing directories. ... When you add your domain to Microsoft 365 or Office 365, it's called an accepted domain.
🌐
Microsoft Learn
learn.microsoft.com › en-us › entra › identity › domain-services › tutorial-create-instance
Tutorial - Create a Microsoft Entra Domain Services managed domain - Microsoft Entra ID | Microsoft Learn
Microsoft Entra Domain Services provides managed domain services such as domain join, group policy, LDAP, Kerberos/NTLM authentication that is fully compatible with Windows Server Active Directory.
🌐
Microsoft Support
support.microsoft.com › en-us › office › connect-your-domain-to-office-365-cd74b4fa-6d34-4669-9937-ed178ac84515
Connect your domain to Office 365 - Microsoft Support
On the Connect your domain page, select I'll manage my own DNS records. We do this because we have a website that also relies on the DNS records, and we want to keep the website up. If you don't have a website or other DNS records you want to keep, choose Set up my online services for me.
Top answer
1 of 2
2

The plan to move the organization on to a domain based infra can be achieved using local domain hosted in an internal network connecting all devices using internal switches and routers and securing the infrastructure or by using Azure Active directiry which needs systems to have active internet connected.

Let's assume you are going with Azure AD and configure AD domain on Azure and public DNS. You also enable:
-- Users can register devices

We wish to introduce domain logins to our company computers. Could someone guide me where to begin as Microsoft documentation is very confusing. What services do I need to look in? The requirements we need:

First and foremost should be to configure and Azure AD settings under free plan and add users that can access the Azure services such as Domain joining etc,
Compare premium features needed under differed AAD plans and M365.
You can ask users to register the devices using windows 10/11 settings.

https://support.microsoft.com/en-us/account-billing/register-your-personal-device-on-your-work-or-school-network-8803dd61-a613-45e3-ae6c-bd1ab25bf8a8

Employees login to their W10/11 devices via domain logins (we sync users from Google, so login via e-mail user test@test .com would be what's needed).

You can federate user logons on AAD from GCP Connector using below link

https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial

We need to see the logs when and what user logged in into company owned W10/11 device.

All the logons can be seen in Azure for registered devices and can use Intune to control device behavior.

We need to manage those devices a bit, like force BitLocker to be enabled.

https://learn.microsoft.com/en-us/mem/intune/protect/advanced-threat-protection-configure

We need to be able to block user from logging in into device.

Control user logons and local admins using Azure AD.

We need to be able to give those users Admin permissions on W10/11 devices.

Control local Administrators group membership to control admin rights.

https://learn.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin#:~:text=Browse%20to%20Azure%20Active%20Directory,to%20add%20and%20select%20Add.

So, what Microsoft subscriptions I should look into to achieve this? M365? Azure? Else?
You can compare the required features of Azure AD Premium services and Microsoft 365 plans to better align resources and adapt to required feaures.
https://techbento.zendesk.com/hc/en-us/articles/1500000350541-Azure-Active-Directory-Premium-Product-Comparison
https://www.microsoft.com/en-us/microsoft-365/business/compare-all-microsoft-365-business-products

2 of 2
0

Thank you @Jasreet Singh . Digging into this now.

🌐
ZNetLive
znetlive.com › home › how to add a domain in your microsoft 365 admin center? | step-by-step guide
How to add a domain in Microsoft 365 Admin Center? ( A Guide)
October 8, 2024 - For that, Login to manage.znetlive.com/memberp >> My Services >> List Search Services >> Select the domain>> Domain Control Center >> DNS Management · Click on the DNS settings for the domain you want to configure and click on TXT Records. ... 11. Mention all the details you got from the Microsoft Admin Center and Click on Edit the Records once done to save the changes.
🌐
Reddit
reddit.com › r/office365 › microsoft hosted domains - am i going mad?
r/Office365 on Reddit: Microsoft hosted domains - Am I going mad?
September 26, 2023 -

So I recently had the need to move a sites DNS records from their current host (Cloudfair).

I didn't want to use the registrar as their interface is utter trash and transferring it out is not an option at the moment. So I thought I would move the hosting of the records to their Office 365 tenant.

Now though, it appears to be no longer an option. There used to be an option to click "Manage DNS" and one of the options was "Let Microsoft manage your DNS records". You could then change the domains name servers to ns1.bdm.microsoftonline.com, ns2, ns3 etc etc. Then add the records and away you went.

This doesn't seem possible any more? I tried speaking to MS support, but they said it's not possible even though I KNOW I did it before.

Am I going mad?

EDIT SPOKE TO Microsoft support. It has indeed been removed. Unless you select use MS name servers initially there is no way to move it across later other than removing and readding the domain. Were going to use the Azure DNS instead. Thanks all

🌐
Reddit
reddit.com › r/microsoft365 › transfer domain registrar to microsoft 365
r/microsoft365 on Reddit: Transfer Domain Registrar TO Microsoft 365
February 9, 2024 -

Hi All,

I see that you can purchase a domain in 365, move DNS SOA to 365, transfer a domain out of 365. But can you transfer a domain registration TO 365? Can't seem to see where you do that or documentation on that.