Skip to content
Sunrise Digital Labs

Method

When one tenant holds several businesses

A single Microsoft 365 tenant containing more than one company is a common arrangement, and usually a deliberate one. It becomes a problem later, for reasons nobody could have acted on at the time.

The arrangement

Several distinct businesses run inside one Microsoft 365 tenant. They share a directory. They may share a domain, or hold their own domains inside somebody else’s tenant. Administrative control sits with whoever provisioned it.

This is often the right call when it is made. One tenant is cheaper than five. It is simpler to administer, licensing is easier to manage in one place, and for small businesses with no separate regulatory obligation there is no practical reason to pay for isolation nobody has asked for.

The arrangement holds for as long as those conditions hold.

What changes

It stops holding when one of the businesses stops resembling the others.

  • One of them grows, and needs security policy its neighbors do not want
  • One of them is acquired, and the buyer requires its own tenant
  • One of them takes on a compliance obligation — a customer contract, an insurer, a regulator — that requires a boundary the shared tenant cannot draw
  • One of them is sold, and the data has to leave with it
  • The relationship with the provider ends, and the tenant does not belong to the business sitting in it

None of these are failures of the original decision. They are changes in circumstance that the original decision was not required to anticipate.

What is actually shared

This is the part a reader can check against their own tenant, and it is where the real scope of a separation lives.

Identity

One directory holds every user from every business. Group membership, guest access and admin roles were granted inside that single scope. There is no attribute that reliably says which person belongs to which company unless someone maintained one deliberately.

Domains

A verified domain normally lives in one tenant only. Every domain in the shared tenant is anchored there, so none of them can move until they are released. Releasing one is a scheduled event, not a setting.

The security boundary

Conditional Access, sharing policy, retention and DLP apply at the tenant. One business cannot tighten its posture without applying that posture to companies it does not own. It also cannot loosen it.

Administrative reach

Global administrators can see everything. In a shared tenant that means administrators of one business, or of the provider, hold reach across all of them.

Data that has quietly commingled

Shared SharePoint sites, Teams with members from more than one company, documents sharing-linked across the boundary, a distribution group with mixed membership. This is the item that takes the longest to establish and the one most likely to be discovered late.

Licensing

Subscriptions were bought against one tenant. They do not transfer to a new one, and the replacement has to exist before anyone moves.

Why it does not simply split

Three states of a tenant separation. Before: one tenant holding Business A, B and C, with one directory and one security boundary. During: the shared tenant still running with B and C inside it while a new tenant is built alongside for Business A, and the domain is released and then claimed. After: Business A in its own tenant, and the shared tenant still live with B and C working in it.

A tenant cannot be divided. There is no operation that takes one Microsoft 365 tenant and returns two.

What actually happens is that a new tenant is built and one business is migrated into it — the same mechanics as any tenant-to-tenant move, with two constraints that a normal consolidation does not carry.

The first is that the source keeps running. The businesses left behind are not migrating and cannot be disrupted, so nothing can be switched off to make the move simpler.

The second is that the domain has to be released before it can be claimed. For the period between those two events, mail routing and sign-in are running on an arrangement that was designed rather than assumed.

What gets decided before anything moves

These are decisions rather than steps. Each one has to be settled before a date means anything.

Who owns the new tenant
Not a technical question. It determines who holds administrative access to the new environment, and who can grant or withdraw it later.
Which identities move, and under what address
Some people work for more than one of the businesses. Some accounts belong to systems rather than people.
What happens to shared content
A site used by two companies has to become one company's site, both companies' copies, or neither's. Each answer has a different cost, and the decision belongs to the businesses rather than to whoever runs the migration.
Which domain goes where
If the businesses have been sharing a domain, one of them needs a different one. That decision reaches email addresses, sign-in names, published links and anything authenticating against it.
What the provider keeps
Administrative access, backup, and the retention obligations attached to data that is about to sit somewhere else.

What tends to surface late

  • The applications nobody listed. A line-of-business system authenticating against the shared directory keeps working right up to the moment its users are in a different one.
  • The shared mailbox two companies both use. It has one home in the new arrangement, and somebody has to say which.
  • Retention and legal hold. Data under hold does not move freely, and the obligation does not disappear because the tenant did.
  • The domain nobody can release yet, because a service still depends on it.

Where this usually starts

Before a date is set, the useful thing is an inventory. Who is actually in the tenant, what each business depends on, what is shared, and what has to be true before anything moves.

That is a Microsoft 365 Readiness Assessment. For a shared tenant the parts that decide the separation are the estate inventory and the dependency map — who is actually in there, and what cannot move without something else moving first. You keep what it produces whether Sunrise runs the separation or another provider does.