Migrate Intune Between Tenants
Complete guide for migrating Microsoft Intune policies, configurations, and assignments between Microsoft 365 tenants.
Overview
This guide shows you how to migrate Microsoft Intune policies, configurations, and assignments between Microsoft 365 tenants using Cloudiway.
Video Tutorial
Looking for our Intune Migration Solution?
Discover all features, pricing, and use cases for Intune cross-tenant migration.
View Solution PagePrerequisites
To perform the Intune migration, you need an Entra ID Application with the appropriate permissions on both source and target tenants.
The sections below describe the permissions required for each tenant. These are provided for reference if you prefer to create the Entra ID Application manually or need to verify the permissions.
Source Tenant Entra ID Application
The source tenant application requires read permissions to discover Intune policies and configurations:
- DeviceManagementConfiguration.Read.All - Read device configurations
- DeviceManagementApps.Read.All - Read app management data
- DeviceManagementManagedDevices.Read.All - Read managed devices
- Group.Read.All - Read group information for assignments
Target Tenant Entra ID Application
The target tenant application requires the following permissions:
- Agreement.ReadWrite.All
- Application.Read.All
- DeviceManagementApps.ReadWrite.All
- DeviceManagementConfiguration.ReadWrite.All
- DeviceManagementManagedDevices.ReadWrite.All
- DeviceManagementRBAC.ReadWrite.All
- DeviceManagementServiceConfig.ReadWrite.All
- Group.Read.All
- User.Read.All
- Policy.Read.All
- Policy.ReadWrite.ConditionalAccess
- Directory.Read.All
In addition for device migration these one are needed:
- Organization.Read.All
- Device.Read.All
What is Migrated
Cloudiway migrates the following Intune components across three main categories:
Devices
- Device | Clean-up rules
- Device | Compliance Policies
- Policies (all platforms: Android, Linux, iOS, Windows, macOS)
- Notifications
- Scripts
- Devices | Conditional access policies
- Policies
- Named Location
- Terms of Use
- Devices | Configuration profiles and updates
- Update rings for Windows 10 and later
- Feature updates for Windows 10 and later
- Quality updates for Windows 10 and later
- Update policies for iOS/iPadOS
- Update policies for macOS
- Devices | Enrollment and management
- Enrollment device limit restrictions
- Enrollment device platform restrictions
- Policy sets
- Device categories
- Filters
Endpoint Security
- Endpoint security | Antivirus
- Endpoint security | Disk encryption
- Endpoint security | Firewall
- Endpoint security | Endpoint Privilege Management
- Endpoint security | Endpoint detection and response
- Endpoint security | Attack surface reduction
- Endpoint security | Account protection
Applications
- Apps | All Apps *
- Apps | App categories
- eBooks | eBook categories
- Apps | App protection policies
- Apps | App configuration policies
- Apps | iOS app provisioning profiles
(Recommended): Re-upload the original .intunewin
If you still have the original package:
- Open Target Tenant → Intune Admin Center.
- Go to Apps → Windows → Add → Win32 app.
- Upload the original .intunewin file.
- Configure the install/uninstall commands, detection rules, requirements, and assignments (or recreate them from the migrated app).
Migration Process
The migration is a five-step process:
- Create the connectors for connecting to the source and the target
- Run a Discovery to discover the Intune policies and settings
- Select what to migrate
- Create your mapping table to map source and target accounts and groups
- Run the migration
Step 1: Create Connectors
To facilitate the migration, the Cloudiway platform needs to communicate with both your source and target tenants. To do this, Cloudiway uses connectors. You will need to set up a connector for each source tenant and each target tenant.
Microsoft Connector
To configure your Microsoft 365 connector, proceed with the steps in the following article:
Step 2: Discovery
In the menu, under Cross Tenant Migration, open Intune.
Then click on Discover.
In the popup, select your connector, then click OK. This will schedule the discovery job.
Step 3: Select What to Migrate
Once the discovery is completed, you can see the result and select the policies to migrate.
By default, everything is selected. You can modify the selection and click on SAVE SELECTION.
Only these policies will be migrated.
Step 4: Mapping Table
Assignments are groups and users assigned to a policy.
A mapping needs to be established between the source and target groups.
To help you in this task, Cloudiway uses a mapping table to link source and target groups.
Furthermore, after the discovery, it helps you find and report the broken links (assigned groups that are not found at the target).
For this, switch to the flat view, and click on ASSIGNMENTS.
Any group that does not exist in the mapping table is reported.
To fix the missing assignment group, you can do it in 2 ways:
Using the Cloudiway Platform
- Navigate to the Mapping Group tab
- Run a Get Mapping and select the option to automatically Provision the missing entries
Using Your Manual Process
- Create the missing group entry manually from your Microsoft 365 tenant
- Then navigate to the Mapping Group tab and rediscover the entries without selecting the option to autoprovision
Step 5: Run Migration
When you are ready to migrate, click on MIGRATE.
Select the source and target connector and click OK.
This will schedule the migration job.
You can monitor and see the migration logs under Migration Logs.
Troubleshooting
Cloudiway provides an extensive knowledge base with many resources, including common error messages, video guides, and downloads.
Please visit the knowledge base here: Cloudiway Help Center
Support
Support tickets are opened through the platform.
Once logged in, go to your project and select Help, then Support. The chatbot will ask you a couple of questions and then open a support ticket. You will receive an email response to your ticket, and you can continue the support by email.
More information regarding our support program is available here: Cloudiway Support
Frequently Asked Questions
How many migration licenses will I need?
You need a global Cross-Tenant migration license. It is a yearly subscription. Please contact sales to get a complete quote.
What Intune configurations are migrated?
Cloudiway migrates device configuration profiles, compliance policies, app protection policies, and group assignments between tenants.
Are group assignments preserved during migration?
Yes, Cloudiway uses a mapping table to link source and target groups. The platform identifies broken links (assigned groups not found at target) and helps you fix them before migration.
Can I select which policies to migrate?
Yes, after discovery, all policies are selected by default. You can modify the selection and click "SAVE SELECTION" to choose only the policies you want to migrate.
Get a free migration quote in minutes — entirely self-service.