使用 Azure Active Directory 门户添加自定义域名Add your custom domain name using the Azure Active Directory portal

每个新的 Azure AD 租户都附带了一个初始域名 domainname.partner.onmschina.cn。Every new Azure AD tenant comes with an initial domain name, domainname.partner.onmschina.cn. 无法更改或删除初始域名,但可以将组织的名称添加到列表中。You can't change or delete the initial domain name, but you can add your organization's names to the list. 添加自定义域名有助于创建用户所熟悉的用户名,例如 alain@contoso.comAdding custom domain names helps you to create user names that are familiar to your users, such as alain@contoso.com.

准备阶段Before you begin

添加自定义域名之前,必须在域注册机构处创建域名。Before you can add a custom domain name, you must create your domain name with a domain registrar. 有关认证的域注册机构,请参阅 ICANN 认证的注册机构For an accredited domain registrar, see ICANN-Accredited Registrars.

在 Azure AD 中创建目录Create your directory in Azure AD

获取域名后,可以创建第一个 Azure AD 目录。After you get your domain name, you can create your first Azure AD directory.

  1. 使用具有订阅“所有者”角色的帐户登录到 Azure 门户,然后选择“Azure Active Directory”。Sign in to the Azure portal for your directory, using an account with the Owner role for the subscription, and then select Azure Active Directory. 有关订阅角色的详细信息,请参阅经典订阅管理员角色、Azure RBAC 角色和 Azure AD 管理员角色For more information about subscription roles, see Classic subscription administrator roles, Azure RBAC roles, and Azure AD administrator roles.

    Azure 门户屏幕,其中显示了 Azure AD 选项

    Tip

    如果计划使用 Azure AD 联合你的本地 Windows Server AD,则需要在运行 Azure AD Connect 工具来同步目录时选中“我计划将此域配置为使用本地 Active Directory 进行单一登录”复选框。If you plan to federate your on-premises Windows Server AD with Azure AD, then you need to select the I plan to configure this domain for single sign-on with my local Active Directory checkbox when you run the Azure AD Connect tool to synchronize your directories. 还需要在向导的“Azure AD 域”步骤中注册选择用于与本地目录进行联合的域名。You also need to register the same domain name you select for federating with your on-premises directory in the Azure AD Domain step in the wizard. 这些说明中示范了向导中该步骤的大致情形。You can see what that step in the wizard looks like in these instructions. 如果没有 Azure AD Connect 工具,可以 在此处下载If you do not have the Azure AD Connect tool, you can download it here.

  2. 遵循为组织创建新租户中的步骤创建新目录。Create your new directory by following the steps in Create a new tenant for your organization.

    Important

    租户的创建者将自动成为该租户的全局管理员。The person who creates the tenant is automatically the Global administrator for that tenant. 全局管理员可将其他管理员添加到租户中。The Global administrator can add additional administrators to the tenant.

将自定义域名添加到 Azure ADAdd your custom domain name to Azure AD

创建目录后,可以添加自定义域名。After you create your directory, you can add your custom domain name.

  1. 依次选择“自定义域名”、“添加自定义域”。Select Custom domain names, and then select Add custom domain.

    “自定义域名”页,其中显示了“添加自定义域”

  2. 在“自定义域名”框中键入组织的新域名(例如 contoso.com),然后选择“添加域”。Type your organization's new domain name into the Custom domain name box (for example, contoso.com), and then select Add domain.

    随即会添加未验证的域,并出现“Contoso”页,其中显示了 DNS 信息。The unverified domain is added and the Contoso page appears showing you your DNS info.

    Important

    若要正常完成此过程,必须包含 .com、.net 或其他任何顶级扩展名。You must include .com, .net, or any other top-level extension for this to work properly.

    “自定义域名”页,其中显示了“添加自定义域”页

  3. 复制“Contoso”页中的 DNS 信息。Copy the DNS info from the Contoso page. 例如 MS=ms64983159。For example, MS=ms64983159.

    包含 DNS 条目信息的“Contoso”页

将 DNS 信息添加到域注册机构Add your DNS information to the domain registrar

将自定义域名添加到 Azure AD 之后,必须返回到域注册机构,并添加已复制的 TXT 文件中的 Azure AD DNS 信息。After you add your custom domain name to Azure AD, you must return to your domain registrar and add the Azure AD DNS information from your copied TXT file. 为域创建此 TXT 记录可以“验证”域名的所有权。Creating this TXT record for your domain "verifies" ownership of your domain name.

  • 返回到域注册机构,根据复制的 DNS 信息为域创建新的 TXT 记录,将“TTL”(生存时间)设置为 3600 秒(60 分钟),然后保存信息。Go back to your domain registrar, create a new TXT record for your domain based on your copied DNS information, set the TTL (time to live) to 3600 seconds (60 minutes), and then save the information.

    Important

    可以注册任意数目的域名。You can register as many domain names as you want. 但是,每个域将从 Azure AD 获取其自身的 TXT 记录。However, each domain gets its own TXT record from Azure AD. 在域注册机构处输入 TXT 文件信息时请小心。Be careful when entering your TXT file information at the domain registrar. 如果输入了错误或重复的信息,则必须等到 TTL 超时(60 分钟),然后才能重试。If you enter the wrong, or duplicate information by mistake, you'll have to wait until the TTL times out (60 minutes) before you can try again.

验证自定义域名Verify your custom domain name

注册自定义域名后,需确保它在 Azure AD 中有效。After you register your custom domain name, you need to make sure it's valid in Azure AD. 将信息从域注册机构传播到 Azure AD 有时可以瞬间完成,有时需要几天时间,具体取决于域注册机构的状况。The propagation from your domain registrar to Azure AD can be instantaneous or it can take up to a few days, depending on your domain registrar.

验证自定义域名To verify your custom domain name

  1. 使用目录的全局管理员帐户登录到 Azure 门户Sign in to the Azure portal using a Global administrator account for the directory.

  2. 依次选择“Azure Active Directory”、“自定义域名”。Select Azure Active Directory, and then select Custom domain names.

  3. 在“Fabrikam - 自定义域名”页上,选择自定义域名“Contoso”。On the Fabrikam - Custom domain names page, select the custom domain name, Contoso.

    “Fabrikam - 自定义域名”页,其中突出显示了“Contoso”

  4. 在“Contoso”页上,选择“验证”以确保自定义域已正确注册并且在 Azure AD 中有效。On the Contoso page, select Verify to make sure your custom domain is properly registered and is valid for Azure AD.

    包含 DNS 条目信息和“验证”按钮的“Contoso”页

验证自定义域名后,可以删除验证 TXT 或 MX 文件。After you've verified your custom domain name, you can delete your verification TXT or MX file.

常见验证问题Common verification issues

  • 如果 Azure AD 无法验证自定义域名,请尝试以下建议的方法:If Azure AD can't verify a custom domain name, try the following suggestions:

    • 至少等待一小时,然后重试Wait at least an hour and try again. 只有在传播 DNS 记录之后,Azure AD 才能验证域,而此过程可能需要一小时或更长时间。DNS records must propagate before Azure AD can verify the domain and this process can take an hour or more.

    • 确保 DNS 记录正确。Make sure the DNS record is correct. 返回到域名注册机构站点,确保其中包含该条目,并且该条目与 Azure AD 提供的 DNS 条目信息相匹配。Go back to the domain name registrar site and make sure the entry is there, and that it matches the DNS entry information provided by Azure AD.

      如果无法在注册机构站点上更新记录,必须与有权添加条目并验证其准确性的某人共享该条目。If you can't update the record on the registrar site, you must share the entry with someone that has the right permissions to add the entry and verify it's accurate.

  • 确保域名尚未在另一目录中使用。Make sure the domain name isn't already in use in another directory. 只能在一个目录中验证一个域名,这意味着,如果当前在另一目录中验证你的域名,则无法同时在新目录中验证该域名。A domain name can only be verified in one directory, which means that if your domain name is currently verified in another directory, it can't also be verified in the new directory. 若要解决此重复问题,必须从旧目录中删除该域名。To fix this duplication problem, you must delete the domain name from the old directory. 有关删除域名的详细信息,请参阅管理自定义域名For more information about deleting domain names, see Manage custom domain names.

  • 确保你没有任何非托管的 Power BI 租户。Make sure you don't have any unmanaged Power BI tenants. 如果你的用户通过自助注册激活了 Power BI 并为你的组织创建了一个非托管租户,那么你必须使用 PowerShell 以内部或外部管理员的身份接管管理。If your users have activated Power BI through self-service sign-up and created an unmanaged tenant for your organization, you must take over management as an internal or external admin, using PowerShell.

后续步骤Next steps