Part of the Okta-M365 Integration guide
You cannot federate the default Microsoft domain with Okta. For this reason, you must configure the *.OnMicrosoft domain to be the default domain before proceeding with the integration.
BEFORE YOU BEGIN
Completing this as part of the Okta-M365 Integration? This procedure assumes you have already identified and managed all Entra ID service accounts using legacy authentication.
Steps
NOTE
Most M365 tenants will already have a purchased domain registered — if so, skip Step 1 and proceed directly to Step 2. You only need Step 1 if you are working in a new sandbox or lab environment where the purchased domain has not yet been added to M365.
If your domain is not yet registered in M365: Follow Microsoft's instructions to add a domain to Microsoft 365. Then continue to Step 2.
In your M365 tenant, navigate to Settings → Domains.
If the *.OnMicrosoft domain is not already listed as the default, click the three dots next to the *.OnMicrosoft domain and select Set as default.
Click Set as default on the confirmation window.
Confirm that the *.OnMicrosoft domain is now listed as the default domain.
NEXT STEPS
Completing the Okta-M365 Integration? Continue to Remove Entra Connect.
