Set up domains for directory authentication

Last updated on Aug 3, 2026

Claim domains using DNS validation or IdP sync, then link them to directories to enable user authentication.

Setting up domains in your Admin Console controls how users authenticate and allows you to share entitlements across your organization.

Use this procedure to manually add and validate domains when your directory uses Microsoft Azure AD federation or Google Federation sync. Validated domains from your identity provider sync automatically to the Admin Console.

Add domains at the organization level and link them to directories or add domains directly to a directory.

Add domains at the organization level

Sign in to the Admin Console and navigate to Settings > Identity > Domains.

Select Add Domains.

Enter one or more domain names and select Next. You can claim and validate up to 15 domains at a time.

Review the domain list and select Add Domains.

Add domains inside a directory

Sign in to the Admin Console and navigate to Settings > Identity > Domains.

Select and open the target directory, then select Add domain.

Choose your method: add domains from Microsoft Azure Active Directory, Google, or via DNS proof.

Follow the provider-specific steps for Azure or Google to import claimed domains. For DNS proof, enter domain names, review them, and select Add.

Note

Users on domains added via DNS proof cannot sign in until you verify ownership with your domain host.

Demonstrate domain ownership in Admin Console

In the Admin Console, navigate to Settings > Identity > Domains.

Select the menu icon and choose Access DNS Token.

Work with your DNS manager to add a TXT record containing the generated DNS token to your domain's DNS configuration.

Wait for DNS propagation. Admin Console automatically validates domains when DNS records are correct.

Tip

DNS changes can take up to 72 hours to propagate. The Admin Console validates domains when records are detected.

To validate immediately after DNS configuration, navigate to Settings > Identity > Domains, select the menu icon, choose Validate domains, and select Validate.

When you validate a domain, all subdomains are validated instantly as you add them to the Admin Console. You use a single DNS token to demonstrate ownership of all domains in your organization.

Link domains to directories

If your directories and domains are configured separately in the Admin Console, link each domain to a directory. You can link multiple domains to the same directory if they use the same SSO settings.

Note

Skip this step if you added domains directly inside a directory. All domains linked to a single directory must share identical SSO settings.

In the Admin Console, navigate to Settings > Identity > Domains.

Select your target domain, then select Link directory from the menu icon. To link multiple domains to the same directory, select multiple checkboxes before choosing Link directory.

On the Link to directory screen, choose the directory from the dropdown, then select Link.

You can also add users with email addresses on unclaimed domains, including public domains like gmail.com. However, your control over authentication for these users may be limited. For domains claimed by other organizations, you can request access via directory trust.