Giter Club home page Giter Club logo

azure-subscription-migration's Introduction

Azure Subscription Migration

Migrating an Azure subscription to a new Azure AD tenant can be a complex and time-consuming process that involves a lot of manual overhead.To simplify this process, this repository contains tools and reports that helps reduce the amount of manual overhead when migrating subscriptions to a new Azure AD Tenant.

Warning Please note that transferring an Azure subscription to another Azure AD Tenant can have significant impacts on your Azure resources. In some scenarios, transferring a subscription might require downtime to complete the process. Before proceeding with a transition, we strongly recommend that you develop a comprehensive plan for managing the impacts and risks associated.

Warning Many Azure services require security principals (identities) to operate. Please read the Microsoft migration article article that tries to cover most of the Azure services that depend heavily on security principals, but is not a comprehensive list.

Subscription Assessment

Deploy the Azure Monitor Workbook to view the resources that are impacted during the migration of a subscription to a different tenant. The workbook provides a live view of the resources impacted in the migration process across multiple subscriptions. The workbook is deployed per tenant and can be provisioned manually or using the provided terraform code.

Process Overview for the Subscription Migration

  1. Plan for the migration
  2. Prepare for the transfer
  3. Transfer the Azure subscription to a different directory
    1. Transfer billing ownership
      1. Microsoft Online Services Program (MOSP) - also referred to as pay-as-you-go, Azure subscription to another MOSP account. Transfer Documentation
      2. Enterprise Agreement (EA) customer, your enterprise administrator can transfer billing ownership of your subscriptions between accounts. EA Transfer Documentation
  4. Re-create resources in the target directory such as role assignments, custom roles, and managed identities

After the Subscription Transfer

  • It may take upwards of 20 minutes to view the subscription in the new directory
  • After the subscription shows in the destination tenant, it may take up to 30 minutes for the subscription to show in the default management group.
  • All RBAC assignments in the source tenant are removed from the subscription scope. In the destination tenant the subscription will inherit the user access administrator from the Root (Inherited) scope Elevated Access
  • The user who triggered the transfer will be assigned the classic administrator role.

azure-subscription-migration's People

Contributors

azferry avatar jerrywolff avatar

Stargazers

 avatar  avatar

Watchers

 avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.