Migrating to a new tenant; Offboarding Procedure

Brass Contributor

Hi All,

We are working through mergers, and as such have many tenant to tenant migrations to do (Azure, M365, etc.). As it pertains to Defender for Endpoint though... I am trying to determine what happens when we migrate PC's and the persons user account from one AD domain to another. If we have PCs onboarded in Defender for Endpoint, and then we join them to a new AD domain... both source and target domains are synced with AAD connect to thier respective tenants... Will I still need to run the offboarding script on these machines to clean up before they get onboarded to Defender for Endpoint in the new domain / tenant?
I guess what is throwing me is that the devices - to some degree - are showing in the Defender portal (security.microsoft.com) for both the source and target tenant. In the source is shows as onboarded, in the target it shows as "can be onboarded".

Thanks!

2 Replies
this product addresses this need:
Intune and laptop migration
https://cloudiway.com/solutions/intune-migration/
The supported migration method is a device reset. MDE onboarding to the new tenant can be part of it. Devices in the old MDE tenant will eventually become inactive and get cleaned up on the basis of data retention policy.