Introduction
Device Migration in Tenant Migrations
When migrating between Microsoft 365 tenants, device registrations require special attention. Devices registered to Azure AD must be properly transitioned to maintain security and compliance.
During Microsoft 365 tenant-to-tenant migrations, one often overlooked aspect is device management. Devices registered with Azure AD and managed by Microsoft Intune in the source tenant must be properly migrated to maintain security policies and user productivity.
This guide explains the different device registration types and provides a step-by-step approach to migrating devices between tenants. For detailed technical instructions, refer to our admin guides.
Device Registration Types
Understanding the different device registration types is crucial for planning your migration. Cloudiway's Intune migration tool handles all these scenarios alongside SharePoint migration:
Azure AD Joined
Corporate devices fully managed by the organization. These require complete re-provisioning during migration.
Azure AD Registered
Personal devices with work account added. Users can remove and re-add their work account to the new tenant.
Hybrid Azure AD Joined
On-premises AD joined and Azure AD registered. These require careful planning due to dual identity.
Migration Challenges
Device migration between tenants presents several challenges. These are similar to challenges in OneDrive migration projects:
Key Challenges
- No direct transfer between tenants
- End user participation required
- Policy recreation needed
- Brief compliance gap during transition
Solutions
- Cloudiway automation tools
- Step-by-step user guides
- Policy export/import scripts
- Compliance monitoring dashboard
Migration Process
Follow these steps to migrate devices between tenants. This process integrates with broader mailbox migration workflows:
Inventory Devices
Export list of all registered devices from Azure AD. Identify device types, owners, and compliance status.
Prepare Destination Tenant
Configure Azure AD and Intune settings in destination. Recreate conditional access and compliance policies.
Communicate with Users
Notify users about the migration timeline and provide instructions for device re-registration.
Remove Source Registration
Have users remove work account from devices or use automation tools to unregister devices.
Register in Destination
Guide users to add new work account and complete device registration in destination tenant.
Verify Compliance
Confirm devices appear in destination tenant and comply with security policies.
Important Considerations
- BitLocker Keys: Export recovery keys before migration as they are tenant-specific
- Conditional Access: Recreate policies in destination before device migration
- App Configuration: Some apps may require reconfiguration with new credentials
Best Practices
Follow these recommendations for a smooth device migration. Our Teams migration tool integrates with device migration for comprehensive transitions. See our case studies for real-world examples:
Plan Policy Migration First
Before migrating devices, ensure all Intune policies, compliance rules, and conditional access policies are configured in the destination tenant.
Migrate in Waves
Don't migrate all devices at once. Start with a pilot group, validate the process, then proceed with larger waves.
Provide Clear Instructions
Create step-by-step guides with screenshots for users to follow during device re-registration.
Monitor Compliance
After migration, closely monitor device compliance in the destination tenant and address any issues promptly.
Prepare Support Team
Train your IT support team on common issues and provide them with troubleshooting guides.
Validate Applications
Test critical applications on migrated devices to ensure they work correctly with new tenant credentials.
Need Help with Device Migration?
Cloudiway offers tools and expertise to streamline your tenant-to-tenant device migration. Check our pricing or request consulting services. Our platform is ISO 27001 certified.
For comprehensive migrations, Cloudiway provides coexistence tools including GALSync for address list synchronization during the transition period.
Cloudiway supports complete Microsoft 365 migrations including Exchange migration and Google Workspace to Microsoft 365 migration projects.
Frequently Asked Questions
What is the difference between Azure AD Joined and Azure AD Registered?
Azure AD Joined devices are fully managed by the organization and typically company-owned. Azure AD Registered devices are personal devices where users add their work account while maintaining personal ownership. During migration, both types need different handling approaches.
Can devices be migrated automatically between tenants?
Devices cannot be automatically transferred between tenants. The device registration must be removed from the source tenant and re-registered in the destination tenant. Cloudiway provides tools to streamline this process and guide users through device re-registration.
What happens to Intune policies during device migration?
Intune policies from the source tenant will no longer apply after the device is unregistered. You must recreate or export/import policies to the destination tenant and ensure devices receive new policies after re-registration.
Do users need to re-authenticate after device migration?
Yes, users will need to sign in with their new tenant credentials after re-registering their devices. Applications may require re-authentication, and some cached credentials may need to be cleared.