First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Entra ID Tenant-to-Tenant Staged Transition
Migration

Entra ID Tenant-to-Tenant Staged Transition — Phased Identity Migration

Entra ID Tenant-to-Tenant Staged Transition moves Microsoft Entra ID identities, resources, and configuration from one tenant to another in phased waves rather than a single cutover — built for mergers, acquisitions, and restructurings where users need working access to both environments during the transition. Coexistence between the tenants is established with Microsoft-documented mechanisms — Microsoft Entra cross-tenant synchronization and B2B collaboration — while users, groups, and permissions move wave by wave, the custom domain cutover is sequenced (a domain can live in only one tenant at a time), and devices and applications are reconfigured against the target tenant. The service is $1,300 + $2 per user over a 20-day engagement.

Timeline 20 daysService owner Roman SotnikMicrosoft Azure

What this engagement is

This service supports a staged transition from one Microsoft Entra ID tenant to another for organizations that need to consolidate or reorganize identity environments while reducing risk and user disruption. There is no native way to move a tenant, so a staged transition is built from Microsoft-documented parts: identities are provisioned in the target tenant in planned waves; coexistence between the tenants during the transition is established with Microsoft Entra cross-tenant synchronization and B2B collaboration, so users retain working access across both environments while their wave is pending; permissions and group memberships are mapped and rebuilt in the target; the custom domain and UPN cutover is sequenced in a controlled window, because a domain can be verified in only one tenant at a time; and devices and applications tied to Microsoft Entra ID are re-joined or re-registered against the target tenant. Passwords cannot be exported, so each wave's authentication transition is planned explicitly. The phased model keeps application dependencies working and aligns each wave with your security requirements before the next begins.

Success criteria

01A phased migration approach is used to reduce risk and support a smooth transition.
02Phased access to both old and new environments is maintained during the transition — via Microsoft Entra cross-tenant synchronization and B2B collaboration — to help preserve user productivity.
03The transition is planned to minimize business disruption and downtime.
04In-scope users, groups, and permissions are migrated securely and completely, wave by wave, with validation between waves.
05The transition plan is tailored to the organization's needs.

What you receive

A step-by-step migration plan for the staged Entra ID tenant-to-tenant transition, including wave definitions and validation checkpoints.
Phased migration of Entra ID user identities from the source tenant to the target tenant.
Phased migration of in-scope Entra ID-related resources and configurations.
Migration of users, groups, and permissions, with identity mapping between tenants.
Coexistence configuration for phased access to both environments during the transition, using Microsoft Entra cross-tenant synchronization and B2B collaboration where appropriate.

How the work unfolds

Milestone 1

Kickoff and scope confirmation — confirm source and target tenants, business drivers, user counts, migration waves, timing constraints, key stakeholders, and success criteria for the staged transition.

Milestone 2

Discovery and inventory — review users, groups, administrative roles, domains, identity synchronization dependencies, authentication methods, conditional access policies, enterprise applications, app registrations, and permission dependencies relevant to the transition.

Milestone 3

Transition design — define the staged migration approach, identity mapping, naming and UPN strategy, group and permission handling, coexistence requirements, pilot group, cutover windows, validation approach, and rollback or remediation checkpoints.

Milestone 4

Target tenant readiness — prepare the target Entra ID tenant configuration needed for the agreed scope, including baseline identity settings, administrative access, security configuration alignment, required domains or domain planning, and migration tooling readiness where applicable.

Milestone 5

Pilot stage — migrate or transition a controlled pilot group of users, groups, and permissions; validate sign-in, access, group membership, application access dependencies, and administrative visibility before broader rollout.

Milestone 6

Staged migration waves — execute approved migration waves for in-scope users, groups, permissions, and related Entra ID configurations, with progress tracking and issue remediation between waves.

Milestone 7

Cutover coordination — coordinate final identity, access, and configuration updates needed for each wave or final transition event, including user communication support and validation checkpoints.

Milestone 8

Validation and remediation — verify that migrated identities, groups, and permissions are present and functioning in the target tenant, review exceptions, and remediate issues within the agreed engagement scope.

Milestone 9

Knowledge transfer and closeout — provide a summary of completed activities, known exceptions, recommended next steps, and operational handover guidance for the client’s administrators.

Prerequisites

Authorized administrative access to both the source and target Microsoft Entra ID tenants, with roles sufficient to review and configure users, groups, domains, enterprise applications, app registrations, conditional access, and related identity settings within scope.
A designated client project owner and technical contacts who can approve decisions, provide information, validate results, and coordinate business communications.
Confirmed list of in-scope users, groups, permissions, domains, applications, and Entra ID configurations to be transitioned.
Current inventory or access to discover identity objects, group memberships, privileged roles, authentication methods, and application dependencies in the source tenant.
A target tenant that is available, licensed as required, and approved for configuration changes during the engagement.
Required Microsoft licensing for users and features in the target tenant, including any Entra ID, Microsoft 365, security, or governance capabilities needed by the client’s design.
Domain ownership, DNS access, and domain cutover planning where custom domains or UPN changes are part of the transition.
Documented identity synchronization dependencies, such as Microsoft Entra Connect, Microsoft Entra Cloud Sync, hybrid Active Directory, HR provisioning, SCIM provisioning, or third-party identity providers.
Approved pilot users and test accounts for validation before broad migration waves.
Agreed maintenance windows or change windows for activities that may affect authentication, user access, application access, or domain configuration.
Client approval to make configuration changes and to communicate expected user impact during each migration phase.
Recent export, documentation, or backup of critical identity and access configurations where supported by Microsoft tooling or the client’s operational process.

Who does what

IT Partner

  • Lead project kickoff, confirm the agreed scope, and document the staged transition approach.
  • Perform discovery of in-scope Entra ID identities, groups, permissions, configuration dependencies, and application access dependencies.
  • Prepare a migration wave plan and validation checklist for the staged tenant-to-tenant transition.
  • Provide technical guidance on identity mapping, UPN and domain planning, group and permission handling, and coexistence considerations.
  • Configure in-scope target tenant settings required for the staged transition, subject to approved access and permissions.
  • Execute pilot and production migration waves for in-scope users, groups, permissions, resources, and configurations as defined in the service scope.
  • Monitor migration progress, identify exceptions, and provide remediation guidance for issues within the agreed service scope.
  • Coordinate cutover activities with the client technical team and provide status updates during migration phases.
  • Validate migrated objects and access outcomes against the agreed checklist.
  • Provide closeout notes, known exceptions, and recommended next steps after completion.

Your team

  • Provide timely administrative access, approvals, and tenant permissions required for the engagement.
  • Assign a business owner, technical owner, and decision makers who are available during discovery, pilot, cutover, and validation phases.
  • Provide accurate source and target tenant information, user lists, group lists, application inventories, privileged account lists, and known dependency documentation.
  • Confirm the in-scope population, migration waves, pilot users, success criteria, and acceptable change windows.
  • Manage internal business communications to users, help desk teams, application owners, and leadership unless otherwise separately scoped.
  • Provide DNS access and domain ownership validation when custom domain or UPN transition work is required.
  • Ensure required Microsoft licenses, subscriptions, and third-party tools are available before migration activities begin.
  • Coordinate with application owners to validate application access, SSO dependencies, provisioning integrations, and any required application-side changes.
  • Test and approve pilot and production wave outcomes, including user sign-in, access, group membership, and critical business workflows.
  • Make client-side changes that are outside IT Partner’s authorized access or agreed scope, including endpoint, network, application, or third-party system changes.
  • Provide timely feedback on exceptions and approve remediation decisions that may affect user access or security posture.

What's not included

Migration of Exchange Online mailboxes, calendars, contacts, OneDrive, SharePoint, Teams content, Planner, Power Platform data, or other Microsoft 365 workload content unless separately scoped.
Full application migration, application redesign, source-code changes, SAML/OIDC application reengineering, or third-party SaaS reconfiguration beyond identity dependency guidance unless separately scoped.
Azure subscription moves, Azure resource migration, infrastructure migration, or workload modernization outside the agreed Entra ID identity and configuration transition scope.
Endpoint rejoin, device re-enrollment, Intune migration, Autopilot migration, profile migration, or workstation remediation unless separately scoped.
Active Directory domain migration, forest consolidation, server migration, file share migration, or on-premises infrastructure remediation unless separately scoped.
Purchase of Microsoft licenses, third-party migration tools, certificates, domain registrations, or other external services.
Long-term managed services, help desk support, user training, or post-project administration beyond the agreed 20-day engagement unless separately purchased.
Security redesign, zero-trust architecture program, compliance assessment, access governance rollout, privileged access management deployment, or identity governance implementation beyond transition-specific configuration.
Guaranteed zero downtime, guaranteed application compatibility, or remediation of issues caused by unsupported legacy applications or third-party identity integrations.
Legal, compliance, HR, records retention, eDiscovery, or data residency advisory services.

Limitations & technical notes

!Microsoft Entra ID tenant-to-tenant transitions are dependency-sensitive; application behavior, identity synchronization, domain configuration, and conditional access policies must be reviewed before each major phase.
!Object identifiers, service principal identifiers, group identifiers, and application relationships may differ between tenants; applications or scripts that depend on fixed object IDs may require updates by the application owner.
!User passwords are not migrated in plaintext. Password reset, temporary access, federation, synchronization, or other authentication transition methods may be required depending on the client’s identity model.
!A custom domain generally cannot be verified and actively used in two Microsoft Entra ID tenants at the same time, so domain and UPN cutover planning may require a controlled change window.
!Conditional access policies, MFA methods, authentication strength settings, named locations, privileged roles, and access reviews may require validation or recreation in the target tenant depending on tenant configuration and licensing.
!Guest users, external collaboration settings, cross-tenant access settings, B2B relationships, and partner integrations may not transfer one-for-one and may require separate review.
!App secrets, certificates, reply URLs, API permissions, admin consent, SCIM provisioning, and SSO settings may require application-owner action and testing.
!The staged approach is designed to minimize disruption, but it does not guarantee zero downtime or zero user impact; brief access interruptions may occur during cutover, domain, sign-in, or application configuration changes.
!Final scope, timing, and technical approach may vary based on tenant size, application complexity, identity synchronization architecture, security requirements, and Microsoft service limitations at the time of execution.

Frequently asked questions

What is IT Partner's Entra ID Tenant-to-Tenant Staged Transition service?

It moves Microsoft Entra ID identities, resources, and configurations from one tenant to another in phases. It is designed for mergers, acquisitions, divestitures, restructuring, or tenant consolidation scenarios where a lower-risk, wave-based transition is needed and users must keep working access throughout.

What does "staged transition" mean for an Entra ID tenant-to-tenant migration?

The move is performed in planned waves rather than a single all-at-once cutover. Each wave provisions its users in the target tenant, validates sign-in and access, and remediates issues before the next wave starts — which reduces risk and keeps the organization productive during a longer transition.

How can users have access to both tenants during the transition?

Coexistence is established with Microsoft-documented mechanisms: Microsoft Entra cross-tenant synchronization, which provisions and keeps identities updated across tenants, and B2B collaboration for cross-tenant resource access. IT Partner configures the coexistence model appropriate to your wave plan so users retain working access while their wave is pending.

What is included in the staged transition service?

A step-by-step migration plan with wave definitions, phased migration of user identities, in-scope Entra ID resources and configurations, migration of users, groups, and permissions with identity mapping, and coexistence configuration for phased access to both environments during the transition.

How long does the staged transition take, and what does it cost?

The service is priced at $1,300 + $2 per user and runs as a 20-day engagement, quoted fixed-price in writing before work begins. Wave timing within the engagement is set in the transition plan.

Will user passwords move to the new tenant?

No — passwords cannot be exported from Microsoft Entra ID. Each wave's authentication transition is planned explicitly: password reset or temporary credentials, MFA re-registration, and any federation or synchronization arrangements your identity model requires.

What happens to our custom domain and sign-in names?

A custom domain can be verified in only one Microsoft Entra ID tenant at a time, so the domain and UPN cutover is sequenced as a controlled change window within the wave plan. Until the domain moves, target-tenant users may sign in with onmicrosoft.com or another verified domain per the agreed naming strategy.

What happens to devices and applications tied to the old tenant?

Microsoft Entra join does not transfer between tenants: devices are re-joined or re-registered against the target tenant, and applications need new registrations, updated redirect URIs, secrets or certificates, and re-consent. IT Partner provides the dependency mapping and coordinates application-owner actions; large-scale hands-on device work is scoped separately.

Does this service migrate mailboxes, OneDrive, SharePoint, or Teams content?

No — the scope is Microsoft Entra ID identities, groups, permissions, and related configuration. Workload data moves through separate migrations that IT Partner also provides, typically sequenced against the identity waves.

Will there be downtime during the tenant-to-tenant transition?

The staged approach is designed to minimize disruption, and coexistence keeps users working between waves. Zero downtime is not guaranteed: brief access interruptions can occur during domain, sign-in, or application configuration changes, which is why those steps run in agreed change windows.

How does the staged transition handle security and permissions?

Group memberships, permissions, and privileged roles are mapped during discovery and rebuilt in the target tenant within the agreed scope. Conditional Access policies, MFA methods, and access reviews do not transfer between tenants; they are validated or recreated per wave depending on your target-tenant configuration and licensing.

How is this different from the Basic transition?

The Basic transition is a single coordinated cutover within a 5-day engagement — right for smaller organizations and clean breaks. The Staged Transition adds wave planning and cross-tenant coexistence over a 20-day engagement, for organizations that cannot move everyone at once.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1300 + $2 per user
20 days
Book a meeting