Ready to migrate?
Admin Guide

Migrate Intune Between Tenants

Complete guide for migrating Microsoft Intune policies, configurations, and assignments between Microsoft 365 tenants.

10 min read Updated: 2024-12-01 Microsoft 365 Tenant to Tenant

Overview

This guide shows you how to migrate Microsoft Intune policies, configurations, and assignments between Microsoft 365 tenants using Cloudiway.

Video Tutorial

Important: The migration is a five-step process that includes discovery of all Intune policies, selection of what to migrate, mapping of groups and users, and the actual migration.

Looking for our Intune Migration Solution?

Discover all features, pricing, and use cases for Intune cross-tenant migration.

View Solution Page

Prerequisites

To perform the Intune migration, you need an Entra ID Application with the appropriate permissions on both source and target tenants.

Automatic Mode Available: Cloudiway can automatically create the Entra ID Application with all required permissions when you configure your connector. Simply use the automatic provisioning option during connector setup, and Cloudiway will handle the application registration and permission grants for you.

The sections below describe the permissions required for each tenant. These are provided for reference if you prefer to create the Entra ID Application manually or need to verify the permissions.

Source Tenant Entra ID Application

The source tenant application requires read permissions to discover Intune policies and configurations:

  • DeviceManagementConfiguration.Read.All - Read device configurations
  • DeviceManagementApps.Read.All - Read app management data
  • DeviceManagementManagedDevices.Read.All - Read managed devices
  • Group.Read.All - Read group information for assignments

Target Tenant Entra ID Application

The target tenant application requires the following permissions:

  • Agreement.ReadWrite.All
  • Application.Read.All
  • DeviceManagementApps.ReadWrite.All
  • DeviceManagementConfiguration.ReadWrite.All
  • DeviceManagementManagedDevices.ReadWrite.All
  • DeviceManagementRBAC.ReadWrite.All
  • DeviceManagementServiceConfig.ReadWrite.All
  • Group.Read.All
  • User.Read.All
  • Policy.Read.All
  • Policy.ReadWrite.ConditionalAccess
  • Directory.Read.All

In addition for device migration these one are needed:

  • Organization.Read.All
  • Device.Read.All
Connector Configuration: For detailed instructions on configuring your Microsoft 365 connector, refer to the How to Create an EntraID Application for Cloudiway documentation.

What is Migrated

Cloudiway migrates the following Intune components across three main categories:

Devices

  • Device | Clean-up rules
  • Device | Compliance Policies
    • Policies (all platforms: Android, Linux, iOS, Windows, macOS)
    • Notifications
    • Scripts
  • Devices | Conditional access policies
    • Policies
    • Named Location
    • Terms of Use
  • Devices | Configuration profiles and updates
    • Update rings for Windows 10 and later
    • Feature updates for Windows 10 and later
    • Quality updates for Windows 10 and later
    • Update policies for iOS/iPadOS
    • Update policies for macOS
  • Devices | Enrollment and management
    • Enrollment device limit restrictions
    • Enrollment device platform restrictions
    • Policy sets
    • Device categories
    • Filters

Endpoint Security

  • Endpoint security | Antivirus
  • Endpoint security | Disk encryption
  • Endpoint security | Firewall
  • Endpoint security | Endpoint Privilege Management
  • Endpoint security | Endpoint detection and response
  • Endpoint security | Attack surface reduction
  • Endpoint security | Account protection

Applications

  • Apps | All Apps *
  • Apps | App categories
  • eBooks | eBook categories
  • Apps | App protection policies
  • Apps | App configuration policies
  • Apps | iOS app provisioning profiles
* Note: Cloudiway only migrates apps that can be created from Intune > Apps. Some app types that require external dependencies or store connections may need to be recreated manually.
Note: The .intunewin package stored in Intune is not downloadable from the source tenant.

(Recommended): Re-upload the original .intunewin
If you still have the original package:
  1. Open Target Tenant → Intune Admin Center.
  2. Go to Apps → Windows → Add → Win32 app.
  3. Upload the original .intunewin file.
  4. Configure the install/uninstall commands, detection rules, requirements, and assignments (or recreate them from the migrated app).
This is Microsoft's recommended approach.

Migration Process

The migration is a five-step process:

  1. Create the connectors for connecting to the source and the target
  2. Run a Discovery to discover the Intune policies and settings
  3. Select what to migrate
  4. Create your mapping table to map source and target accounts and groups
  5. Run the migration
Intune Migration Settings
Intune Migration interface in Cloudiway platform

Step 1: Create Connectors

To facilitate the migration, the Cloudiway platform needs to communicate with both your source and target tenants. To do this, Cloudiway uses connectors. You will need to set up a connector for each source tenant and each target tenant.

Microsoft Connector

To configure your Microsoft 365 connector, proceed with the steps in the following article:

How to Create an EntraID Application for Cloudiway - Complete guide to configure your source and target connectors.

Step 2: Discovery

In the menu, under Cross Tenant Migration, open Intune.

Then click on Discover.

Intune migration discovery
Intune Discovery dialog

In the popup, select your connector, then click OK. This will schedule the discovery job.

Discovery Process: The discovery will scan your source tenant and identify all Intune policies, configurations, and their assignments.

Step 3: Select What to Migrate

Once the discovery is completed, you can see the result and select the policies to migrate.

By default, everything is selected. You can modify the selection and click on SAVE SELECTION.

Only these policies will be migrated.

Intune discovery results
Discovery results showing all Intune policies available for migration

Step 4: Mapping Table

Assignments are groups and users assigned to a policy.

A mapping needs to be established between the source and target groups.

To help you in this task, Cloudiway uses a mapping table to link source and target groups.

Furthermore, after the discovery, it helps you find and report the broken links (assigned groups that are not found at the target).

For this, switch to the flat view, and click on ASSIGNMENTS.

Intune Assignments
View policy assignments and identify broken links
Intune Assignment Group
Assignment group mapping details

Any group that does not exist in the mapping table is reported.

To fix the missing assignment group, you can do it in 2 ways:

Using the Cloudiway Platform

  • Navigate to the Mapping Group tab
  • Run a Get Mapping and select the option to automatically Provision the missing entries

Using Your Manual Process

  • Create the missing group entry manually from your Microsoft 365 tenant
  • Then navigate to the Mapping Group tab and rediscover the entries without selecting the option to autoprovision

Step 5: Run Migration

When you are ready to migrate, click on MIGRATE.

Migrate Intune
Click MIGRATE to start the Intune migration

Select the source and target connector and click OK.

This will schedule the migration job.

You can monitor and see the migration logs under Migration Logs.

Intune Migration Progress
Monitor migration progress and logs

Troubleshooting

Cloudiway provides an extensive knowledge base with many resources, including common error messages, video guides, and downloads.

Please visit the knowledge base here: Cloudiway Help Center

Support

Support tickets are opened through the platform.

Once logged in, go to your project and select Help, then Support. The chatbot will ask you a couple of questions and then open a support ticket. You will receive an email response to your ticket, and you can continue the support by email.

More information regarding our support program is available here: Cloudiway Support

Frequently Asked Questions

How many migration licenses will I need?

You need a global Cross-Tenant migration license. It is a yearly subscription. Please contact sales to get a complete quote.

What Intune configurations are migrated?

Cloudiway migrates device configuration profiles, compliance policies, app protection policies, and group assignments between tenants.

Are group assignments preserved during migration?

Yes, Cloudiway uses a mapping table to link source and target groups. The platform identifies broken links (assigned groups not found at target) and helps you fix them before migration.

Can I select which policies to migrate?

Yes, after discovery, all policies are selected by default. You can modify the selection and click "SAVE SELECTION" to choose only the policies you want to migrate.

Ready to Start Your Intune Migration?

Get a free migration quote in minutes — entirely self-service.