Consolidation merges tenants into one. A divestiture carve-out extracts a business unit out of a tenant against a deal deadline, with contractual data-segregation obligations and a Transition Services Agreement clock. EPC Group treats them as different projects, because the risk, the evidence burden and the sequence are different.
Last updated: 2026-07-31
EPC Group is a Houston-based Microsoft consulting firm operating since 1997, with six Microsoft Solutions Partner designations and 216+ M&A tenant migrations covering 1.83M users. Governed Microsoft AI, Data & Cloud — since 1997.
Key facts
- Mailboxes on any type of hold are blocked from cross-tenant migration, as are OneDrive accounts under a hold policy. In a regulated carve-out this, not data volume, is the critical path.
- Cross-tenant moves are one-and-done. Content is moved, a redirect is left on the source, and delta passes cannot be performed.
- The Cross-Tenant User Data Migration add-on licence is mandatory — a one-time per-user fee assignable on either side. Migrations fail without it and Microsoft publishes no exceptions.
- Cross-tenant SharePoint migration is licensed separately, per 100 GB moved, for Enterprise Agreement customers. Size it from
Get-SPOSite | Select-Object Url, StorageUsageCurrent, allowing for the published 20% storage grace. - Teams and Channels are out of scope for the orchestrator and stay in the source tenant. Licences do not transfer between tenants either.
- Cancelling and deleting a subscription are not the same act. A cancelled subscription moves to Disabled; data may be deleted after 90 days and will be deleted no later than 180. A deleted subscription skips those stages and SharePoint and OneDrive data is destroyed immediately.
Quick facts
| Question | Answer |
|---|---|
| Is a carve-out the same project as a consolidation? | No — opposite direction, different risk, different evidence burden |
| What sets the schedule? | The TSA exit date, not the data volume |
| Can content on legal hold be migrated? | No. Holds block mailbox and OneDrive moves |
| Can you re-run a cross-tenant move? | No. One pass only; no delta |
| Max size per site or OneDrive | 5 TB or 1 million items |
| Path length ceiling | 400 characters, decoded, path plus file name |
| Do Teams and Channels move? | Not with the orchestrator — shared data stays behind |
| Do licences move? | No |
| Domain reuse | One Entra tenant at a time; removal from source is a prerequisite and can take 24 hours |
| Typical elapsed time | 12–20 weeks, signing to TSA exit |
Consolidation and divestiture are not the same project
Both move data between Microsoft 365 tenants. That is where the similarity ends.
Consolidation is additive. You are pulling users into a tenant that already works. Your risk is collision: duplicate UPNs, conflicting Conditional Access, incompatible sharing defaults, two term stores, two retention regimes. You can go slowly and if a batch fails nothing is destroyed. Success is measured by user experience.
Divestiture is subtractive, with a deadline and a lawyer attached. You are removing a defined population and its data from a tenant that must keep operating for everyone else, into a tenant that frequently does not exist yet. Your risk is contamination in both directions: the buyer receiving seller data it has no right to hold, and the seller retaining buyer data it is obliged to surrender or destroy. You cannot go slowly, because the TSA charges by the month, and you cannot keep the source, because you are required to remove it. Success is measured by evidence.
| Dimension | Consolidation | Divestiture / carve-out |
|---|---|---|
| Direction | Many tenants into one | One tenant into two |
| Target tenant | Exists, is governed, is running | Often greenfield; built during the project |
| Deadline | Internal, movable | Contractual, immovable, priced |
| Primary risk | Collision and user disruption | Contamination, retention breach, TSA overrun |
| Rollback | Source remains; re-run possible | Source must be removed; no delta pass |
| Legal involvement | Low | Continuous — counsel signs the exit |
| Deliverable | A working merged tenant | A working new tenant plus an evidence pack |
| Hardest problem | Identity and licence reconciliation | Commingled data with no owner |
Choose the consolidation path when you own both tenants, control the timeline, and nobody outside the company will audit the result. Choose the carve-out path when a signed agreement defines the population, the data, the exit date and the destruction obligations — even if the "buyer" is an internal spin-off.
What data segregation actually means, and how you evidence it
"Clean separation" is not a technical state. It is four contractual assertions, each of which someone will ask you to prove:
- The divested entity received everything it is entitled to — completeness.
- It received nothing it is not entitled to — no over-delivery of seller records, seller mailboxes, or shared sites holding retained-business content.
- The seller no longer holds divested data beyond the permitted window — destruction, or a documented time-boxed exception.
- The seller retains what it is legally obliged to retain — tax, employment, regulatory and litigation records — notwithstanding item 3.
Items 2 and 3 conflict with item 4 more often than anyone expects, and that conflict is a legal decision documented before you touch a mailbox.
The hardest object in a carve-out is the commingled container: the site, channel or shared mailbox used by both populations, with a decade of files and no reliable owner. Four dispositions are defensible, and you record which you chose for every container. Split at the item level — expensive, justified only where the boundary is clean. Copy in full to both sides, then remediate under a dated obligation — fast, needs explicit contractual permission. Assign to one side and grant the other read access under the TSA for a fixed window — the most common outcome and cheapest to evidence. Retire — archive, nobody gets live access.
Your Separation Evidence Pack closes the project. Build it as you go; it cannot be reconstructed afterwards.
| Evidence artefact | What it proves | Captured at |
|---|---|---|
| Signed scope register and commingled container disposition log | Who and what was in scope; every shared object had an approved outcome | Lock 1 |
| Identity map file (as executed) | Which source principal became which target principal | Lock 2 |
| Hold register plus per-location release authorisations | Which locations were on hold, and who approved each release | Lock 2 |
| Pre-move eDiscovery export receipts | Litigation-relevant content was preserved before the source was destroyed | Lock 2 |
| Per-batch reconciliation and closed exception register | Completeness — nothing silently dropped or ignored | Lock 3 |
| Redirect and domain removal records | The buyer's namespace and links left the seller's directory | Lock 5 |
| Subscription deprovision plus counter-signed destruction attestation | Obligation 3 was discharged on a dated event | Lock 6 |
Two rules keep the pack credible. Reconcile counts, not feelings — a batch is complete when source and target item counts agree and every delta has a named exception. And never let an engineer release a legal hold: counsel authorises in writing, per location, and the authorisation goes in the pack. Our SOC 2 compliance guidance covers the control mapping this feeds.
The TSA clock
The Transition Services Agreement is the schedule. Everything else is scheduling around it.
A TSA is the arrangement under which the seller keeps running IT for the divested entity after close, for a fee, for a bounded period, with extension options priced to be unattractive. Four dates matter and they are almost never the same: signing, when discovery opens; close / Day 1, when the entity is legally separate and its people need to work; TSA start, usually at close; and TSA exit, when the entity stands alone and the seller's obligations end.
Day 1 and TSA exit are different problems. Day 1 is readiness: can people send mail, join meetings, open files, get support. TSA exit is separation: is the data moved, is the evidence complete, is the source removed. Teams that conflate them try to migrate everything by Day 1 and either miss the deal date or ship an unevidenced separation.
Microsoft's platform clocks are long, fixed and sequential, and they must fit inside the TSA window.
| Platform clock | Published duration | Why it constrains the TSA |
|---|---|---|
| Custom domain deletion | Asynchronous job, up to 24 hours | The buyer cannot verify the domain until the seller releases it |
| Delay hold after releasing an eDiscovery hold | 30 days | Preservation Hold library content cannot be deleted during it |
| Preservation Hold library drain | Up to 37 days (30 days plus a 7-day timer job) | Destruction attestation cannot be issued before it completes |
| Subscription cancel → Disabled | ~90 days of admin-only access | Your last window to extract anything you forgot |
| Data deletion after cancellation | After 90 days, no later than 180 | Your destruction date is a range, not a point — say so in the attestation |
| Subscription delete → Deprovisioned | 72 hours | Required before the Entra tenant itself can be deleted |
Sequence backwards from TSA exit, not forwards from Day 1. The domain hand-back alone commonly sits four to six weeks before exit, because the buyer's mail flow, Conditional Access and device enrolment all depend on the namespace they will own.
The Six-Lock Carve-Out Model
The Six-Lock Carve-Out Model is EPC Group's framework for a divestiture. Each lock is a gate that closes once and is not reopened, and the evidence pack is assembled as you close them. Durations are typical for a single-region carve-out of 1,000–5,000 users.
| Lock | What closes | Owner | Typical duration |
|---|---|---|---|
| 1 — Scope Lock | The in-scope population, the in-scope data, and a disposition for every commingled container, signed by both sides' counsel | Separation programme lead + legal | 3–5 weeks |
| 2 — Identity Lock | Target tenant built, users pre-created as MailUsers, identity map file finalised, hold register produced and releases authorised | Identity architect + records/legal | 3–4 weeks, overlaps Lock 1 |
| 3 — Data Lock | Cross-tenant licences purchased, pilot batch validated, production batches run and reconciled, exception register closed | Migration lead | 4–8 weeks |
| 4 — Operations Lock | Day 1 readiness: mail routing, support desk, device management, Conditional Access, printing, line-of-business integrations | Service delivery lead | 2–3 weeks, ends at close |
| 5 — Namespace Lock | Redirects removed, custom domain removed from source and verified in target, guest and B2B relationships pruned | Directory admin | 1–2 weeks |
| 6 — Decommission Lock | Subscriptions cancelled or deleted on a dated approval, destruction attestation counter-signed, evidence pack delivered | Programme lead + legal + procurement | 1–2 weeks, plus the platform clocks |
Two rules are non-negotiable. Nothing moves before Lock 2 closes, because a migration run against an unapproved identity map produces data you cannot evidence and cannot undo. And Lock 6 is a change-controlled legal event with a named approver — deleting a subscription destroys SharePoint and OneDrive content immediately.
What you can and cannot take with you
Put this table in front of a business sponsor in week one, before anyone promises the buyer a like-for-like environment.
| Object | Moves cross-tenant? | Notes |
|---|---|---|
| Mailbox content — mail, contacts, calendar, tasks, notes | Yes | User-visible content only. The source mailbox is deleted after a successful move and is not discoverable in the source afterwards |
| OneDrive files, versions, ownership history, sharing links | Yes | One pass only; a redirect is left on the source until the source tenant is deprovisioned |
| SharePoint sites — group-connected, modern, classic, communication | Yes, separately licensed | Cross-Tenant Shared Data Migration, priced per 100 GB, EA customers |
| File and folder permissions, user and group level | Yes | Only for principals present in the identity map |
| Teams chats and meetings | Yes, via the orchestrator | Meetings depend on a successful mailbox move; source threads may persist in edited form |
| Teams and Channels themselves | No | Shared data stays in the source tenant |
| Microsoft 365 Groups, licences and subscriptions | No | Pre-create groups in the target; buy new licences there |
| Sensitivity labels and their protection | No | Labels are not exported; protection does not survive. Recreate in the target |
| Retention labels and policies, eDiscovery cases and holds | No | Rebuild the compliance posture in the target as a workstream in its own right |
| Content on any hold | No — blocked | Release under counsel's authorisation, migrate, re-apply in the target |
| Workflows, apps, Power Apps, Power Automate | No | Recreate and reconnect on the target |
| Distribution lists, mail contacts, public folders, journaling, mailbox rules, delegates | No | Pre-create, or recreate manually after the move |
| Sites over 5 TB or 1 million items; paths over 400 characters | No | Remediate before the batch, or the batch fails |
| Content under Customer Key encryption, or labels with user-defined permissions | No | Migration fails. Resolve encryption first; decrypt files with Unlock-SPOSensitivityLabelEncryptedFile |
Two consequences follow. The buyer's Teams estate is a build, not a move. And the compliance posture is a build too: labels, policies and holds are recreated, so the buyer's records programme has a start date and a coverage gap, and both must be disclosed. Our SharePoint migration services guidance covers the content-side remediation this generates.
Licensing and subscription unwind
Licences are not portable. The divested entity buys its own, in its own tenant, before Day 1 — and Enterprise Agreement procurement lead time is frequently longer than the migration itself. Start there in week one. Four cost lines surprise sponsors.
The cross-tenant migration add-ons. The Cross-Tenant User Data Migration licence is a required one-time per-user fee, assignable on either side, with no exceptions. Cross-tenant SharePoint is licensed separately per 100 GB moved. The seller usually buys both and the TSA usually reimburses — put the recharge in the agreement, not in an email.
The double-run. Through the TSA window both tenants are licensed for the divested population. Model the overlap in months: it is the cheapest line to shorten and the most expensive to discover late.
The seat reduction. Removing users does not reduce the seller's bill; Enterprise Agreement seat counts change at anniversary or true-up. Book that conversation at Lock 1, not Lock 6.
The destruction decision. Cancelling puts the subscription into Disabled for roughly 90 days with admin-only access — your last chance to extract anything the evidence pack needs. Deleting destroys SharePoint and OneDrive content immediately. Cancel, extract, attest, then delete. Compare licence footprints with our Microsoft 365 E3 vs E5 comparison before the buyer's SKU is chosen, and model add-ons against our Copilot pricing and licensing guide.
eDiscovery and legal-hold continuity
This is where carve-outs go wrong quietly, and it is the section the vendor guides omit.
Holds block migration. Mailboxes on any type of hold are not migrated; OneDrive accounts with a hold policy applied are blocked. The only way to move a custodian's data is to release the hold — a legal act, not a ticket.
Releasing a hold does not immediately free the content. A delay hold is applied automatically after a hold is removed, and Preservation Hold library content is not deleted during the 30-day delay period. Mailbox hold changes can take 240 minutes to apply, and the library can take 37 days to drain. Policies under Preservation Lock cannot be removed at all — that disposition is a legal negotiation, not a migration task.
The source disappears. After a successful cross-tenant mailbox move, the source mailbox is deleted and is not available, discoverable or accessible in the source tenant. If litigation-relevant content existed only there and you did not export it first, it is gone.
The runbook that survives audit: enumerate every hold source before you plan a batch — eDiscovery case holds, Purview retention policies, retention labels, Litigation Hold, delay holds and Single Item Recovery all preserve independently, and any one blocks a move. Produce a hold register with location, hold type, source, matter, custodian and counsel owner. Export before you release, into the seller's retained estate. Release per location on written authorisation, filed in the evidence pack. Migrate, then re-apply in the target, and record the coverage gap for both sides' counsel before close.
Where the divested entity is regulated, sequence the first three steps into Lock 1. Discovery on holds routinely takes longer than discovery on data. Our data governance consulting guidance covers the target-side rebuild.
What breaks — failure modes
| Symptom | Root cause | Fix |
|---|---|---|
| A user is silently skipped from every batch | Mailbox or OneDrive is on a hold; the move is blocked by design | Enumerate hold sources, obtain written release, wait for propagation, re-batch |
| Migration fails immediately for every user | Cross-Tenant User Data Migration licence not purchased or not assigned | Purchase and assign; Microsoft publishes no exceptions to this requirement |
| SharePoint site migration fails on start | Target site already exists — you cannot overwrite or merge | Delete the pre-created target and re-run; never pre-create targets |
| Migration fails with an invalid-character or path error | Combined source path plus longer target URL exceeds 400 characters | Shorten the target site or user URL, or restructure the source folders |
| A site times out, or files arrive unreadable | Site exceeds 5 TB or 1 million items; or sensitivity labels with user-defined permissions | Split the site or trim versions; decrypt labelled files before migration and re-label afterwards |
| The buyer cannot verify its own domain, or deletion keeps failing | Domain still verified in the seller's tenant; or over 1,000 references, an Exchange-mastered group, a multitenant app, or federated authentication | Clean references in the Exchange admin center, then delete; allow 24 hours. ForceDelete will not work on a federated domain |
| Content is unexpectedly gone at attestation time | The subscription was deleted rather than cancelled | Not recoverable. Cancel, extract, attest, then delete — in that order |
| Reconciliation counts never agree | Delta passes were assumed; moves are one-and-done | Freeze the source for the batch window; treat every miss as an exception |
What changed in 2026
- The Microsoft 365 Migration Orchestrator changes the shape of the project. It coordinates Exchange mailboxes, OneDrive, Teams chats and Teams meetings in one dependency-aware batch, and explicitly names Tenant Move/Split as a supported architecture model for divestitures. Batches fail to initiate if Teams meetings are selected without Teams chats and mailboxes.
- Cross-tenant SharePoint migration is now a licensed capability, priced per 100 GB moved, for Enterprise Agreement customers. Most carve-out plans still assume a third-party tool is mandatory for sites. Re-scope.
- The orchestrator's scope boundary is now explicit. Shared data — Teams and Channels, SharePoint sites — is out of scope and remains in the source tenant. Microsoft also states plainly that the orchestrator moves content, not identities: configuring target users remains the customer's responsibility, which is exactly where a carve-out consumes its schedule.
- FastTrack offers a cross-tenant migration service on an invitation-only basis, requiring a minimum of 150 Cross-Tenant User Data Migration licences, and excluding Teams, Microsoft 365 Groups, Planner, Stream, Power Automate, Power Apps and device management.
- Multi-geo carve-outs need a trust per instance, and each source instance is subject to the 4,000-item queue limit regardless of how many targets exist.
Where to go next
If a deal has been signed and you do not yet have a disposition for every commingled SharePoint site, Teams channel and shared mailbox, the TSA clock is already costing you money. EPC Group runs Scope Lock and Identity Lock as a fixed-scope separation assessment and hands you a dated runbook, a hold register and the index of the evidence pack. Start with enterprise Microsoft consulting or Azure cloud migration consulting.
Related: Exchange to Microsoft 365 migration · SharePoint migration services · SharePoint consulting Dallas · My Sites in SharePoint · Box vs SharePoint · Teams Premium features · E3 vs E5 · Microsoft Frontier Company · Delivery partner vendor risk · CFO AI governance · EPC Group
Frequently asked questions
Is a tenant divestiture just a consolidation run backwards?
No. Consolidation is additive, internally scheduled, and reversible in practice because the source survives. A divestiture is subtractive, scheduled by a Transition Services Agreement, audited by both parties' counsel, and ends with the deliberate destruction of the source. The deliverable is a working tenant plus an evidence pack.
Can we migrate data that is on legal hold?
No. Mailboxes on any type of hold are not migrated and the move is blocked, and OneDrive accounts with a hold policy applied are blocked. Release the hold under written authorisation from counsel, migrate, then re-apply in the target. Export first — the source mailbox is deleted after a successful move.
Do Teams and Channels move to the buyer's tenant?
Not with the Cross-Tenant User Data Migration solution. It does not migrate shared data such as Teams and Channels or SharePoint sites; that content remains in the source tenant. Teams chats and meetings are supported by the orchestrator, but the team structure is a target-side build.
What happens to our licences?
Nothing moves. Licences and subscriptions do not transfer between tenants, so the divested entity buys its own before Day 1. Removing users does not reduce the seller's bill either — Enterprise Agreement seat counts change at anniversary or true-up under contractual terms.
Should we cancel or delete the source subscription?
Cancel first. A cancelled subscription moves to Disabled with admin-only access for roughly 90 days; data may be deleted after 90 days and will be deleted no later than 180. Deleting a subscription skips those stages and destroys SharePoint and OneDrive content immediately. Cancel, extract, attest, then delete.
How long does a carve-out take?
For a single-region estate of 1,000–5,000 users, plan 12–20 weeks from signing to TSA exit. The long poles are rarely data volume: they are scope agreement on commingled containers, hold enumeration and release, target-tenant procurement, and the fixed platform clocks.
When can the buyer take our custom domain?
Only after the seller removes it. A custom domain can be verified in only one Microsoft Entra tenant at a time. Removal requires clearing every user, group and application reference, deletion can take 24 hours, and ForceDelete fails above 1,000 references or on a federated domain.
What is the minimum evidence a buyer's counsel will accept?
In practice: a signed scope register, the identity map as executed, a hold register with per-location release authorisations, per-batch reconciliation, a closed exception register, confirmation of redirect and domain removal, subscription deprovision confirmation, and a counter-signed destruction attestation stating the deletion window as a range.
Sources and verification
- Microsoft Learn — Plan a Microsoft 365 tenant-to-tenant migration
- Microsoft Learn — An overview of tenant-to-tenant migration with orchestrator in Microsoft 365
- Microsoft Learn — Microsoft 365 migration overview
- Microsoft Learn — Cross-tenant mailbox migration
- Microsoft Learn — Cross-tenant OneDrive migration
- Microsoft Learn — Cross-tenant SharePoint migration
- Microsoft Learn — Cross-Tenant Migration (FastTrack)
- Microsoft Learn — What is cross-tenant synchronization?
- Microsoft Learn — Multitenant organization capabilities in Microsoft Entra ID
- Microsoft Learn — Scenarios for multiple Microsoft Entra tenants
- Microsoft Learn — Manage custom domain names in your Microsoft Entra ID
- Microsoft Learn — Delete a tenant in Microsoft Entra ID
- Microsoft Learn — Cancel your subscription in the Microsoft 365 admin center
- Microsoft Learn — What happens to my data and access when my Microsoft 365 for business subscription ends?
- Microsoft Learn — Data retention, deletion, and destruction in Microsoft 365
- Microsoft Learn — Manage holds in eDiscovery
- Microsoft Learn — Create holds in eDiscovery
- Microsoft Learn — Learn about retention policies and retention labels
- Microsoft Learn — Learn about retention for SharePoint and OneDrive
- Microsoft Learn — Use Preservation Lock to restrict changes to retention policies
- Microsoft Learn — Plan for Microsoft 365 Multi-Geo
- Microsoft Learn — Data Residency for SharePoint and OneDrive
- Microsoft Learn — SharePoint limits
- Microsoft Learn — Parallel and combined identity infrastructure options
- CoreView — Microsoft 365 tenant-to-tenant migration: a comprehensive guide for IT leaders (target citation, reviewed 2026-07-31)
