Practical guide
Intune tenant to tenant migration: moving configuration
An Intune tenant to tenant migration moves configuration by recreating it in the target tenant, because Intune has no built-in transfer. Microsoft's own guidance uses Graph sample scripts that cover some policies, warns that you will recreate others, and notes that compliance policy assignments cannot be imported because group IDs differ between tenants. This guide covers what can be copied, what cannot, and a checklist for moving configuration with or without TenuVault.
At a glance
- Microsoft's migration scripts do not export and import every policy, such as certificate profiles.
- Assignments target group IDs, which are different in the new tenant, so they have to be recreated.
- Win32 and line-of-business apps need their original installer files in the target tenant.
- TenuVault MSP copies configuration to other connected tenants as unassigned items with their original names and the Default scope tag.
- Copying configuration does not move, enroll or re-enroll devices.
What Microsoft's migration guidance says
Microsoft documents that you can export and import some of your policies using Microsoft Graph and PowerShell. The same page sets clear expectations: the scripts do not export and import every policy, such as certificate profiles, you should expect to do more tasks than the scripts cover, and you will have to recreate some policies.
Two limits in Microsoft's export and import table shape every migration. Compliance policy assignments can be exported but not imported, because assignments are targeted to a group ID and the group ID is different in a new tenant. Win32 apps can be neither exported nor imported, and adding an app to a new tenant needs the original .intunewin source files.
Microsoft's export and import table goes type by type, so read it for the object types you use before you estimate the effort.
Plan the migration as three separate streams: configuration, which tools can copy; identities and groups, which live in Microsoft Entra; and devices, which have to be enrolled in the new tenant. This guide covers the first stream.
What TenuVault MSP copies and what it does not
TenuVault MSP can copy items from a backup of one connected tenant into one or more other connected tenants. The source tenant does not change. Copies use Create copies only, so replace in place and assignment restore are not available across tenants.
- If an item refers to an ID that cannot be resolved in the target, it is not created and the error names the unresolved paths.
- Service-wide identifiers such as setting definition and template IDs are the same in every tenant and need no mapping.
- Every tenant involved needs the MSP plan, a signed-in connection with its own app registration, and an Intune role that can create the copied types.
| Item | What TenuVault does | What you do |
|---|---|---|
| Policies, profiles, scripts and other supported types | Creates them in the target with original names and the Default scope tag | Review each copy and adjust scope tags |
| Assignments and exclusions | Never copied; every copy is unassigned | Recreate targeting for the target tenant's groups and filters |
| Groups | Not part of the backup | Create or migrate groups in Microsoft Entra |
| Scope tags, filters, roles, categories, notification templates, reusable settings | Copied first when selected in the same restore; later items are pointed to the new IDs | Select dependencies together with the items that use them |
| Apps and app categories that already exist in the target | Can be mapped from source ID to target ID, up to 100 mappings, one target tenant | Look up and confirm each target ID in the target tenant |
| Win32 and line-of-business app installers | Never downloaded, so never copied | Upload the installer in the target, then map the new app |
| Certificates with private keys, Apple tokens | Not exportable through Microsoft Graph | Upload or reissue them in the target tenant |
Step by step checklist
Use this checklist whichever tool moves the configuration. The TenuVault specific steps are marked by name.
- Inventory the source configuration and decide what to move. Retire stale policies instead of migrating them.
- Collect what a Graph-based backup cannot hold: app installers, certificates and private keys, and Apple enrollment tokens, plus any documents such as terms and conditions files. Android Enterprise enrollment profiles restore with a new token.
- Create or migrate the Entra groups, and record a mapping from each source group to its target group.
- Prepare the target tenant: licenses, Intune administrator roles and, for TenuVault, an app registration created with the setup script.
- Take a fresh, complete backup of the source tenant and review its log for skipped types.
- In TenuVault, connect both tenants, open the restore wizard on the source backup and review Recovery readiness for missing mappings and manual actions.
- Copy dependencies first, or select them in the same restore: scope tags, assignment filters, roles and categories.
- Upload installers in the target, then supply reviewed app mappings for a single target tenant.
- Copy the remaining configuration under Copy to other tenants instead, and check each result line.
- Review the copies in the target admin center, set scope tags and recreate assignments and exclusions for pilot groups first.
- Review Intune roles and their memberships separately so the copy does not grant access you did not intend.
- Enroll pilot devices in the target tenant, validate policy delivery, then widen the assignments.
Rebuild assignments deliberately
Because no tool can carry a source group ID into a new tenant, assignments are where migrations go wrong. A configuration copy that lands unassigned is the safe default: nothing reaches a device until you decide it should.
Work from a written map of source groups to target groups, including exclusion groups and assignment filters. Assign each policy to a pilot group first, check the result on a few enrolled devices, then add the production groups. Review Intune role assignments last and on their own, since copying a role definition is harmless but assigning it grants access.
- Export or record every assignment in the source tenant before you start.
- Recreate assignment filters in the target before you assign anything that uses them.
- Keep exclusions with the policies they protect; a missing exclusion can apply a restrictive policy to break-glass or kiosk devices.
- Assign compliance policies after their notification templates and actions are in place.
Other tools that support cross-tenant copies
Several free tools cover parts of this work. IntuneManagement can import into another tenant using a migration table and creates missing groups during import, including dynamic groups. IntuneCD is built around promoting configuration from a development tenant to production and matches objects by display name. Microsoft365DSC can clone a configuration to another tenant, though some tenant specific values must be replaced by hand. Compare their behavior on assignments and existing objects before you choose.
What a configuration migration does not do
Copying policies does not move devices. Devices must be enrolled in the target tenant through your chosen enrollment method, and nothing in a configuration backup enrolls or re-enrolls them. User data, Entra identities and licenses are separate workstreams.
Plan for new object IDs everywhere. Any script, report or documentation that refers to source tenant IDs needs updating, and assignments must be rebuilt for the target tenant's groups regardless of the tool you use.
Read the technical guides
Product scope reviewed . Check your installed release and the current plan table before using a workflow.
Frequently asked questions
Can Intune policies be moved to another tenant natively?+
Not with a built-in feature. Microsoft documents Graph and PowerShell sample scripts that export and import some policies, and states that you will have to recreate others, such as certificate profiles.
Do assignments transfer in an Intune tenant to tenant migration?+
Generally no. Assignments point to group IDs, and group IDs are different in the new tenant; Microsoft notes that compliance policy assignments cannot be imported for this reason. Recreate the groups and then rebuild the assignments in the target tenant.
Can Win32 apps be migrated between Intune tenants?+
Only with the original installer files. Microsoft notes that adding the app to a new tenant needs the original .intunewin source files, and Intune does not let apps download installer files, so TenuVault does not save them.
Which TenuVault plan supports copying configuration between tenants?+
MSP. Copy to other tenants instead requires the MSP plan on the source tenant and on every target tenant, and each tenant must be connected and signed in.
Are copies created by TenuVault in the target tenant assigned?+
No. Cross-tenant copies keep their original names, get the Default scope tag and are never assigned. You review them and assign them to the target tenant's groups.
Does copying Intune configuration migrate devices?+
No. A configuration copy recreates policies and other objects. Devices still have to be enrolled in the target tenant through a separate process.