First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Entra ID Tenant-to-Tenant Basic Transition
Migration

Microsoft Entra ID Tenant-to-Tenant Basic Transition — Microsoft 365 Tenant Migration

Entra ID Tenant-to-Tenant Basic Transition establishes your users, groups, and identity configuration in a new Microsoft 365 tenant, typically for mergers, acquisitions, restructuring, or a move to a different geographic region. There is no native way to "move" a Microsoft Entra ID tenant, so the honest model is re-provisioning: IT Partner creates and maps identities in the target tenant, sequences the custom domain cutover (a domain can be verified in only one tenant at a time), issues temporary passwords because passwords cannot be exported, and supports the device and application reconfiguration that a tenant change requires. The basic transition is delivered as a single coordinated cutover, commonly scheduled over a weekend, within a 5-day engagement for $1,300.

Timeline 5 daysService owner Roman SotnikMicrosoft Azure

What this engagement is

This service transitions Microsoft Entra ID (formerly Azure AD) identities from one Microsoft 365 tenant to another. Because Microsoft provides no native mechanism to move a tenant or export its identities wholesale, the transition is a controlled re-provisioning exercise: IT Partner creates or maps the in-scope users and groups in the target tenant, plans the sign-in name strategy around the custom domain — which can exist in only one tenant at a time, so its removal from the source and verification in the target happen in a planned cutover window — and sets up temporary passwords, because Microsoft Entra ID passwords cannot be exported. Devices joined or registered to the source tenant cannot carry their join state across; IT Partner provides reconfiguration support and guidance so devices re-join and applications tied to Microsoft Entra ID are re-registered or re-pointed in the target tenant. The basic transition uses a single coordinated cutover, commonly scheduled over a weekend; organizations that need phased coexistence between the two tenants should look at the Entra ID Tenant-to-Tenant Staged Transition instead.

Success criteria

01Target Microsoft Entra ID tenant is prepared for the agreed basic identity transition scope.
02In-scope users and groups are created, mapped, or transitioned in the target tenant according to the approved migration plan.
03Temporary password process is configured and validated for in-scope users because source passwords cannot be exported.
04A pilot or validation sample confirms that migrated users can sign in to the target tenant using the agreed login format and temporary password process.
05In-scope group membership and basic identity attributes are validated against the agreed migration inventory.
06Device and application reconfiguration guidance is provided for the identified Entra ID-dependent devices, applications, and services.
07Client administrator receives handover notes, known issues, and any recommended next steps after the transition.
08The engagement is considered complete when the agreed basic transition checklist is completed and accepted by the client.

What you receive

Migration of users, groups, and resources to a new Microsoft Entra ID tenant.
User and group migration to the new tenant while preserving logins.
Temporary passwords for users to access the new tenant and set up permanent credentials.
Support for reconfiguring devices that use Microsoft Entra ID for authentication.
Guidance for reconfiguring applications and services tied to Microsoft Entra ID.
Customized migration plan to fit business size and needs.

How the work unfolds

Kickoff and scope confirmation

Confirm business drivers, source and target tenants, expected user and group scope, migration constraints, cutover preferences, success criteria, and key stakeholders.

Tenant and identity discovery

Review the source tenant identity inventory, including users, groups, domains, sign-in names, role assignments, device dependencies, and applications or services tied to Microsoft Entra ID.

Target tenant readiness

Validate target tenant access, administrative permissions, licensing assumptions, domain readiness, baseline Entra ID settings, and any policies that could affect user sign-in.

Migration design and mapping

Prepare the user and group mapping approach, login naming approach, temporary password handling, cutover checklist, validation approach, and user communication requirements.

Pilot or sample validation

Transition a small representative sample where feasible, verify sign-in behavior, confirm group mapping, validate temporary passwords, and adjust the runbook before full execution.

Basic transition execution

Create, update, or migrate in-scope Entra ID users and groups in the target tenant, apply the agreed temporary password process, and perform the planned identity cutover activities.

Device and application reconfiguration support

Provide agreed assistance and guidance for devices, applications, and services that authenticate through Microsoft Entra ID so owners can complete required reconfiguration.

Post-transition validation

Validate representative user sign-in, group membership, basic access behavior, and identified Entra ID dependencies. Track and triage transition issues discovered during validation.

Handover and closure

Provide final status, known issues, recommended next steps, and administrative handover information for the target tenant.

Prerequisites

Source and target Microsoft 365 tenants are available and accessible before kickoff.
Client provides appropriate administrative access or delegated access to both source and target tenants, typically Global Administrator, Privileged Role Administrator, or other roles required for the agreed tasks.
Client provides an approved list of in-scope users, groups, required login names, and any users or groups that must be excluded.
Target tenant licensing is available for in-scope users where licensing is required for the target-state services.
Custom domain ownership, DNS administration access, and domain release or verification approach are available if sign-in names or domains must be moved between tenants.
Client identifies device owners, application owners, and service owners for systems that use Microsoft Entra ID authentication.
Existing Conditional Access, MFA, security defaults, identity protection, and authentication method requirements are reviewed for impact on first sign-in and temporary passwords.
Any hybrid identity dependencies, such as on-premises Active Directory or Microsoft Entra Connect, are disclosed before planning the transition.
A user communication plan is available, including timing, login instructions, temporary password distribution approach, and support escalation contacts.
Client approves a transition window and understands that sign-in changes may require user action.

Who does what

IT Partner

  • Transfer users and groups to the new tenant while preserving logins.
  • Set up temporary passwords so users can access the new tenant and set up permanent credentials.
  • Provide assistance with reconfiguring devices that use Microsoft Entra ID for authentication.
  • Provide help with reconfiguring applications and services tied to Microsoft Entra ID.
  • Provide customized migration plans to fit the client’s business size and needs.
  • Provide support from planning to execution.

Your team

  • Provide timely administrative access or approve delegated access for the source and target tenants.
  • Confirm the in-scope users, groups, domains, devices, applications, and services for the basic transition.
  • Supply or approve the desired target login format, user mapping, group mapping, and any naming changes.
  • Ensure required Microsoft licenses, subscriptions, and third-party licenses are available in the target environment.
  • Provide DNS access and approve any custom domain changes if domain movement or verification is required.
  • Communicate the migration schedule, expected sign-in changes, and temporary password instructions to end users.
  • Coordinate business application owners, device owners, and help desk teams for testing and reconfiguration.
  • Participate in pilot testing, validation, and final acceptance of the completed transition.
  • Maintain business decisions, approvals, and change-management communications outside the technical migration tasks.

What's not included

Full Microsoft 365 workload migration, including Exchange mailboxes, SharePoint sites, Teams content, OneDrive data, Planner, Forms, Power Platform, or other service data, unless separately scoped.
Large-scale hands-on device rejoin, workstation rebuild, Intune enrollment, Autopilot deployment, or endpoint profile migration unless separately scoped.
Complex application remediation, custom application code changes, SAML/OIDC redesign, third-party vendor configuration, or full SSO modernization unless separately scoped.
On-premises Active Directory redesign, domain consolidation, forest migration, or Microsoft Entra Connect redesign unless separately scoped.
Advanced security architecture redesign, Conditional Access policy redesign, Identity Protection tuning, privileged access program design, or compliance policy implementation unless separately scoped.
Source tenant decommissioning, license cancellation, archival, legal hold, eDiscovery, or data-retention work unless separately scoped.
End-user training sessions, onsite floor-walking, extended hypercare, or after-hours support unless included in the agreed statement of work.
Third-party migration tools, Microsoft licensing costs, DNS provider fees, application vendor fees, or other external charges.
Migration of existing user passwords, because passwords cannot be exported from Microsoft Entra ID.

Limitations & technical notes

!Passwords cannot be exported from Microsoft Entra ID due to security restrictions. Users receive temporary passwords to access the new tenant and set up permanent credentials.
!A custom domain can be verified in only one Microsoft Entra ID tenant at a time. Preserving sign-in names requires removing the domain from the source tenant and verifying it in the target during a planned change window; users may sign in with onmicrosoft.com addresses in the interim.
!Custom domain changes can be affected by DNS propagation, existing tenant bindings, and Microsoft service dependencies.
!Users should expect sign-in changes and may need to re-authenticate, update credentials, reconfigure profiles, or complete MFA registration in the target tenant.
!Microsoft Entra join and registration cannot be migrated between tenants: devices joined to or registered with the source tenant must be re-joined, re-registered, or re-enrolled in management in the target tenant.
!Applications using Microsoft Entra ID authentication may require new app registrations, redirect URI updates, certificate or secret updates, consent changes, or vendor-side configuration.
!Conditional Access, MFA, authentication methods, directory roles, enterprise applications, and audit history do not transfer between tenants; they are rebuilt in the target tenant, and only items within the agreed scope are configured by this service.
!Hybrid identity environments can introduce dependencies on on-premises Active Directory, synchronization rules, source anchors, and Microsoft Entra Connect configuration.

Frequently asked questions

What is the Entra ID Tenant-to-Tenant Basic Transition service?

It moves your Microsoft Entra ID identities — users, groups, and related configuration — from one Microsoft 365 tenant to another as a single coordinated cutover. It is typically used for mergers, acquisitions, restructuring, or migration to a different geographic region, where identities must be established in a new tenant.

Can a Microsoft Entra ID tenant just be moved to another tenant?

No. Microsoft provides no native mechanism to move a tenant or export its identities wholesale. The supported approach — and what this service delivers — is re-provisioning: users and groups are created and mapped in the target tenant, the custom domain is cut over in a planned window, and devices and applications are reconfigured against the new tenant.

What does this tenant-to-tenant transition include?

Migration of in-scope users, groups, and identity configuration to the new Microsoft Entra ID tenant, a customized migration plan, temporary password setup, sign-in and domain cutover planning, and support for reconfiguring devices, applications, and services that authenticate through Microsoft Entra ID.

Will user sign-in names be preserved?

Sign-in names on your custom domain can be preserved, but not simultaneously in both tenants: a domain can be verified in only one Microsoft Entra ID tenant at a time. IT Partner sequences the domain removal from the source tenant and verification in the target during the cutover window; in the interim users may sign in with onmicrosoft.com addresses.

Can users keep their existing passwords after the tenant migration?

No — Microsoft Entra ID passwords cannot be exported, for security reasons. IT Partner sets up temporary passwords so users can sign in to the new tenant and create permanent credentials, and users should also expect to re-register MFA methods in the target tenant.

What happens to devices joined to the old tenant?

Microsoft Entra join and registration cannot be migrated between tenants. Devices joined or registered to the source tenant must be re-joined or re-registered against the target tenant, and re-enrolled in management where Intune is used. This service includes reconfiguration assistance and guidance; large-scale hands-on device rejoin work is scoped separately.

What about Conditional Access, MFA settings, and enterprise applications?

These do not transfer between tenants. Conditional Access policies, authentication methods, directory roles, and application registrations are rebuilt in the target tenant. This service covers the items within the agreed basic scope; a full security-architecture rebuild is scoped separately.

How long does the basic transition take, and what does it cost?

The engagement is priced at $1,300 fixed and runs 5 days, with the identity cutover itself executed as a single coordinated event — commonly scheduled over a weekend to reduce business impact. The price is quoted in writing before work begins.

Is this a full Microsoft 365 tenant migration?

No — this offering covers Microsoft Entra ID identities only. Mailboxes, SharePoint, Teams, and OneDrive move through separate workload migrations, which IT Partner also provides; the identity transition is typically the foundation those migrations build on.

What is the difference between the Basic and Staged transitions?

Basic is a single cutover: all in-scope identities move in one coordinated event, which suits smaller organizations and clean breaks. The Staged Transition runs the two tenants in coexistence and moves users in waves — appropriate when the organization needs phased access to both environments during a longer transition.

What prerequisites are required before starting?

Accessible source and target tenants with appropriate administrative access, an approved list of in-scope users and groups, target-tenant licensing for in-scope users, DNS access and a domain cutover approach where sign-in names move, disclosure of any hybrid identity dependencies (such as Microsoft Entra Connect), identified device and application owners, a user communication plan, and an approved transition window.

What is not included in this basic transition service?

Microsoft 365 workload data migration (Exchange, SharePoint, Teams, OneDrive, Power Platform), large-scale hands-on device rejoin or Intune/Autopilot deployment, complex application remediation or SSO redesign, on-premises Active Directory or Microsoft Entra Connect redesign, Conditional Access architecture redesign, source tenant decommissioning, third-party tool and licensing costs, and password migration — which is technically impossible. Each can be scoped separately where needed.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,300
5 days
Book a meeting