Microsoft Entra ID Tenant-to-Tenant Basic Transition — Microsoft 365 Tenant Migration
Entra ID Tenant-to-Tenant Basic Transition establishes your users, groups, and identity configuration in a new Microsoft 365 tenant, typically for mergers, acquisitions, restructuring, or a move to a different geographic region. There is no native way to "move" a Microsoft Entra ID tenant, so the honest model is re-provisioning: IT Partner creates and maps identities in the target tenant, sequences the custom domain cutover (a domain can be verified in only one tenant at a time), issues temporary passwords because passwords cannot be exported, and supports the device and application reconfiguration that a tenant change requires. The basic transition is delivered as a single coordinated cutover, commonly scheduled over a weekend, within a 5-day engagement for $1,300.
What this engagement is
This service transitions Microsoft Entra ID (formerly Azure AD) identities from one Microsoft 365 tenant to another. Because Microsoft provides no native mechanism to move a tenant or export its identities wholesale, the transition is a controlled re-provisioning exercise: IT Partner creates or maps the in-scope users and groups in the target tenant, plans the sign-in name strategy around the custom domain — which can exist in only one tenant at a time, so its removal from the source and verification in the target happen in a planned cutover window — and sets up temporary passwords, because Microsoft Entra ID passwords cannot be exported. Devices joined or registered to the source tenant cannot carry their join state across; IT Partner provides reconfiguration support and guidance so devices re-join and applications tied to Microsoft Entra ID are re-registered or re-pointed in the target tenant. The basic transition uses a single coordinated cutover, commonly scheduled over a weekend; organizations that need phased coexistence between the two tenants should look at the Entra ID Tenant-to-Tenant Staged Transition instead.
Success criteria
What you receive
How the work unfolds
Confirm business drivers, source and target tenants, expected user and group scope, migration constraints, cutover preferences, success criteria, and key stakeholders.
Review the source tenant identity inventory, including users, groups, domains, sign-in names, role assignments, device dependencies, and applications or services tied to Microsoft Entra ID.
Validate target tenant access, administrative permissions, licensing assumptions, domain readiness, baseline Entra ID settings, and any policies that could affect user sign-in.
Prepare the user and group mapping approach, login naming approach, temporary password handling, cutover checklist, validation approach, and user communication requirements.
Transition a small representative sample where feasible, verify sign-in behavior, confirm group mapping, validate temporary passwords, and adjust the runbook before full execution.
Create, update, or migrate in-scope Entra ID users and groups in the target tenant, apply the agreed temporary password process, and perform the planned identity cutover activities.
Provide agreed assistance and guidance for devices, applications, and services that authenticate through Microsoft Entra ID so owners can complete required reconfiguration.
Validate representative user sign-in, group membership, basic access behavior, and identified Entra ID dependencies. Track and triage transition issues discovered during validation.
Provide final status, known issues, recommended next steps, and administrative handover information for the target tenant.
Prerequisites
Who does what
IT Partner
- Transfer users and groups to the new tenant while preserving logins.
- Set up temporary passwords so users can access the new tenant and set up permanent credentials.
- Provide assistance with reconfiguring devices that use Microsoft Entra ID for authentication.
- Provide help with reconfiguring applications and services tied to Microsoft Entra ID.
- Provide customized migration plans to fit the client’s business size and needs.
- Provide support from planning to execution.
Your team
- Provide timely administrative access or approve delegated access for the source and target tenants.
- Confirm the in-scope users, groups, domains, devices, applications, and services for the basic transition.
- Supply or approve the desired target login format, user mapping, group mapping, and any naming changes.
- Ensure required Microsoft licenses, subscriptions, and third-party licenses are available in the target environment.
- Provide DNS access and approve any custom domain changes if domain movement or verification is required.
- Communicate the migration schedule, expected sign-in changes, and temporary password instructions to end users.
- Coordinate business application owners, device owners, and help desk teams for testing and reconfiguration.
- Participate in pilot testing, validation, and final acceptance of the completed transition.
- Maintain business decisions, approvals, and change-management communications outside the technical migration tasks.
What's not included
Limitations & technical notes
Frequently asked questions
What is the Entra ID Tenant-to-Tenant Basic Transition service?
It moves your Microsoft Entra ID identities — users, groups, and related configuration — from one Microsoft 365 tenant to another as a single coordinated cutover. It is typically used for mergers, acquisitions, restructuring, or migration to a different geographic region, where identities must be established in a new tenant.
Can a Microsoft Entra ID tenant just be moved to another tenant?
No. Microsoft provides no native mechanism to move a tenant or export its identities wholesale. The supported approach — and what this service delivers — is re-provisioning: users and groups are created and mapped in the target tenant, the custom domain is cut over in a planned window, and devices and applications are reconfigured against the new tenant.
What does this tenant-to-tenant transition include?
Migration of in-scope users, groups, and identity configuration to the new Microsoft Entra ID tenant, a customized migration plan, temporary password setup, sign-in and domain cutover planning, and support for reconfiguring devices, applications, and services that authenticate through Microsoft Entra ID.
Will user sign-in names be preserved?
Sign-in names on your custom domain can be preserved, but not simultaneously in both tenants: a domain can be verified in only one Microsoft Entra ID tenant at a time. IT Partner sequences the domain removal from the source tenant and verification in the target during the cutover window; in the interim users may sign in with onmicrosoft.com addresses.
Can users keep their existing passwords after the tenant migration?
No — Microsoft Entra ID passwords cannot be exported, for security reasons. IT Partner sets up temporary passwords so users can sign in to the new tenant and create permanent credentials, and users should also expect to re-register MFA methods in the target tenant.
What happens to devices joined to the old tenant?
Microsoft Entra join and registration cannot be migrated between tenants. Devices joined or registered to the source tenant must be re-joined or re-registered against the target tenant, and re-enrolled in management where Intune is used. This service includes reconfiguration assistance and guidance; large-scale hands-on device rejoin work is scoped separately.
What about Conditional Access, MFA settings, and enterprise applications?
These do not transfer between tenants. Conditional Access policies, authentication methods, directory roles, and application registrations are rebuilt in the target tenant. This service covers the items within the agreed basic scope; a full security-architecture rebuild is scoped separately.
How long does the basic transition take, and what does it cost?
The engagement is priced at $1,300 fixed and runs 5 days, with the identity cutover itself executed as a single coordinated event — commonly scheduled over a weekend to reduce business impact. The price is quoted in writing before work begins.
Is this a full Microsoft 365 tenant migration?
No — this offering covers Microsoft Entra ID identities only. Mailboxes, SharePoint, Teams, and OneDrive move through separate workload migrations, which IT Partner also provides; the identity transition is typically the foundation those migrations build on.
What is the difference between the Basic and Staged transitions?
Basic is a single cutover: all in-scope identities move in one coordinated event, which suits smaller organizations and clean breaks. The Staged Transition runs the two tenants in coexistence and moves users in waves — appropriate when the organization needs phased access to both environments during a longer transition.
What prerequisites are required before starting?
Accessible source and target tenants with appropriate administrative access, an approved list of in-scope users and groups, target-tenant licensing for in-scope users, DNS access and a domain cutover approach where sign-in names move, disclosure of any hybrid identity dependencies (such as Microsoft Entra Connect), identified device and application owners, a user communication plan, and an approved transition window.
What is not included in this basic transition service?
Microsoft 365 workload data migration (Exchange, SharePoint, Teams, OneDrive, Power Platform), large-scale hands-on device rejoin or Intune/Autopilot deployment, complex application remediation or SSO redesign, on-premises Active Directory or Microsoft Entra Connect redesign, Conditional Access architecture redesign, source tenant decommissioning, third-party tool and licensing costs, and password migration — which is technically impossible. Each can be scoped separately where needed.