Skip to main content

Tenant-to-Tenant Migration Playbook

Microsoft 365 Tenant Migration Control Tower

Run tenant migration as a business cutover program

Tenant-to-tenant migration is not a simple data transfer. It requires coordinated planning across identity, domains, Exchange Online, Teams, SharePoint, OneDrive, security, compliance, communication and hypercare.

IdentityMailDataCutover

Executive Summary​

Tenant-to-tenant migration is not a simple data transfer project.

It requires coordinated planning across identity, domain, mail flow, Teams, SharePoint, OneDrive, security, compliance, user communication and business cutover.

This playbook provides a structured delivery model for Microsoft 365 tenant migration programs.

Executive lens: Tenant migration succeeds when identity, mail, collaboration, security and user communication are treated as one business cutover program rather than separate technical workstreams.


Migration Scope​

Typical tenant-to-tenant migration scope includes:

  • User accounts
  • Mailboxes
  • Shared mailboxes
  • Distribution groups
  • Microsoft Teams
  • SharePoint sites
  • OneDrive data
  • Domains and aliases
  • Security policies
  • Compliance policies
  • User communication and support

Migration Architecture​

Tenant-to-tenant migration architectureSource to target with controlled cutover
01Discovery and assessmentInventory identities, Exchange, Teams, SharePoint, OneDrive, policies and dependencies.
02Migration designMap source to target, define coexistence, tooling, batch plan, DNS and rollback assumptions.
03Pilot and cutoverValidate representative users, perform production cutover and stabilize mail flow and access.
04Validation and hypercareConfirm workloads, permissions, mobile, Outlook, Teams, SharePoint and business process continuity.

Migration Lifecycle​

Migration LifecycleDiscover to controlled closure
01DiscoverScope, dependency, volume, stakeholder and risk discovery.
02AssessIdentity, Exchange, Teams, SharePoint, OneDrive, domains and security.
03DesignMigration strategy, mapping, coexistence, pilot and rollback plan.
04PilotRepresentative users, validation checklist and issue backlog.
05CutoverProduction wave, DNS/mail flow, workload validation and communications.
06HypercareSupport, executive reporting, stabilization and closure evidence.

Phase 1. Discovery​

Objectives​

  • Understand the source tenant environment
  • Identify migration scope
  • Validate business requirements
  • Identify dependencies and risks
  • Define stakeholder and communication model

Discovery Areas​

AreaKey Questions
TenantHow many tenants are involved?
UsersHow many users and mailboxes are in scope?
DomainsWhich domains and aliases are used?
MailAre there hybrid or mail relay dependencies?
TeamsAre Teams, channels and chats in scope?
SharePointHow many sites and how much data?
OneDriveHow many users and how much data?
SecurityAre policies required in target tenant?
ComplianceAre retention, DLP or audit requirements present?

Phase 2. Assessment​

Assessment Checklist​

WorkloadAssessment Item
IdentityUser mapping, guest users, admin roles
ExchangeMailbox size, shared mailboxes, mail flow
TeamsTeams inventory, owners, guests, channels
SharePointSite inventory, permissions, external sharing
OneDriveStorage size, sharing links, ownership
DomainMX, SPF, DKIM, DMARC, aliases
SecurityCA, Defender, DLP, labels
OperationsHelp desk, escalation, communication

Phase 3. Migration Design​

Design Components​

  • Migration strategy
  • Identity mapping
  • Domain strategy
  • Mail flow strategy
  • Coexistence strategy
  • Data migration sequence
  • Pilot scope
  • Cutover plan
  • Rollback plan
  • Hypercare model
OutputDescription
Migration ArchitectureSource and target tenant design
User MappingSource to target identity mapping
Domain PlanDomain release and verification plan
Cutover RunbookStep-by-step cutover procedure
Rollback PlanRecovery and fallback approach
Communication PlanUser and executive communication

Identity Migration​

Key Considerations​

  • Source user principal name
  • Target user principal name
  • Immutable ID dependencies
  • Guest users
  • Admin accounts
  • MFA state
  • Conditional Access
  • Licensing assignment
AreaRecommendation
User MappingFreeze mapping before pilot
Admin AccountsSeparate admin accounts from user migration
MFARevalidate after target tenant sign-in
Guest UsersReinvite or recreate where needed
LicensingAssign before workload validation

Domain Migration​

Key Considerations​

  • Domain removal from source tenant
  • Domain verification in target tenant
  • MX record update
  • Autodiscover
  • SPF, DKIM, DMARC
  • Alias continuity
  • SMTP relay dependencies

Domain Cutover Sequence​

Domain cutover sequenceLower risk before DNS changes
01Prepare source tenantRemove domain dependencies, aliases, mail flow blockers and workload references.
02Prepare DNSLower TTL and confirm MX, SPF, DKIM, DMARC, Autodiscover and relay dependencies.
03Verify target tenantAdd and verify the domain in the target tenant, then activate target mail routing.
04User validationConfirm sign-in, Outlook, mobile access, internal and external mail flow after cutover.

Exchange Online Migration​

Scope Items​

  • User mailboxes
  • Shared mailboxes
  • Resource mailboxes
  • Distribution groups
  • Mail contacts
  • Mail flow rules
  • SMTP relay
  • Mobile access
  • Outlook profile impact

Validation Checklist​

ItemValidation
Mailbox AccessUser can access mailbox
Mail FlowInternal and external mail flow works
CalendarCalendar data visible
Shared MailboxDelegation works
MobileMobile profile reconfigured
OutlookOutlook profile recreated or reconnected

Teams Migration​

Scope Items​

  • Teams
  • Channels
  • Membership
  • Owners
  • Guest users
  • Files
  • Tabs and apps
  • Meeting policies

Key Risks​

RiskMitigation
Chat history limitationsConfirm migration tool capability
Private channel complexityValidate during pilot
Guest user mismatchReinvite or remap guests
App and tab limitationsDocument unsupported items

SharePoint Migration​

Scope Items​

  • Site collections
  • Libraries
  • Lists
  • Permissions
  • Metadata
  • Sharing links
  • Version history
  • Retention requirements

Validation Checklist​

ItemValidation
Site AccessOwners and members can access
PermissionsPermission model is preserved
FilesFiles and folders migrated
MetadataMetadata preserved where required
SharingExternal sharing reviewed
SearchContent searchable after indexing

OneDrive Migration​

Scope Items​

  • User OneDrive data
  • Folder structure
  • Sharing links
  • Ownership
  • Deleted user data
  • Large file constraints

Validation Checklist​

ItemValidation
User AccessUser can access OneDrive
Data CountFile and folder count validated
SharingSharing links reviewed
SyncOneDrive sync works
OwnershipOwnership mapped correctly

Security and Compliance Migration​

Assessment Areas​

  • Conditional Access
  • MFA
  • Defender policies
  • DLP policies
  • Sensitivity labels
  • Retention policies
  • Audit settings
  • eDiscovery requirements

Recommendation​

Security and compliance policies should not be blindly copied.

They should be reviewed, rationalized and redesigned for the target tenant operating model.


Pilot Migration​

Pilot Objectives​

  • Validate migration tools
  • Test cutover process
  • Identify user impact
  • Confirm support readiness
  • Validate rollback assumptions
User GroupPurpose
IT UsersTechnical validation
Business ChampionsBusiness process validation
Executive AssistantExecutive calendar and mailbox validation
Security TeamPolicy and access validation

Production Cutover​

Cutover Preparation​

  • Final user mapping confirmed
  • Communication sent
  • Migration tool ready
  • DNS access confirmed
  • Support team staffed
  • Rollback plan approved
  • Executive contacts identified

Cutover Activities​

StepActivity
1Stop source changes
2Final delta migration
3Domain removal from source
4Domain verification in target
5DNS update
6Mail flow validation
7User access validation
8Executive confirmation

Hypercare​

Hypercare Scope​

  • Mailbox access issues
  • Outlook profile issues
  • Mobile access issues
  • Teams access issues
  • SharePoint permission issues
  • OneDrive sync issues
  • External sharing issues
  • Executive support

Hypercare Reporting​

ReportFrequency
Issue SummaryDaily
Executive StatusDaily or as required
Risk RegisterDaily
User Impact ReportDaily
Closure ReportEnd of hypercare

Risk Register​

IDRiskImpactMitigation
R-001Domain release delayMail cutover delayPre-check domain dependencies
R-002User mapping mismatchAccess failureFreeze mapping before pilot
R-003Teams migration limitationUser experience impactValidate tool capability
R-004Permission mismatchData access issuePilot and permission review
R-005Executive disruptionBusiness escalationDedicated executive migration wave
R-006DNS update issueMail flow impactLower TTL and prepare rollback

Communication Plan​

Communication Audiences​

  • Executive sponsors
  • IT administrators
  • End users
  • Help desk
  • Security and compliance teams
  • External partners

Communication Timeline​

TimingCommunication
T-4 weeksProject announcement
T-2 weeksMigration preparation guide
T-1 weekUser impact notice
T-1 dayFinal reminder
Cutover daySupport channel notice
T+1 dayKnown issue and support guide

Deliverables​

Tenant migration projects should produce:

  • Discovery Report
  • Migration Assessment
  • User Mapping
  • Domain Migration Plan
  • Workload Migration Plan
  • Cutover Runbook
  • Rollback Plan
  • Communication Plan
  • Hypercare Report
  • Final Closure Report

Success Criteria​

The migration is considered successful when:

  • Target tenant sign-in works
  • Mail flow is operational
  • Required data is migrated
  • Executive users are validated
  • Critical business workloads are operational
  • Hypercare issues are within acceptable threshold
  • Customer accepts migration closure

Advanced Tenant Consolidation Considerations​

Mail Coexistence with Legacy Mail Systems​

Tenant consolidation may require mail coexistence when the headquarters and regional entities use different mail platforms.

Typical scenarios include:

  • Legacy mail platform and Exchange Online coexistence
  • Multiple Microsoft 365 tenants
  • Shared SMTP domain
  • Regional mail domain transition
  • Staged mailbox migration
AreaRecommendation
Primary SMTPPreserve user-facing address where possible
Alternate SMTPUse routing address for coexistence
Mail ContactsRepresent users from the other system
ForwardingConfigure temporary forwarding where required
Mail FlowValidate both inbound and outbound routing
CutoverPrepare rollback and validation checklist

Shared Domain and Subdomain Routing​

When the same email domain must be shared or transitioned between environments, routing design must be completed before migration.

Recommended options:

OptionUse Case
Subdomain routingLong-term coexistence or phased transition
Alternate address routingUser-level coexistence
Mail contact routingRepresent non-migrated users
Full domain cutoverFinal consolidation into target tenant

Domain Transfer Impact​

Moving a domain from one tenant to another can affect:

  • User sign-in
  • Mail reception
  • Teams identity
  • Guest access
  • External collaboration
  • Mobile mail profile
  • Outlook profile

Required Controls​

  • Lower DNS TTL before cutover
  • Freeze proxy address changes
  • Validate all aliases
  • Prepare domain removal checklist
  • Prepare target tenant verification
  • Validate MX, SPF, DKIM and DMARC
  • Communicate user sign-in impact
  • Prepare rollback plan

Purview and Sensitivity Label Migration​

If documents are protected by Microsoft Purview Information Protection, migration requires additional planning.

Key considerations:

AreaConsideration
Sensitivity LabelsSource tenant labels may not directly map to target tenant labels
EncryptionEncrypted files may require decryption or relabeling
DLPTarget tenant DLP policies must be reviewed
RetentionRetention policies may need redesign
Access ValidationSample protected documents must be tested after migration
  1. Inventory sensitivity labels and protected files.
  2. Identify encrypted or restricted documents.
  3. Define source-to-target label mapping.
  4. Validate sample migration.
  5. Reapply target tenant labels where required.
  6. Confirm user access after migration.

Regional Policy Separation in a Single Tenant​

A single Microsoft 365 tenant can still support different policies by region or business unit.

The recommended design is group-based policy assignment, not domain-based policy assignment.

Policy AreaRecommended Scope
Conditional AccessUser or security group
IntuneUser group or device group
DefenderUser, device or policy group
DLPUser, group or workload scope
Sensitivity LabelsLabel policy assignment
SharePoint Download RestrictionConditional Access group exception

Administrative Units for Regional Delegation​

Microsoft Entra Administrative Units can provide limited regional administration.

Use cases:

  • Regional password reset
  • Regional user management
  • Help desk delegation
  • Limited device administration

Important limitation:

Administrative Units do not provide full tenant-level separation. They should be used for scoped delegation, not as a replacement for tenant isolation.


Download Restriction and SharePoint Limited Access​

Download restrictions can be implemented using Conditional Access and SharePoint limited access controls.

Example model:

User TypeAccess Model
Guest userBrowser-only access
Internal employeeDownload allowed based on policy
Regional employeeGroup-based exception
Unmanaged deviceBrowser-only or download blocked
Privileged userDownload and offline access allowed

Tenant Consolidation Readiness Checklist​

Before executing tenant consolidation, validate:

  • Domain ownership
  • DNS control
  • SMTP proxy addresses
  • Mail coexistence routing
  • User identity mapping
  • Guest access impact
  • Teams collaboration impact
  • Purview label and encryption impact
  • Conditional Access policy scope
  • Regional policy exceptions
  • Administrative Unit requirements
  • User communication plan
  • Hypercare support model

References​

  • Microsoft Learn
  • Microsoft Exchange Online Migration Guidance
  • Microsoft SharePoint Migration Guidance
  • Microsoft Teams Migration Considerations
  • Microsoft Entra Documentation

Global Tenant Consolidation Considerations​

Mail Coexistence Strategy​

테넌트 통합 프로젝트에서는 데이터 마이그레이션보다 메일 공존(Coexistence) 설계가 선행되어야 한다.

특히 아래와 같은 환경에서는 메일 흐름 설계가 필수적이다.

  • Notes + Exchange Online
  • Google Workspace + Exchange Online
  • Multiple Exchange Online Tenants
  • Shared SMTP Domain Environment

Key Design Principles​

  • Primary SMTP 유지
  • Alternate SMTP 설계
  • Mail Forwarding 구성
  • Mail Contact 활용
  • Mail Routing 검증

Shared Domain Migration​

동일 SMTP Domain을 사용하는 경우 다음 절차를 수행한다.

Current State​

Tenant A

user@company.com

Target State​

Tenant B

user@company.com

Migration Procedure​

  1. Source Tenant Domain 제거
  2. Target Tenant Domain 추가
  3. User SMTP Reassignment
  4. Mail Flow Validation
  5. Teams Federation Validation

Risks​

  • Mail Delivery Failure
  • Teams Chat Failure
  • Guest Access Loss
  • Login UPN Change

Teams Identity Impact​

Tenant Consolidation 이후

다음 데이터는 자동 유지되지 않는다.

User Impact​

  • Teams Chat History
  • Teams Membership
  • Private Channel Membership
  • Shared Channel Membership
  • Guest Invitations

Recommendation​

Cross Tenant Sync를 우선 검토하고

Full Migration은 Business Requirement 검증 후 수행한다.


Sensitivity Label Migration​

Microsoft Purview Information Protection 적용 환경에서는

문서 마이그레이션 이전에 정책 검토가 필요하다.

Considerations​

  • Label Mapping
  • Encryption Removal
  • Rights Migration
  • Label Reassignment

Risk​

암호화된 문서는 단순 Migration Tool로 이동 불가

별도 검증 필요


Regional Security Policy​

Single Tenant에서도 국가별 정책 분리가 가능하다.

Supported Controls​

  • Conditional Access
  • Intune Policy
  • DLP
  • Sensitivity Labels
  • Defender Policies
  • SharePoint Access Control

Design Principle​

정책은 Domain 기반이 아닌

Group 기반으로 설계한다.


Administrative Units​

글로벌 운영 조직의 경우

Administrative Units를 사용하여

지역별 관리자 권한을 분리한다.

Example​

Korea Admin

  • Password Reset
  • User Management

Myanmar Admin

  • Password Reset
  • Device Management

HQ Admin

  • Global Administrator

Download Restriction Model​

Conditional Access 기반

SharePoint Limited Access 정책을 활용한다.

Typical Scenario​

Guest User

  • Browser Only

Employee

  • Download Allowed

Privileged User

  • Download Allowed
  • Offline Access Allowed

Regional User

  • Group Based Exception

Migration Readiness Checklist​

Before Migration

  • Domain Ownership Review
  • SMTP Routing Validation
  • Mail Coexistence Design
  • Teams Impact Assessment
  • Guest Access Assessment
  • Sensitivity Label Review
  • Conditional Access Review
  • Administrative Unit Design
  • Data Migration Validation
  • User Communication Plan

검색 키워드​

  • Microsoft 365 playbook
  • Copilot readiness playbook
  • security modernization playbook
  • tenant migration playbook
  • change management playbook
  • Microsoft 365 구축 방법론
  • Copilot 도입 방법론

Contact / Asset Request​

For editable playbooks, delivery checklists, workshop agendas, risk registers or handover templates, use Contact and Asset Request.