Skip to main content

Practical guide

Intune tenant to tenant migration: moving configuration

An Intune tenant to tenant migration moves configuration by recreating it in the target tenant, because Intune has no built-in transfer. Microsoft's own guidance uses Graph sample scripts that cover some policies, warns that you will recreate others, and notes that compliance policy assignments cannot be imported because group IDs differ between tenants. This guide covers what can be copied, what cannot, and a checklist for moving configuration with or without TenuVault.

At a glance

  • Microsoft's migration scripts do not export and import every policy, such as certificate profiles.
  • Assignments target group IDs, which are different in the new tenant, so they have to be recreated.
  • Win32 and line-of-business apps need their original installer files in the target tenant.
  • TenuVault MSP copies configuration to other connected tenants as unassigned items with their original names and the Default scope tag.
  • Copying configuration does not move, enroll or re-enroll devices.

What Microsoft's migration guidance says

Microsoft documents that you can export and import some of your policies using Microsoft Graph and PowerShell. The same page sets clear expectations: the scripts do not export and import every policy, such as certificate profiles, you should expect to do more tasks than the scripts cover, and you will have to recreate some policies.

Two limits in Microsoft's export and import table shape every migration. Compliance policy assignments can be exported but not imported, because assignments are targeted to a group ID and the group ID is different in a new tenant. Win32 apps can be neither exported nor imported, and adding an app to a new tenant needs the original .intunewin source files.

Microsoft's export and import table goes type by type, so read it for the object types you use before you estimate the effort.

Plan the migration as three separate streams: configuration, which tools can copy; identities and groups, which live in Microsoft Entra; and devices, which have to be enrolled in the new tenant. This guide covers the first stream.

What TenuVault MSP copies and what it does not

TenuVault MSP can copy items from a backup of one connected tenant into one or more other connected tenants. The source tenant does not change. Copies use Create copies only, so replace in place and assignment restore are not available across tenants.

  • If an item refers to an ID that cannot be resolved in the target, it is not created and the error names the unresolved paths.
  • Service-wide identifiers such as setting definition and template IDs are the same in every tenant and need no mapping.
  • Every tenant involved needs the MSP plan, a signed-in connection with its own app registration, and an Intune role that can create the copied types.
Cross-tenant copy in TenuVault MSP
ItemWhat TenuVault doesWhat you do
Policies, profiles, scripts and other supported typesCreates them in the target with original names and the Default scope tagReview each copy and adjust scope tags
Assignments and exclusionsNever copied; every copy is unassignedRecreate targeting for the target tenant's groups and filters
GroupsNot part of the backupCreate or migrate groups in Microsoft Entra
Scope tags, filters, roles, categories, notification templates, reusable settingsCopied first when selected in the same restore; later items are pointed to the new IDsSelect dependencies together with the items that use them
Apps and app categories that already exist in the targetCan be mapped from source ID to target ID, up to 100 mappings, one target tenantLook up and confirm each target ID in the target tenant
Win32 and line-of-business app installersNever downloaded, so never copiedUpload the installer in the target, then map the new app
Certificates with private keys, Apple tokensNot exportable through Microsoft GraphUpload or reissue them in the target tenant

Step by step checklist

Use this checklist whichever tool moves the configuration. The TenuVault specific steps are marked by name.

  • Inventory the source configuration and decide what to move. Retire stale policies instead of migrating them.
  • Collect what a Graph-based backup cannot hold: app installers, certificates and private keys, and Apple enrollment tokens, plus any documents such as terms and conditions files. Android Enterprise enrollment profiles restore with a new token.
  • Create or migrate the Entra groups, and record a mapping from each source group to its target group.
  • Prepare the target tenant: licenses, Intune administrator roles and, for TenuVault, an app registration created with the setup script.
  • Take a fresh, complete backup of the source tenant and review its log for skipped types.
  • In TenuVault, connect both tenants, open the restore wizard on the source backup and review Recovery readiness for missing mappings and manual actions.
  • Copy dependencies first, or select them in the same restore: scope tags, assignment filters, roles and categories.
  • Upload installers in the target, then supply reviewed app mappings for a single target tenant.
  • Copy the remaining configuration under Copy to other tenants instead, and check each result line.
  • Review the copies in the target admin center, set scope tags and recreate assignments and exclusions for pilot groups first.
  • Review Intune roles and their memberships separately so the copy does not grant access you did not intend.
  • Enroll pilot devices in the target tenant, validate policy delivery, then widen the assignments.

Rebuild assignments deliberately

Because no tool can carry a source group ID into a new tenant, assignments are where migrations go wrong. A configuration copy that lands unassigned is the safe default: nothing reaches a device until you decide it should.

Work from a written map of source groups to target groups, including exclusion groups and assignment filters. Assign each policy to a pilot group first, check the result on a few enrolled devices, then add the production groups. Review Intune role assignments last and on their own, since copying a role definition is harmless but assigning it grants access.

  • Export or record every assignment in the source tenant before you start.
  • Recreate assignment filters in the target before you assign anything that uses them.
  • Keep exclusions with the policies they protect; a missing exclusion can apply a restrictive policy to break-glass or kiosk devices.
  • Assign compliance policies after their notification templates and actions are in place.

Other tools that support cross-tenant copies

Several free tools cover parts of this work. IntuneManagement can import into another tenant using a migration table and creates missing groups during import, including dynamic groups. IntuneCD is built around promoting configuration from a development tenant to production and matches objects by display name. Microsoft365DSC can clone a configuration to another tenant, though some tenant specific values must be replaced by hand. Compare their behavior on assignments and existing objects before you choose.

What a configuration migration does not do

Copying policies does not move devices. Devices must be enrolled in the target tenant through your chosen enrollment method, and nothing in a configuration backup enrolls or re-enrolls them. User data, Entra identities and licenses are separate workstreams.

Plan for new object IDs everywhere. Any script, report or documentation that refers to source tenant IDs needs updating, and assignments must be rebuilt for the target tenant's groups regardless of the tool you use.

Read the technical guides

Product scope reviewed . Check your installed release and the current plan table before using a workflow.

Frequently asked questions

Can Intune policies be moved to another tenant natively?

Not with a built-in feature. Microsoft documents Graph and PowerShell sample scripts that export and import some policies, and states that you will have to recreate others, such as certificate profiles.

Do assignments transfer in an Intune tenant to tenant migration?

Generally no. Assignments point to group IDs, and group IDs are different in the new tenant; Microsoft notes that compliance policy assignments cannot be imported for this reason. Recreate the groups and then rebuild the assignments in the target tenant.

Can Win32 apps be migrated between Intune tenants?

Only with the original installer files. Microsoft notes that adding the app to a new tenant needs the original .intunewin source files, and Intune does not let apps download installer files, so TenuVault does not save them.

Which TenuVault plan supports copying configuration between tenants?

MSP. Copy to other tenants instead requires the MSP plan on the source tenant and on every target tenant, and each tenant must be connected and signed in.

Are copies created by TenuVault in the target tenant assigned?

No. Cross-tenant copies keep their original names, get the Default scope tag and are never assigned. You review them and assign them to the target tenant's groups.

Does copying Intune configuration migrate devices?

No. A configuration copy recreates policies and other objects. Devices still have to be enrolled in the target tenant through a separate process.