管理 Azure Active Directory 中的自定义域名Managing custom domain names in your Azure Active Directory

域名是许多目录资源标识符的重要部分:它可能是用户的用户名或电子邮件地址的一部分、组地址的一部分,有时是应用程序的应用 ID URI 的一部分。A domain name is an important part of the identifier for many directory resources: it's part of a user name or email address for a user, part of the address for a group, and is sometimes part of the app ID URI for an application. Azure Active Directory (Azure AD) 中的资源可包含目录(包含该资源)所拥有的域名。A resource in Azure Active Directory (Azure AD) can include a domain name that's owned by the directory that contains the resource. 只有全局管理员可以在 Azure AD 中管理域。Only a Global Administrator can manage domains in Azure AD.

设置 Azure AD 目录的主域名Set the primary domain name for your Azure AD directory

创建目录时,初始域名(例如“contoso.partner.onmschina.cn”)也是主域名。When your directory is created, the initial domain name, such as ‘contoso.partner.onmschina.cn,’ is also the primary domain name. 创建新用户时,主域名是新用户的默认域名。The primary domain is the default domain name for a new user when you create a new user. 设置主域名简化了管理员在门户中创建新用户的过程。Setting a primary domain name streamlines the process for an administrator to create new users in the portal. 若要更改主域名,请执行以下操作:To change the primary domain name:

  1. 使用目录全局管理员的帐户登录到 Azure 门户Sign in to the Azure portal with an account that's a Global Administrator for the directory.

  2. 选择“Azure Active Directory” 。Select Azure Active Directory.

  3. 选择“自定义域名”。Select Custom domain names.

    打开用户管理页面

  4. 选择你希望设为主域的域名。Select the name of the domain that you want to be the primary domain.

  5. 选择“设置主域”命令。Select the Make primary command. 出现提示时确认所做的选择。Confirm your choice when prompted.

    将域名设为主域名

可以将目录的主域名更改为任何未联合的已验证自定义域。You can change the primary domain name for your directory to be any verified custom domain that isn't federated. 更改目录的主域不会更改任何现有用户的用户名。Changing the primary domain for your directory won't change the user name for any existing users.

将自定义域名添加到 Azure AD 租户Add custom domain names to your Azure AD tenant

最多可以添加 900 个托管域名。You can add up to 900 managed domain names. 若要配置所有域以便与本地 Active Directory 联合,最多可在每个目录中添加 450 个域名。If you're configuring all your domains for federation with on-premises Active Directory, you can add up to 450 domain names in each directory.

添加自定义域的子域Add subdomains of a custom domain

如果想要将第三级域名(如 “test.contoso.com”)添加到目录,则应首先添加并验证第二级域,例如 contoso.com。If you want to add a third-level domain name such as ‘test.contoso.com’ to your directory, you should first add and verify the second-level domain, such as contoso.com. 子域由 Azure AD 自动验证。The subdomain is automatically verified by Azure AD. 若要查看添加的子域是否已验证,请在浏览器中刷新域列表。To see that the subdomain you added is verified, refresh the domain list in the browser.

更改自定义域名的 DNS 注册机构会发生什么情况What to do if you change the DNS registrar for your custom domain name

如果更改 DNS 注册机构,不需要 Azure AD 中执行额外的配置任务。If you change the DNS registrars, there are no additional configuration tasks in Azure AD. 可以继续对 Azure AD 使用该域名,而不会遇到中断。You can continue using the domain name with Azure AD without interruption. 如果在 Office 365、Intune 或其他依赖于 Azure AD 中的自定义域名的服务中使用自定义域名,请参阅这些服务的文档。If you use your custom domain name with Office 365, Intune, or other services that rely on custom domain names in Azure AD, see the documentation for those services.

删除自定义域名Delete a custom domain name

如果组织不再使用某个自定义域名,或者需要在另一个 Azure AD 中使用该域名,可以从 Azure AD 中删除该域名。You can delete a custom domain name from your Azure AD if your organization no longer uses that domain name, or if you need to use that domain name with another Azure AD.

要删除自定义域名,则必须先确保目录中没有任何资源依赖域名。To delete a custom domain name, you must first ensure that no resources in your directory rely on the domain name. 在以下情况下,,无法从目录删除域名:You can't delete a domain name from your directory if:

  • 任何用户都有包含域名的用户名、电子邮件地址或代理地址。Any user has a user name, email address, or proxy address that includes the domain name.
  • 任何组都有包含域名的电子邮件地址或代理地址。Any group has an email address or proxy address that includes the domain name.
  • Azure AD 中的任何应用程序都具有包含域名的应用 ID URI。Any application in your Azure AD has an app ID URI that includes the domain name.

必须更改或删除 Azure AD 目录中的任何此类资源,才能删除自定义域名。You must change or delete any such resource in your Azure AD directory before you can delete the custom domain name.

常见问题Frequently asked questions

问:为何域删除操作失败,并显示错误“此域名包含 Exchange 主控的组”?Q: Why is the domain deletion failing with an error that states that I have Exchange mastered groups on this domain name?
答: 目前,某些组(例如,支持邮件的安全组和分发列表)由 Exchange 预配,需要手动在 Exchange 管理中心 (EAC) 清理这些组。A: Today, certain groups like Mail-Enabled Security groups and distributed lists are provisioned by Exchange and need to be manually cleaned up in Exchange Admin Center (EAC). 可能有遗留的 ProxyAddresses 依赖于自定义域名,需要手动将其更新为另一个域名。There may be lingering ProxyAddresses which rely on the custom domain name and will need to be updated manually to another domain name.

问:我以 admin@contoso.com 身份登录,但无法删除域名“contoso.com”,为什么?Q: I am logged in as admin@contoso.com but I cannot delete the domain name “contoso.com”?
答: 无法引用你尝试在用户帐户名中删除的自定义域名。A: You cannot reference the custom domain name you are trying to delete in your user account name. 请确保全局管理员帐户使用初始默认域名 (.partner.onmschina.cn),例如 admin@contoso.partner.onmschina.cn。Ensure that the Global Administrator account is using the initial default domain name (.partner.onmschina.cn) such as admin@contoso.partner.onmschina.cn. 使用不同的全局管理员帐户(例如 admin@contoso.partner.onmschina.cn),或帐户为 admin@fabrikam.com 的另一个自定义域名(例如“fabrikam.com”)登录。Sign in with a different Global Administrator account that such as admin@contoso.partner.onmschina.cn or another custom domain name like “fabrikam.com” where the account is admin@fabrikam.com.

问:我单击了“删除域”按钮,但看到删除操作的状态为 In ProgressQ: I clicked the Delete domain button and see In Progress status for the Delete operation. 需要多长时间?How long does it take? 如果该操作失败,会发生什么情况?What happens if it fails?
答: 域删除操作是一个异步后台任务,会重命名对域名的所有引用。A: The delete domain operation is an asynchronous background task that renames all references to the domain name. 它在一两分钟内应会完成。It should complete within a minute or two. 如果域删除失败,请确保不存在以下情况:If domain deletion fails, ensure that you don’t have:

  • 使用 appIdentifierURI 在域名中配置了应用Apps configured on the domain name with the appIdentifierURI
  • 有任何支持邮件的组引用了自定义域名Any mail-enabled group referencing the custom domain name
  • 对域名的引用超过 1000 个More than 1000 references to the domain name

如果不符合上述任何情况,请手动清理引用,然后重试删除域。If you find that any of the conditions haven’t been met, manually clean up the references and try to delete the domain again.

使用 PowerShell 或图形 API 管理域名Use PowerShell or Graph API to manage domain names

针对 Azure Active Directory 中域名的大多数管理任务也可以使用 Microsoft PowerShell 或者使用 Azure AD 图形 API 以编程方式来完成。Most management tasks for domain names in Azure Active Directory can also be completed using Microsoft PowerShell, or programmatically using Azure AD Graph API.

后续步骤Next steps