Ready to migrate?
Azure AD device management and migration
How-To

Azure AD Device Migration Guide

How to Seamlessly Transfer Device Registrations During Microsoft 365 Tenant Migration

Aziz Ldir
Aziz Ldir Escalation Engineer
November 10, 2023 · 6 min read

Introduction

Device Migration in Tenant Migrations

When migrating between Microsoft 365 tenants, device registrations require special attention. Devices registered to Azure AD must be properly transitioned to maintain security and compliance.

During Microsoft 365 tenant-to-tenant migrations, one often overlooked aspect is device management. Devices registered with Azure AD and managed by Microsoft Intune in the source tenant must be properly migrated to maintain security policies and user productivity.

This guide explains the different device registration types and provides a step-by-step approach to migrating devices between tenants. For detailed technical instructions, refer to our admin guides.

Device Registration Types

Understanding the different device registration types is crucial for planning your migration. Cloudiway's Intune migration tool handles all these scenarios alongside SharePoint migration:

Azure AD Joined

Corporate devices fully managed by the organization. These require complete re-provisioning during migration.

Azure AD Registered

Personal devices with work account added. Users can remove and re-add their work account to the new tenant.

Hybrid Azure AD Joined

On-premises AD joined and Azure AD registered. These require careful planning due to dual identity.

Migration Challenges

Device migration between tenants presents several challenges. These are similar to challenges in OneDrive migration projects:

Key Challenges

  • No direct transfer between tenants
  • End user participation required
  • Policy recreation needed
  • Brief compliance gap during transition

Solutions

  • Cloudiway automation tools
  • Step-by-step user guides
  • Policy export/import scripts
  • Compliance monitoring dashboard

Migration Process

Follow these steps to migrate devices between tenants. This process integrates with broader mailbox migration workflows:

1

Inventory Devices

Export list of all registered devices from Azure AD. Identify device types, owners, and compliance status.

2

Prepare Destination Tenant

Configure Azure AD and Intune settings in destination. Recreate conditional access and compliance policies.

3

Communicate with Users

Notify users about the migration timeline and provide instructions for device re-registration.

4

Remove Source Registration

Have users remove work account from devices or use automation tools to unregister devices.

5

Register in Destination

Guide users to add new work account and complete device registration in destination tenant.

6

Verify Compliance

Confirm devices appear in destination tenant and comply with security policies.

Important Considerations

  • BitLocker Keys: Export recovery keys before migration as they are tenant-specific
  • Conditional Access: Recreate policies in destination before device migration
  • App Configuration: Some apps may require reconfiguration with new credentials

Best Practices

Follow these recommendations for a smooth device migration. Our Teams migration tool integrates with device migration for comprehensive transitions. See our case studies for real-world examples:

Plan Policy Migration First

Before migrating devices, ensure all Intune policies, compliance rules, and conditional access policies are configured in the destination tenant.

Migrate in Waves

Don't migrate all devices at once. Start with a pilot group, validate the process, then proceed with larger waves.

Provide Clear Instructions

Create step-by-step guides with screenshots for users to follow during device re-registration.

Monitor Compliance

After migration, closely monitor device compliance in the destination tenant and address any issues promptly.

Prepare Support Team

Train your IT support team on common issues and provide them with troubleshooting guides.

Validate Applications

Test critical applications on migrated devices to ensure they work correctly with new tenant credentials.

Need Help with Device Migration?

Cloudiway offers tools and expertise to streamline your tenant-to-tenant device migration. Check our pricing or request consulting services. Our platform is ISO 27001 certified.

For comprehensive migrations, Cloudiway provides coexistence tools including GALSync for address list synchronization during the transition period.

Cloudiway supports complete Microsoft 365 migrations including Exchange migration and Google Workspace to Microsoft 365 migration projects.

Frequently Asked Questions

What is the difference between Azure AD Joined and Azure AD Registered?

Azure AD Joined devices are fully managed by the organization and typically company-owned. Azure AD Registered devices are personal devices where users add their work account while maintaining personal ownership. During migration, both types need different handling approaches.

Can devices be migrated automatically between tenants?

Devices cannot be automatically transferred between tenants. The device registration must be removed from the source tenant and re-registered in the destination tenant. Cloudiway provides tools to streamline this process and guide users through device re-registration.

What happens to Intune policies during device migration?

Intune policies from the source tenant will no longer apply after the device is unregistered. You must recreate or export/import policies to the destination tenant and ensure devices receive new policies after re-registration.

Do users need to re-authenticate after device migration?

Yes, users will need to sign in with their new tenant credentials after re-registering their devices. Applications may require re-authentication, and some cached credentials may need to be cleared.