Skip to main content

By Errin O'Connor, Founder & Chief AI Architect, EPC Group

16 min readMicrosoft 365 Consulting

Tenant-to-Tenant Migration: The Enterprise Guide for Mergers, Acquisitions & Divestitures

Quick answer

Tenant-to-tenant migration is a phased program: identity prep + directory sync → mailbox migration in batches → SharePoint + OneDrive content → Teams → Intune policy recreation → DNS cutover + domain transfer. For a 10,000-user organization, plan 4–8 months and budget $500K–$1.5M. The critical success factors are coexistence for business continuity, batch scheduling to minimize disruption, and comprehensive testing before domain cutover.

5K–75K
User scale handled
4–14 mo
Typical timeline
$30–$150
Per-user cost range
70%
Triggered by M&A

Microsoft 365 tenant-to-tenant migration moves users, mailboxes, SharePoint sites, Teams, OneDrive, and Intune policies between two Microsoft 365 tenants. It's triggered by mergers and acquisitions (about 70% of cases), divestitures, or rebrand/restructure. For a 10K-user org, plan 4-8 months and budget $500K-$1.5M. The work breaks into six tightly coordinated workstreams: identity merging, Exchange mailbox cutover, SharePoint + OneDrive content migration, Teams reconstruction, Intune policy recreation, and DNS/domain cutover. EPC Group has delivered tenant-to-tenant migrations for 2,000 to 75,000-user organizations across healthcare, financial services, government, and technology. Last updated: 2026-06-17 • Read time: 16 min

Key Facts

  • M&A drives ~70% of tenant-to-tenant migrations; divestitures and rebranding make up the rest.
  • Cost ranges $30–$50 per user (simple), $50–$100 (standard), $100–$150+ (complex w/ Intune + custom apps).
  • A custom domain can only exist in ONE Microsoft 365 tenant at a time — domain transfer is the highest-risk single step.
  • One-to-one Teams chat history cannot be migrated natively. Channel messages + files can.
  • Intune configurations do not transfer between tenants — they must be rebuilt from export.
  • Microsoft offers temporary migration licensing through your account team to cut the 30–90 day overlap cost.

When tenant-to-tenant migration is required

Three scenarios trigger the work. Each has a different organizational driver and a different set of constraints — and each requires a different approach to planning and execution.

Mergers & Acquisitions

~70%
of tenant migrations

Two organizations combine into a single Microsoft 365 tenant for unified identity, consolidated licensing, and seamless collaboration. The acquiring tenant is usually the target. Often constrained by deal timelines and Transitional Service Agreement (TSA) deadlines.

Divestitures & Spin-offs

6–18 mo
typical coexistence window

A business unit is sold and must be cleanly separated from the parent tenant. Requires legal-grade data separation of IP and customer data, plus a long coexistence period governed by the TSA. The parent retains everything that belongs to the continuing entity.

Rebranding & Restructuring

Clean tenant
free of legacy debt

Domain namespace changes significantly, or the organization wants to escape years of legacy configuration, policies, and technical debt. Also triggered when a regulated subsidiary needs independence from a parent company.

The six workstreams

A tenant migration is six coordinated workstreams running on overlapping timelines. Identity is the foundation — every other workload depends on it being right.

Workstream 1

Identity & Entra ID

UPN, proxy address, and group-name conflicts must be resolved before any workload migration starts.

  • Inventory every user, shared mailbox, room/resource, service account, and guest in both directories
  • Map group memberships, custom attributes, conditional-access policies, and app registrations
  • Detect UPN, proxy address, group-name, and attribute conflicts (EPC Group ships a conflict-resolution report in week 2)
  • Configure cross-tenant synchronization for coexistence-period external member access
  • Multi-forest AD: rebuild Azure AD Connect / Cloud Sync with conflict rules, OU filters, and attribute mapping
Workstream 2

Exchange Online Mailboxes

Cross-tenant mailbox migration preserves mail, calendar, contacts, tasks, notes, and folder structure.

  • 8–15 migration batches over 4–8 weeks for a 10K-user org
  • Group by department to keep collaborating teams together
  • Balance batches by mailbox size — 50GB+ users skew throughput
  • VIPs get white-glove migration with same-day validation
  • Shared and resource mailboxes ready in target tenant before user migration
  • Litigation hold and eDiscovery state preserved across the move
Workstream 3

SharePoint + OneDrive

Largest data volume in most migrations. SPMT, ShareGate, and AvePoint each cover different gaps.

  • Inventory site collections, owners, last activity, custom SPFx solutions
  • Recreate managed metadata term stores and content type hubs in target tenant FIRST
  • Redeploy custom SPFx apps and rewrite tenant-specific endpoints
  • Recreate Power Automate workflows and reconnect to migrated content
  • Map source-tenant identities to target-tenant identities for site permissions
  • Maintain external sharing configs and retention labels post-migration
Workstream 4

Microsoft Teams

The most complex workload — Teams is an integration layer over Exchange, SharePoint, and OneDrive.

  • Migrate team structures + channel configs via Microsoft Graph API or third-party tools
  • Channel files ride along with the underlying SharePoint site migration
  • Accept 1:1 and group chat history limitations — archive for compliance, do not promise migration
  • Recreate Teams apps, tabs, and connectors per team in target tenant
  • Migrate Teams Phone: call queues, auto-attendants, calling policies, number assignments
  • Re-establish meeting policies, compliance recording, and guest access policies
Workstream 5

Intune & Endpoint Management

Intune configurations do not transfer between tenants. Everything is rebuilt from export.

  • Device compliance policies
  • Device configuration profiles
  • App protection policies for BYOD
  • Conditional access integrated with Entra ID
  • Windows Autopilot deployment profiles
  • LOB + standard application deployment packages
  • Device re-enrollment is the most disruptive end-user event — sequence after identity + mailbox migrate
Workstream 6

Domain Transfer + DNS Cutover

A custom domain can only exist in one Microsoft 365 tenant at a time. 4–12 hour window.

  • Update every UPN, proxy address, group, and app registration off the source domain first
  • Remove custom domain from source tenant once all references are cleared
  • Add and verify domain in target tenant (DNS TXT record)
  • Update MX, SPF, DKIM, and DMARC for the target tenant
  • Lower DNS TTL to 5 minutes 48 hours before cutover
  • Execute cutover during weekend low-volume window with bidirectional mail forwarding as safety net

Coexistence: keeping the business running

For 2–4 months users live in both tenants. Six coexistence configurations are non-negotiable for any enterprise-scale migration.

Mail flow coexistence

Bidirectional transport rules route mail between tenants regardless of current mailbox location. Updated as each batch completes.

Free/busy coexistence

Organization relationships enable calendar free/busy sharing across the migration boundary — meetings work regardless of host tenant.

Teams federation

Cross-tenant access policies enable Teams chat and meetings between source and target users in real time throughout the migration.

SharePoint access

Cross-tenant sync + B2B guest access keep shared sites and document libraries accessible during the migration period.

Application access

Conditional access policies in both tenants accommodate users authenticating from either tenant without triggering false-positive security alerts.

Global Address List

GAL synchronization keeps users in both tenants findable in the address book — the user-facing experience stays seamless.

Timeline by user scale

Planning numbers from EPC Group's tenant migration engagements. Real durations depend on hybrid Exchange, custom SharePoint, multi-forest AD, and regulatory complexity.

Phase5K Users15K Users50K Users
Discovery & Planning3–4 weeks4–6 weeks6–8 weeks
Identity Preparation2–3 weeks3–4 weeks4–6 weeks
Mailbox Migration3–4 weeks6–8 weeks10–14 weeks
SharePoint / OneDrive3–5 weeks5–8 weeks8–12 weeks
Teams Migration2–3 weeks3–4 weeks4–6 weeks
Intune Re-enrollment2–3 weeks3–4 weeks4–6 weeks
DNS Cutover1 week1–2 weeks2–3 weeks
Post-Migration2–3 weeks3–4 weeks4–6 weeks
Total4–6 months6–9 months9–14 months

The five failure modes — and how to avoid them

Tenant migrations fail for predictable reasons. Each of these is a real incident from the EPC Group portfolio, and each has a mitigation pattern that works.

Failure mode 1

Email disruption during domain cutover

Mitigation: Reduce DNS TTL 48 hours ahead, bidirectional mail forwarding, lowest-volume cutover window, monitor DNS propagation globally before declaring complete.

Failure mode 2

Data loss during SharePoint migration

Mitigation: Pre-migration validation scans comparing source/target inventories, incremental sync to capture in-flight changes, source kept read-only until target validated.

Failure mode 3

Identity conflicts causing auth failures

Mitigation: Comprehensive directory assessment up front, automated conflict detection tooling, staged approach resolving all conflicts in a test batch first.

Failure mode 4

Third-party application breakage

Mitigation: Full app inventory, vendor coordination on tenant-change procedures, pilot-phase connectivity testing, rollback plan for critical applications.

Failure mode 5

User productivity loss from poor communication

Mitigation: Department-specific communication plans, pre-migration training, migration-day cheat sheets, augmented help desk staffing per batch.

Partner with EPC Group for tenant-to-tenant migration

EPC Group has delivered tenant-to-tenant migrations for organizations from 2,000 to 75,000 users — across healthcare, financial services, government, and technology. The methodology is refined from many M&A integrations and divestitures, with documented data-fidelity checklists, pre-cutover reconciliation, and minimal business disruption.

Our Microsoft 365 consulting practice covers pre-acquisition IT due diligence, migration planning and architecture, execution with dedicated migration engineers and 24/7 cutover support, coexistence management, user communication and training, and post-migration optimization with source-tenant decommissioning.

Frequently asked questions

The five questions enterprise IT teams ask before signing the SOW.

How long does a tenant-to-tenant migration take for a 10,000-user organization?
A tenant-to-tenant migration for 10,000 users typically takes 4 to 8 months from planning through completion. This includes 4-6 weeks of discovery and planning, 2-4 weeks of identity and directory preparation, 4-8 weeks of mailbox migration in batches, 4-8 weeks of SharePoint and OneDrive content migration, 2-4 weeks of Teams migration, 1-2 weeks of DNS cutover and domain transfer, and 2-4 weeks of post-migration validation and cleanup. Complexity factors that extend timelines include hybrid Exchange environments, custom SharePoint solutions, Intune device management, compliance holds, and multi-forest Active Directory.
What is the cost of a tenant-to-tenant migration per user?
Tenant-to-tenant migration costs range from $30 to $150 per user depending on complexity. Simple migrations (mailbox and OneDrive only) run $30-$50 per user. Standard migrations (mailbox, OneDrive, SharePoint, Teams) run $50-$100 per user. Complex migrations (full workload migration with Intune, compliance, custom apps) run $100-$150+ per user. A 10,000-user organization should budget between $500,000 and $1.5 million for a comprehensive tenant-to-tenant migration including planning, execution, licensing overlap, third-party tools, and post-migration support. EPC Group provides fixed-price migration engagements with detailed scoping.
Can you migrate Microsoft Teams channels and chat history between tenants?
Microsoft Teams migration between tenants is the most complex workload. Teams channels can be migrated using the Microsoft 365 cross-tenant migration framework or third-party tools like ShareGate and AvePoint. Channel messages and files migrate effectively, but one-to-one chat history cannot be migrated natively and requires third-party solutions with limitations. Teams apps, tabs, and connectors must be recreated in the target tenant. Meeting recordings stored in OneDrive or SharePoint can be migrated as files. EPC Group recommends a phased approach: migrate channels and files first, accept chat history limitations, and implement a coexistence period where users have access to both tenants.
What happens to email during a tenant-to-tenant migration?
Email continuity is maintained throughout the migration through a coexistence configuration. Before migration, mail forwarding rules route email between tenants so users receive messages regardless of which tenant their mailbox currently resides in. During the domain cutover (which takes 24-72 hours for DNS propagation), some email may be delayed but not lost. Microsoft cross-tenant mailbox migration preserves the full mailbox including mail, calendar, contacts, tasks, and folder structure. After migration, the source mailbox is converted to a mail-enabled user that forwards to the target for any straggling messages. Proper planning ensures zero email loss and minimal disruption.
Do you need to relicense users during a tenant-to-tenant migration?
Yes, users require licenses in both the source and target tenant during the migration period, which creates a licensing overlap cost. Microsoft offers temporary licensing for migration scenarios through your Microsoft account team. The overlap period typically lasts 30-90 days depending on migration batch size and schedule. Organizations should negotiate migration licensing with Microsoft before the project starts, as temporary license agreements can significantly reduce overlap costs. EPC Group helps organizations optimize licensing strategy to minimize duplicate costs while maintaining required service availability throughout the migration.
EO

Errin O'Connor

CEO & Chief AI Architect at EPC Group

in enterprise technology consulting since 1997. Microsoft Press bestselling author of four books on large-scale migrations. Has led tenant-to-tenant migrations for organizations up to 75,000 users across healthcare, financial services, government, and technology.

AI assistant — not human