MICROSOFT 365 MIGRATION

Microsoft 365 tenant-to-tenant migration, planned and cut over properly.

Moving mailboxes, OneDrive, domains and devices from one Microsoft 365 tenant to another, or merging several tenants into one after a rebrand or an acquisition. Done hands-on by the consultant who has moved three organisations between tenants this year, with a cutover runbook and hypercare after go-live.

3 Organisations moved between Microsoft 365 tenants this year, including a cross-tenant migration for a hotel property group.
4 Device platforms enrolled into Intune in the target tenant: Windows, macOS, iOS and Android.
20+ Years across Microsoft 365, Azure, Entra ID and IT security. One consultant, no helpdesk queue, no vendor reselling.

Not every project needs a migration. If one site or business unit simply needs to run its own users and devices, administrative segregation inside the shared tenant is often the better answer.

WHAT'S INCLUDED

What a migration
covers.

06 — parts
01 — MAILBOXES & ONEDRIVE

Mailbox and OneDrive migration

Tenant-to-tenant and cross-tenant mailbox and OneDrive moves, run as MigrationWiz projects. Data is pre-staged ahead of time, so cutover moves only what has changed.

  • User and shared mailboxes mapped source to target before anything moves
  • OneDrive sized up front, because large OneDrives set the timetable
  • A pre-stage pass, delta syncs, then a final pass at cutover
02 — CONSOLIDATION

Merging several tenants into one

After a rebrand or an acquisition, two or three tenants become one: one directory, one set of policies and one licence position to reconcile.

  • Target tenant readied first: licences, Conditional Access, naming
  • Address and username clashes resolved before migration, not during it
03 — SEGREGATION

Administrative segregation, not a split

The alternative to splitting. A business unit manages its own users, mailboxes and devices inside a shared tenant, with no rights over anyone else.

  • Entra Administrative Units with scoped admin roles
  • Exchange Online RBAC management scopes
  • Intune RBAC with scope tags for devices and policies
04 — DOMAINS & MAIL FLOW

DNS and domain cutover

A domain can only be verified in one tenant at a time, so the move is sequenced, timed and written down beforehand.

  • MX and Autodiscover switched to the target tenant
  • SPF, DKIM and DMARC re-established so mail still authenticates
05 — FILES

File shares to SharePoint

File servers and old shares moved into SharePoint with a structure and permissions that make sense.

  • Permissions reviewed before the move, which matters if Copilot is next
  • Sites and libraries mapped to how teams actually work
06 — DEVICES

Re-enrolment with Intune and Autopilot

Devices tied to the old tenant are brought into the new one, so they land managed and compliant, not orphaned.

  • Windows Autopilot registration and enrolment in the target tenant
  • macOS, iOS and Android enrolled alongside Windows
  • Security baselines, BitLocker and compliance policies applied on arrival
WHAT GOES WRONG

Four things that derail a tenant migration.

OneDrive sizing. Mailboxes rarely set the timetable; a handful of very large OneDrives do. Guest accounts. People who already exist in the target tenant as guests collide with the accounts being created for them. Licence mismatches. The target needs the right licence assigned before there is a mailbox or OneDrive to migrate into. Service accounts. The migration account is blocked by a forgotten Conditional Access policy.

Each of these is found in discovery, not on cutover night.

Migration is one part of our wider infrastructure and security work. The hotel group example is written up in the case studies. If the new tenant has to pass an assessment, see Cyber Essentials readiness; if the network is changing at the same time, see network security and Fortinet.

HOW AN ENGAGEMENT RUNS 04 — steps
01

Discover

Mailboxes, OneDrive sizes, domains, devices, guests, licences and service accounts inventoried. Then the decision: migrate, consolidate or segregate.

02

Pre-stage

The target tenant is built and licensed, MigrationWiz projects are set up, and the bulk of the data is copied while people carry on working in the source.

03

Cut over

A written runbook with timings, owners and a rollback point: final delta sync, domain moved, DNS switched, devices re-enrolled.

04

Hypercare

On hand after go-live for profiles, permissions and stragglers, with a handover document and a user guide.

FAQ

Tenant migration
questions.

04 — questions
It depends on the number of mailboxes, the data in OneDrive and file shares, the devices to re-enrol and the domains moving. Most of the elapsed time is pre-staging, which runs in the background while people carry on working. The cutover itself is planned for an evening or a weekend. You get a dated plan after discovery, once the real numbers are known.
No mail should be lost. Mailboxes are pre-staged and delta-synced, so the target is nearly complete before cutover. A domain can only sit in one tenant at a time, so there is a short out-of-hours window while it is moved and DNS is updated. Mail sent in that window is normally queued by the sending server and delivered once the new records are live.
Often you can segregate. If one business unit or site needs to manage its own users, mailboxes and devices without rights over the rest, Entra Administrative Units, Exchange Online RBAC scopes and Intune scope tags deliver that inside the shared tenant. A split is right when the organisations are genuinely separating and need their own domains, data and licensing.
Four things: the number of mailboxes, the volume of data in mailboxes, OneDrive and file shares, the number of devices to re-enrol, and the number of domains to move. Shared mailboxes, guest accounts and tight cutover windows add work. You get a written scope and a price after discovery.

Further reading — Related guides: Microsoft 365 tenant-to-tenant migration: a practical guide and delegating admin safely in a shared tenant.

Planning a tenant move?

Book a free discovery call. Bring the mailbox count, the domains and your target date. You will get a straight view of whether to migrate, consolidate or segregate — no obligation.