Entra ID Tenant-to-Tenant Staged Transition — Phased Identity Migration
Entra ID Tenant-to-Tenant Staged Transition moves Microsoft Entra ID identities, resources, and configuration from one tenant to another in phased waves rather than a single cutover — built for mergers, acquisitions, and restructurings where users need working access to both environments during the transition. Coexistence between the tenants is established with Microsoft-documented mechanisms — Microsoft Entra cross-tenant synchronization and B2B collaboration — while users, groups, and permissions move wave by wave, the custom domain cutover is sequenced (a domain can live in only one tenant at a time), and devices and applications are reconfigured against the target tenant. The service is $1,300 + $2 per user over a 20-day engagement.
What this engagement is
This service supports a staged transition from one Microsoft Entra ID tenant to another for organizations that need to consolidate or reorganize identity environments while reducing risk and user disruption. There is no native way to move a tenant, so a staged transition is built from Microsoft-documented parts: identities are provisioned in the target tenant in planned waves; coexistence between the tenants during the transition is established with Microsoft Entra cross-tenant synchronization and B2B collaboration, so users retain working access across both environments while their wave is pending; permissions and group memberships are mapped and rebuilt in the target; the custom domain and UPN cutover is sequenced in a controlled window, because a domain can be verified in only one tenant at a time; and devices and applications tied to Microsoft Entra ID are re-joined or re-registered against the target tenant. Passwords cannot be exported, so each wave's authentication transition is planned explicitly. The phased model keeps application dependencies working and aligns each wave with your security requirements before the next begins.
Success criteria
What you receive
How the work unfolds
Kickoff and scope confirmation — confirm source and target tenants, business drivers, user counts, migration waves, timing constraints, key stakeholders, and success criteria for the staged transition.
Discovery and inventory — review users, groups, administrative roles, domains, identity synchronization dependencies, authentication methods, conditional access policies, enterprise applications, app registrations, and permission dependencies relevant to the transition.
Transition design — define the staged migration approach, identity mapping, naming and UPN strategy, group and permission handling, coexistence requirements, pilot group, cutover windows, validation approach, and rollback or remediation checkpoints.
Target tenant readiness — prepare the target Entra ID tenant configuration needed for the agreed scope, including baseline identity settings, administrative access, security configuration alignment, required domains or domain planning, and migration tooling readiness where applicable.
Pilot stage — migrate or transition a controlled pilot group of users, groups, and permissions; validate sign-in, access, group membership, application access dependencies, and administrative visibility before broader rollout.
Staged migration waves — execute approved migration waves for in-scope users, groups, permissions, and related Entra ID configurations, with progress tracking and issue remediation between waves.
Cutover coordination — coordinate final identity, access, and configuration updates needed for each wave or final transition event, including user communication support and validation checkpoints.
Validation and remediation — verify that migrated identities, groups, and permissions are present and functioning in the target tenant, review exceptions, and remediate issues within the agreed engagement scope.
Knowledge transfer and closeout — provide a summary of completed activities, known exceptions, recommended next steps, and operational handover guidance for the client’s administrators.
Prerequisites
Who does what
IT Partner
- Lead project kickoff, confirm the agreed scope, and document the staged transition approach.
- Perform discovery of in-scope Entra ID identities, groups, permissions, configuration dependencies, and application access dependencies.
- Prepare a migration wave plan and validation checklist for the staged tenant-to-tenant transition.
- Provide technical guidance on identity mapping, UPN and domain planning, group and permission handling, and coexistence considerations.
- Configure in-scope target tenant settings required for the staged transition, subject to approved access and permissions.
- Execute pilot and production migration waves for in-scope users, groups, permissions, resources, and configurations as defined in the service scope.
- Monitor migration progress, identify exceptions, and provide remediation guidance for issues within the agreed service scope.
- Coordinate cutover activities with the client technical team and provide status updates during migration phases.
- Validate migrated objects and access outcomes against the agreed checklist.
- Provide closeout notes, known exceptions, and recommended next steps after completion.
Your team
- Provide timely administrative access, approvals, and tenant permissions required for the engagement.
- Assign a business owner, technical owner, and decision makers who are available during discovery, pilot, cutover, and validation phases.
- Provide accurate source and target tenant information, user lists, group lists, application inventories, privileged account lists, and known dependency documentation.
- Confirm the in-scope population, migration waves, pilot users, success criteria, and acceptable change windows.
- Manage internal business communications to users, help desk teams, application owners, and leadership unless otherwise separately scoped.
- Provide DNS access and domain ownership validation when custom domain or UPN transition work is required.
- Ensure required Microsoft licenses, subscriptions, and third-party tools are available before migration activities begin.
- Coordinate with application owners to validate application access, SSO dependencies, provisioning integrations, and any required application-side changes.
- Test and approve pilot and production wave outcomes, including user sign-in, access, group membership, and critical business workflows.
- Make client-side changes that are outside IT Partner’s authorized access or agreed scope, including endpoint, network, application, or third-party system changes.
- Provide timely feedback on exceptions and approve remediation decisions that may affect user access or security posture.
What's not included
Limitations & technical notes
Frequently asked questions
What is IT Partner's Entra ID Tenant-to-Tenant Staged Transition service?
It moves Microsoft Entra ID identities, resources, and configurations from one tenant to another in phases. It is designed for mergers, acquisitions, divestitures, restructuring, or tenant consolidation scenarios where a lower-risk, wave-based transition is needed and users must keep working access throughout.
What does "staged transition" mean for an Entra ID tenant-to-tenant migration?
The move is performed in planned waves rather than a single all-at-once cutover. Each wave provisions its users in the target tenant, validates sign-in and access, and remediates issues before the next wave starts — which reduces risk and keeps the organization productive during a longer transition.
How can users have access to both tenants during the transition?
Coexistence is established with Microsoft-documented mechanisms: Microsoft Entra cross-tenant synchronization, which provisions and keeps identities updated across tenants, and B2B collaboration for cross-tenant resource access. IT Partner configures the coexistence model appropriate to your wave plan so users retain working access while their wave is pending.
What is included in the staged transition service?
A step-by-step migration plan with wave definitions, phased migration of user identities, in-scope Entra ID resources and configurations, migration of users, groups, and permissions with identity mapping, and coexistence configuration for phased access to both environments during the transition.
How long does the staged transition take, and what does it cost?
The service is priced at $1,300 + $2 per user and runs as a 20-day engagement, quoted fixed-price in writing before work begins. Wave timing within the engagement is set in the transition plan.
Will user passwords move to the new tenant?
No — passwords cannot be exported from Microsoft Entra ID. Each wave's authentication transition is planned explicitly: password reset or temporary credentials, MFA re-registration, and any federation or synchronization arrangements your identity model requires.
What happens to our custom domain and sign-in names?
A custom domain can be verified in only one Microsoft Entra ID tenant at a time, so the domain and UPN cutover is sequenced as a controlled change window within the wave plan. Until the domain moves, target-tenant users may sign in with onmicrosoft.com or another verified domain per the agreed naming strategy.
What happens to devices and applications tied to the old tenant?
Microsoft Entra join does not transfer between tenants: devices are re-joined or re-registered against the target tenant, and applications need new registrations, updated redirect URIs, secrets or certificates, and re-consent. IT Partner provides the dependency mapping and coordinates application-owner actions; large-scale hands-on device work is scoped separately.
Does this service migrate mailboxes, OneDrive, SharePoint, or Teams content?
No — the scope is Microsoft Entra ID identities, groups, permissions, and related configuration. Workload data moves through separate migrations that IT Partner also provides, typically sequenced against the identity waves.
Will there be downtime during the tenant-to-tenant transition?
The staged approach is designed to minimize disruption, and coexistence keeps users working between waves. Zero downtime is not guaranteed: brief access interruptions can occur during domain, sign-in, or application configuration changes, which is why those steps run in agreed change windows.
How does the staged transition handle security and permissions?
Group memberships, permissions, and privileged roles are mapped during discovery and rebuilt in the target tenant within the agreed scope. Conditional Access policies, MFA methods, and access reviews do not transfer between tenants; they are validated or recreated per wave depending on your target-tenant configuration and licensing.
How is this different from the Basic transition?
The Basic transition is a single coordinated cutover within a 5-day engagement — right for smaller organizations and clean breaks. The Staged Transition adds wave planning and cross-tenant coexistence over a 20-day engagement, for organizations that cannot move everyone at once.