Horizons Consulting

Microsoft Cloud, Security & AI Insights

Clear answers to common questions about Azure, Microsoft 365, cloud security, Copilot readiness, identity, endpoint management, and enterprise IT modernization.

What is the best way to handle identity migration during an M&A Microsoft 365 consolidation?

The best way to handle identity migration during an M&A Microsoft 365 consolidation is to start with a full identity and access assessment before moving users, mailboxes, groups, devices, or collaboration data. In many M&A projects, the technical migration is not the hardest part. The real challenge is understanding which users exist, how they authenticate, what they can access, and which legacy permissions should not be carried into the new environment.

A good identity migration plan should begin with discovery. Review both tenants, Active Directory, Microsoft Entra ID, guest accounts, admin roles, service accounts, distribution groups, Microsoft 365 Groups, Conditional Access policies, MFA settings, and third-party identity integrations. This helps identify duplicate accounts, stale users, unmanaged guests, and risky privileges before consolidation.

Next, create an identity mapping plan. Microsoft’s tenant-to-tenant migration guidance highlights identity mapping as an important part of cross-tenant migration planning, especially in merger and acquisition scenarios. Each user should have a clear source identity, target identity, mailbox plan, licensing plan, and access plan.

Organizations should also decide whether they need full tenant consolidation, staged coexistence, or a temporary cross-tenant collaboration model. In some M&A deals, it may be safer to maintain controlled separation for a period of time rather than rushing every identity into one tenant.

Security controls should be reviewed before cutover. This includes Conditional Access, privileged identity management, guest access, device compliance, and access to sensitive SharePoint, Teams, and OneDrive content. If these controls are not aligned, the merged environment may inherit old risks from both organizations.

In short, identity migration during M&A should not be treated as a simple user move. It should be handled as a security, governance, and business continuity project. The right approach is to assess first, map identities carefully, clean up risky access, plan coexistence, and then migrate in controlled phases.

Helpful References

Relevant FAQs