SOLVED

Azure subscription transfer

%3CLINGO-SUB%20id%3D%22lingo-sub-3326752%22%20slang%3D%22en-US%22%3EAzure%20subscription%20transfer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3326752%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20transfer%20an%20existing%20subscription%20to%20a%20new%20AAD%20(Azure%20Active%20Directory)%20tenant.%20When%20am%20going%20to%20transfer%20it%20all%20Roll-Based-Access-Control%20(RBAC)%20roll%20assignments%20will%20be%20deleted%20from%20the%20source%20tenant.%20So%20my%20question%20is%2C%20do%20we%20need%20to%20re-assign%20the%26nbsp%3B%20access%20for%20each%3F%20or%20is%20there%20any%20other%20way%20to%20transfer%20the%20AAD%20tenant%20with%20all%20RBAC%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3326752%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccessibility%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECommunity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENotifications%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3327440%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20subscription%20transfer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3327440%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1353695%22%20target%3D%22_blank%22%3E%40rangawickramasekara%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHello!%20You've%20posted%20your%20question%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Ftech-community-discussion%2Fbd-p%2FCommunityQuestions%22%20target%3D%22_blank%22%3ETech%20Community%20Discussion%20space%3C%2FA%3E%3CSPAN%3E%2C%20%3C%2FSPAN%3Ewhich%20is%20intended%20for%20discussion%20around%20the%20Tech%20Community%20website%20itself%2C%20not%20product%20questions.%20I'm%20moving%20your%20question%20to%20the%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-active-directory-identity%2Fbd-p%2FAzure-Active-Directory%22%20target%3D%22_self%22%3EAzure%20Active%20Directory%20space%3C%2FA%3E%20-%20please%20post%20Azure%20AD%20questions%20here%20in%20the%20future.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3329675%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20subscription%20transfer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3329675%22%20slang%3D%22en-US%22%3EThanks%20in%20advanced%20Eric!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3349344%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20subscription%20transfer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3349344%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1353695%22%20target%3D%22_blank%22%3E%40rangawickramasekara%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20are%20actually%20transferring%20your%20subscription%20to%20a%20different%20AAD%20tenant%2C%20not%20the%20other%20way%20around.%20Since%20there%20can%20only%20be%20one%20%22authoritative%22%20AAD%20directory%20per%20Azure%20subscription%2C%20it%20is%20not%20possible%20to%20transfer%20%22role%20assignments%22.%20What%20you%20could%20do%20instead%2C%20is%3A%3C%2FP%3E%3CUL%3E%3CLI%3Eexport%20current%20role%20assignments%20with%20'security%20principals'%20(users%2C%20groups%2C%20SPNs%2C%20MIs)%2C%20roles%2C%20and%20scopes%3C%2FLI%3E%3CLI%3Emap%20those%20original%20security%20principals%20with%20their%20%22representatives%22%20in%20the%20new%20tenant%3C%2FLI%3E%3CLI%3Eprepare%20a%20script%20(or%20a%20template)%20that%20will%20populate%20the%20RBAC%20with%20those%20role%20assignments%20as%20a%20bulk%20operation%20to%20minimize%20any%20disruptions%20this%20transfer%20may%20cause%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThere%20is%20a%20comprehensive%20guide%20about%20the%20transfer%20with%20recommended%20workflow%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Frole-based-access-control%2Ftransfer-subscription%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ETransfer%20an%20Azure%20subscription%20to%20a%20different%20Azure%20AD%20directory%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3357143%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20subscription%20transfer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3357143%22%20slang%3D%22en-US%22%3EThank%20you%20very%20much%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F44944%22%20target%3D%22_blank%22%3E%40David%3C%2FA%3E.%20I%20got%20the%20correct%20idea%20from%20your%20well%20explained%20answer.%20It%20was%20very%20supportive.%20Thanks%20again.%20%3Asmiling_face_with_smiling_eyes%3A%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3357799%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20subscription%20transfer%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3357799%22%20slang%3D%22en-US%22%3EI'm%20glad%20it%20helped.%20Will%20you%20please%20mark%20my%20response%20as%20the%20answer%3F%20Thx.%3C%2FLINGO-BODY%3E
New Contributor

Hi,

 

I can transfer an existing subscription to a new AAD (Azure Active Directory) tenant. When am going to transfer it all Roll-Based-Access-Control (RBAC) roll assignments will be deleted from the source tenant. So my question is, do we need to re-assign the  access for each? or is there any other way to transfer the AAD tenant with all RBAC?

5 Replies

@rangawickramasekara 

Hello! You've posted your question in the Tech Community Discussion space, which is intended for discussion around the Tech Community website itself, not product questions. I'm moving your question to the Azure Active Directory space - please post Azure AD questions here in the future. 

Thanks in advanced Eric!
best response confirmed by rangawickramasekara (New Contributor)
Solution

Hi @rangawickramasekara,

 

You are actually transferring your subscription to a different AAD tenant, not the other way around. Since there can only be one "authoritative" AAD directory per Azure subscription, it is not possible to transfer "role assignments". What you could do instead, is:

  • export current role assignments with 'security principals' (users, groups, SPNs, MIs), roles, and scopes
  • map those original security principals with their "representatives" in the new tenant
  • prepare a script (or a template) that will populate the RBAC with those role assignments as a bulk operation to minimize any disruptions this transfer may cause

There is a comprehensive guide about the transfer with recommended workflow: Transfer an Azure subscription to a different Azure AD directory | Microsoft Docs

 

Thank you very much @David. I got the correct idea from your well explained answer. It was very supportive. Thanks again. :smiling_face_with_smiling_eyes:
I'm glad it helped. Will you please mark my response as the answer? Thx.