Federated identity management using Active Directory Federation Services
Hi there,
This is a classic and notoriously frustrating identity lockout scenario. GoDaddy uses a custom Active Directory federation model, and when you migrate your DNS and email to another provider like NameCheap without first defederating the domain inside Azure AD, the tenant remains hardcoded to redirect all authentication attempts back to GoDaddy's defunct SSO infrastructure.
Since you are in a "Zero Admin" state with the custom domain, here is exactly how you can regain access:
1. Check for the "Break-Glass" Account When the Azure AD tenant was first provisioned, Microsoft created a default routing domain. If you (or the previous admin) have the password for the original [admin]@lawsofrobots.onmicrosoft.com Global Administrator account, try logging in with that at portal.azure.com. Accounts ending in .onmicrosoft.com bypass custom domain federation entirely. Once in, you can use the MSOnline or Graph PowerShell modules to force the defederation.
2. Escalate to the Microsoft Data Protection Team If no .onmicrosoft.com fallback exists, standard tier-1 support cannot help you. You must engage the Data Protection Team, as only Microsoft can forcefully defederate the domain from the backend.
Call the Microsoft Azure / Microsoft 365 Business Support phone number for your region.
Clearly state that you are experiencing a "Tenant Lockout due to broken GoDaddy Federation" and need to escalate to the Data Protection Team.
They will ask for the Tenant ID and Subscription ID you provided. To prove ownership, they will give you a unique string to add as a DNS TXT record. Since you have access to NameCheap, you will pass this verification step easily and they will help you reset the admin access.
Hang in there—it takes a little time on the phone with Microsoft, but since you control the DNS, you will definitely get your tenant back!