First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Entra ID Tenant-to-Tenant Basic Transition
Migration

Microsoft Entra ID Tenant-to-Tenant Basic Transition — Microsoft 365 Tenant Migration

Entra ID Tenant-to-Tenant Basic Transition is a Microsoft Entra ID migration service for moving users, groups, and resources from one Microsoft 365 tenant to another, typically for mergers, acquisitions, restructuring, or migration to a different geographic region. Source service details: SKU ITPWW420MIGOT, price 1300, duration 5, manager Roman Sotnik.

Timeline 5 daysService owner Roman SotnikMicrosoft Azure

What this engagement is

This service helps transition Microsoft Entra ID, formerly Azure AD, from one Microsoft 365 tenant to another. IT Partner supports the migration of users, groups, and resources to the new tenant, provides temporary password setup because passwords cannot be exported, and assists with device and application reconfiguration tied to Microsoft Entra ID. This is a Microsoft Azure migration service.

Success criteria

01Target Microsoft Entra ID tenant is prepared for the agreed basic identity transition scope.
02In-scope users and groups are created, mapped, or transitioned in the target tenant according to the approved migration plan.
03Temporary password process is configured and validated for in-scope users because source passwords cannot be exported.
04A pilot or validation sample confirms that migrated users can sign in to the target tenant using the agreed login format and temporary password process.
05In-scope group membership and basic identity attributes are validated against the agreed migration inventory.
06Device and application reconfiguration guidance is provided for the identified Entra ID-dependent devices, applications, and services.
07Client administrator receives handover notes, known issues, and any recommended next steps after the transition.
08The engagement is considered complete when the agreed basic transition checklist is completed and accepted by the client.

What you receive

Migration of users, groups, and resources to a new Microsoft Entra ID tenant.
User and group migration to the new tenant while preserving logins.
Temporary passwords for users to access the new tenant and set up permanent credentials.
Support for reconfiguring devices that use Microsoft Entra ID for authentication.
Guidance for reconfiguring applications and services tied to Microsoft Entra ID.
Customized migration plan to fit business size and needs.

How the work unfolds

Kickoff and scope confirmation

Confirm business drivers, source and target tenants, expected user and group scope, migration constraints, cutover preferences, success criteria, and key stakeholders.

Tenant and identity discovery

Review the source tenant identity inventory, including users, groups, domains, sign-in names, role assignments, device dependencies, and applications or services tied to Microsoft Entra ID.

Target tenant readiness

Validate target tenant access, administrative permissions, licensing assumptions, domain readiness, baseline Entra ID settings, and any policies that could affect user sign-in.

Migration design and mapping

Prepare the user and group mapping approach, login naming approach, temporary password handling, cutover checklist, validation approach, and user communication requirements.

Pilot or sample validation

Transition a small representative sample where feasible, verify sign-in behavior, confirm group mapping, validate temporary passwords, and adjust the runbook before full execution.

Basic transition execution

Create, update, or migrate in-scope Entra ID users and groups in the target tenant, apply the agreed temporary password process, and perform the planned identity cutover activities.

Device and application reconfiguration support

Provide agreed assistance and guidance for devices, applications, and services that authenticate through Microsoft Entra ID so owners can complete required reconfiguration.

Post-transition validation

Validate representative user sign-in, group membership, basic access behavior, and identified Entra ID dependencies. Track and triage transition issues discovered during validation.

Handover and closure

Provide final status, known issues, recommended next steps, and administrative handover information for the target tenant.

Prerequisites

Source and target Microsoft 365 tenants are available and accessible before kickoff.
Client provides appropriate administrative access or delegated access to both source and target tenants, typically Global Administrator, Privileged Role Administrator, or other roles required for the agreed tasks.
Client provides an approved list of in-scope users, groups, required login names, and any users or groups that must be excluded.
Target tenant licensing is available for in-scope users where licensing is required for the target-state services.
Custom domain ownership, DNS administration access, and domain release or verification approach are available if sign-in names or domains must be moved between tenants.
Client identifies device owners, application owners, and service owners for systems that use Microsoft Entra ID authentication.
Existing Conditional Access, MFA, security defaults, identity protection, and authentication method requirements are reviewed for impact on first sign-in and temporary passwords.
Any hybrid identity dependencies, such as on-premises Active Directory or Microsoft Entra Connect, are disclosed before planning the transition.
A user communication plan is available, including timing, login instructions, temporary password distribution approach, and support escalation contacts.
Client approves a transition window and understands that sign-in changes may require user action.

Who does what

IT Partner

  • Transfer users and groups to the new tenant while preserving logins.
  • Set up temporary passwords so users can access the new tenant and set up permanent credentials.
  • Provide assistance with reconfiguring devices that use Microsoft Entra ID for authentication.
  • Provide help with reconfiguring applications and services tied to Microsoft Entra ID.
  • Provide customized migration plans to fit the client’s business size and needs.
  • Provide support from planning to execution.

Your team

  • Provide timely administrative access or approve delegated access for the source and target tenants.
  • Confirm the in-scope users, groups, domains, devices, applications, and services for the basic transition.
  • Supply or approve the desired target login format, user mapping, group mapping, and any naming changes.
  • Ensure required Microsoft licenses, subscriptions, and third-party licenses are available in the target environment.
  • Provide DNS access and approve any custom domain changes if domain movement or verification is required.
  • Communicate the migration schedule, expected sign-in changes, and temporary password instructions to end users.
  • Coordinate business application owners, device owners, and help desk teams for testing and reconfiguration.
  • Participate in pilot testing, validation, and final acceptance of the completed transition.
  • Maintain business decisions, approvals, and change-management communications outside the technical migration tasks.

What's not included

Full Microsoft 365 workload migration, including Exchange mailboxes, SharePoint sites, Teams content, OneDrive data, Planner, Forms, Power Platform, or other service data, unless separately scoped.
Large-scale hands-on device rejoin, workstation rebuild, Intune enrollment, Autopilot deployment, or endpoint profile migration unless separately scoped.
Complex application remediation, custom application code changes, SAML/OIDC redesign, third-party vendor configuration, or full SSO modernization unless separately scoped.
On-premises Active Directory redesign, domain consolidation, forest migration, or Microsoft Entra Connect redesign unless separately scoped.
Advanced security architecture redesign, Conditional Access policy redesign, Identity Protection tuning, privileged access program design, or compliance policy implementation unless separately scoped.
Source tenant decommissioning, license cancellation, archival, legal hold, eDiscovery, or data-retention work unless separately scoped.
End-user training sessions, onsite floor-walking, extended hypercare, or after-hours support unless included in the agreed statement of work.
Third-party migration tools, Microsoft licensing costs, DNS provider fees, application vendor fees, or other external charges.
Migration of existing user passwords, because passwords cannot be exported from Microsoft Entra ID.

Limitations & technical notes

!Passwords cannot be exported due to security restrictions.
!Users receive temporary passwords to access the new tenant and set up permanent credentials.
!Login preservation depends on domain availability, source tenant domain release timing, target tenant verification, and the agreed user principal name strategy.
!Custom domain changes can be affected by DNS propagation, existing tenant bindings, and Microsoft service dependencies.
!Users should expect sign-in changes and may need to re-authenticate, update credentials, reconfigure profiles, or complete MFA registration in the target tenant.
!Devices joined to or registered with the source tenant may require rejoin, re-registration, or management re-enrollment depending on the current configuration.
!Applications using Microsoft Entra ID authentication may require new app registrations, redirect URI updates, certificate or secret updates, consent changes, or vendor-side configuration.
!Conditional Access, MFA, authentication methods, directory roles, enterprise applications, and audit history are not automatically identical between tenants unless specifically configured or migrated within scope.
!Hybrid identity environments can introduce dependencies on on-premises Active Directory, synchronization rules, source anchors, and Microsoft Entra Connect configuration.
!The source record lists duration as "5"; the delivery calendar, unit, cutover window, and any after-hours requirements should be confirmed during scheduling.

Frequently asked questions

What is the Entra ID Tenant-to-Tenant Basic Transition service?

Entra ID Tenant-to-Tenant Basic Transition is a Microsoft Entra ID migration service for moving users, groups, and resources from one Microsoft 365 tenant to another. It is typically used for mergers, acquisitions, restructuring, or migration to a different geographic region, because those scenarios often require identities and related Entra ID configuration to be established in a new tenant.

What does this tenant-to-tenant transition include?

The service includes migration of users, groups, and resources to a new Microsoft Entra ID tenant, plus temporary password setup for users. IT Partner also provides support for reconfiguring devices that use Microsoft Entra ID for authentication and guidance for applications and services tied to Microsoft Entra ID.

Does this service migrate Microsoft Entra ID or Azure AD?

Yes, this service transitions Microsoft Entra ID, formerly called Azure Active Directory or Azure AD, from one Microsoft 365 tenant to another. The scope is identity-focused, because the stated deliverables are users, groups, resources, temporary passwords, and Entra ID-related device and application reconfiguration support.

Will user logins be preserved during the migration?

The stated scope includes user and group migration to the new tenant while preserving logins. The exact handling of domains, usernames, and sign-in formats should be confirmed during planning, because tenant-to-tenant identity behavior can depend on the source and target tenant configuration.

Can users keep their existing passwords after the tenant migration?

No, existing passwords cannot be exported due to security restrictions. IT Partner sets up temporary passwords so users can access the new tenant and then create permanent credentials.

What happens to user passwords during the transition?

Users receive temporary passwords in the new tenant because Microsoft Entra ID passwords cannot be exported from the source tenant. After first access, users set up permanent credentials in the new tenant according to the migration approach agreed with IT Partner.

Does the service include group migration?

Yes, group migration is included as part of the stated deliverables. IT Partner transfers users and groups to the new Microsoft Entra ID tenant as part of the basic tenant-to-tenant transition.

Does this service include device reconfiguration?

The service includes assistance with reconfiguring devices that use Microsoft Entra ID for authentication. The exact amount of hands-on device work, device count, and any endpoint management changes should be confirmed with IT Partner before the engagement, because the provided scope describes assistance rather than a detailed device deployment plan.

Does this service include application and service reconfiguration?

The service includes guidance and help for reconfiguring applications and services tied to Microsoft Entra ID. It does not list every supported application type or integration scenario, so application-specific requirements should be reviewed with IT Partner during planning.

Is this a full Microsoft 365 tenant migration service?

This offering is specifically for Microsoft Entra ID tenant-to-tenant basic transition, not a fully defined migration of every Microsoft 365 workload. The stated scope covers identities, groups, resources, temporary passwords, and Entra ID-related device and application guidance, so mailboxes, SharePoint, Teams, OneDrive, or other workload migrations should be confirmed separately if required.

How long does the Entra ID Tenant-to-Tenant Basic Transition take?

The source service record lists the duration as 5, but it does not specify the unit. Prospective buyers should confirm with IT Partner whether that means hours, days, or another delivery unit before scheduling the migration.

How much does the service cost?

The listed price for Entra ID Tenant-to-Tenant Basic Transition is 1300 for SKU ITPWW420MIGOT. The currency, taxes, and whether any additional work is billable are not specified in the provided service details, so buyers should confirm the final commercial terms with IT Partner.

What happens during the engagement?

IT Partner provides support from planning to execution, including a customized migration plan based on business size and needs. The engagement covers transferring users and groups, setting up temporary passwords, and assisting with Entra ID-related device, application, and service reconfiguration.

What prerequisites are required before starting the transition?

The provided service details do not list prerequisites such as required tenant access, licensing, identity configuration, domain readiness, or administrative permissions. These items should be confirmed with IT Partner before kickoff, because tenant-to-tenant identity transitions usually depend on the current and target tenant environments.

What is IT Partner responsible for in this service?

IT Partner is responsible for transferring users and groups to the new tenant while preserving logins, setting up temporary passwords, and supporting reconfiguration of devices, applications, and services tied to Microsoft Entra ID. IT Partner also provides a customized migration plan and support from planning through execution.

What is the client responsible for?

The provided service content does not list formal client responsibilities. Buyers should confirm required client tasks with IT Partner, such as providing tenant access, approving the migration plan, communicating with users, or coordinating application and device owners, because those responsibilities are not defined in the source scope.

Will there be downtime or user disruption during the migration?

The provided service details do not specify expected downtime or a guaranteed no-downtime migration. Users should expect at least a sign-in change because they receive temporary passwords for the new tenant, and the detailed business impact should be reviewed with IT Partner during planning.

What happens after the transition is completed?

After the transition, users access the new Microsoft Entra ID tenant using temporary passwords and then set up permanent credentials. Devices, applications, and services tied to Microsoft Entra ID may also need reconfiguration support or validation based on the migration plan.

What is not included in this basic transition service?

The provided service details do not include a written exclusions list. The only explicit limitation is that passwords cannot be exported, so any work outside the stated scope—such as specific Microsoft 365 workload migration, advanced application remediation, or large-scale device deployment—should be confirmed with IT Partner before purchase.

Who manages this service at IT Partner?

The service record lists Roman Sotnik as the manager for Entra ID Tenant-to-Tenant Basic Transition. Buyers can reference SKU ITPWW420MIGOT when discussing scope, pricing, timing, and readiness with IT Partner.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,300
5 days
Book a meeting