AgileAscend: Building and Hardening the Tenant

The tenant you migrate into matters more than how you get there.

AgileAscend moves identities, mailboxes, files, and Teams into a tenant that’s already provisioned and hardened, not one you fix after the fact. Every workstream is scoped and priced against what’s moving, not a flat estimate.

2M+

Identities Migrated and Consolidated 

5M+

Mailboxes

500M+

Files, Folders, and Permissions

Where Tenants Go Wrong

Each workstream is scoped independently against what’s in your environment, and lands in the GCC High equivalent:

  • Exchange Online Migration
  • OneDrive Migration
  • SharePoint Migration
  • Microsoft Teams Migration
  • Entra ID Identity Migration
  • Custom Domain Migration
  • Workstation Migration

The source environment isn’t a constraint with a properly discovered and architected migration plan. Multiple source platforms in one migration, like Google Workspace and on-premises Exchange server together, or a hybrid identity environment, get scoped for the added complexity they create.

Our Tenant Build and Hardening Framework

 1 

Tenant Provisioning and Identity

Deploy the new Entra ID tenant and Azure subscriptions the target environment needs. Establish the baseline identity structure and license plan before anything else moves.

 2

 Baseline Security Configuration

Configure MFA, Conditional Access, information protection, and device compliance policies. Validate the environment before cutover, not after. 

3 

Data and Workload Migration

Move mailboxes, files, and applications into the hardened tenant. Assess infrastructure across hybrid, on-premises, and cloud sources before anything is moved. 

4 

Security Hardening and Validation

Apply Zero Trust-aligned policies and align to whichever frameworks govern the environment: NIST 800-171, CMMC, ITAR, or FIPS, where applicable. Harden before and after cutover, not just during the move. 

5 

Handoff and Steady-State Readiness

Deliver documentation, a runbook, and a security baseline the organization can measure against going forward, so drift gets caught instead of accumulating unnoticed. 

When the Migration Is a Merger, Acquisition, or Divestiture

A merger or acquisition puts a deal timeline on top of a standard migration. Two (or more) organizations’ identities, mailboxes, and data need to become one environment on the deal’s schedule, not IT’s. Divestitures bring the added complexity of reluctance to allow discovery within the source environment. 

The framework above still applies. Three things have to be true before the combined organization can operate: 

One Identity, Not Two. One identity per person across formerly separate tenants: Entra ID, on-premises Active Directory, Google, GoDaddy. 

No Loss of Data. Mailboxes, files, apps, and security controls moved without losing data in transit. 

Compliant at Cutover. A compliance posture that holds the day the tenants merge, not one retrofitted afterward. CMMC, ITAR, FedRAMP High. 

Licensing doesn’t carry over automatically. Microsoft does not let you move a license from one tenant to another: existing Commercial licenses stay in the Commercial tenant and run until the end of their term, and the new GCC or GCC High environment gets its own licensing, sized for what your organization needs, not what exists now. The two environments don’t merge into one. Users can run in both at the same time, but those stay separate accounts with separate logins until the migration completes. 

Where compliance shapes the deal (CUI or sensitive IP held across the newly combined entities) that posture has to be correct the day the tenants merge, not reconstructed after. We build the controls into the migration and document them as we go, so the documentation an assessor will ask for already exists at cutover.

FAQ

What identity systems can you consolidate?

Entra ID, on-premises Active Directory, or both together. If you’re migrating off Google Workspace or moving your whole Commercial domain, Entra ID alone is usually simplest. If you need to keep a local Active Directory, we can run it alongside Entra ID. A technical discovery call confirms which fits your environment. 

CMMC, ITAR, DFARS, and FCI on one side, FedRAMP High, FIPS, and NIST SP 800-171 on the other, plus Executive Order 14028 requirements. We identify which ones apply to your organization rather than building against all of them by default. 

MFA and Conditional Access configuration, information protection labels and policies, security baseline policies, and alignment to whichever compliance frameworks apply to the environment. It’s the difference between a tenant that can receive data and a tenant that’s secure once data is in it. 

Typically 1 to 2 weeks, though the timeline is partly client-paced. We meet regularly for knowledge-transfer sessions to review configuration and settings for each major component, and how quickly those sessions happen affects the schedule. Migrating devices, users, and data is scheduled against a jointly developed cutover plan built to minimize disruption to your organization. 

Hardening and support beyond the migration itself run under a separate MSP agreement.

Before. A newly provisioned tenant has no security applied by default. Security configuration and hardening are built in as part of the initial setup, not added as cleanup once the migration is finished. 

Hardening and support beyond the migration itself run under a separate MSP agreement.

Tenant provisioning, security baseline and hardening, and the migration itself are typically grouped as one core service, though they can run in stages when that fits better. Larger scope changes, like Conditional Access redesign or a Purview buildout beyond the baseline, run as Planned Special Projects. 

Usually a newly built tenant, since starting from a clean, hardened baseline is more reliable than retrofitting security onto an existing environment. Migrating into an existing tenant is possible when the situation calls for it, and that gets scoped directly. 

Workstations are included, scoped as a five-device proof of concept. We migrate and configure those five, then train your IT team to handle the rest using the same process, rather than billing per device for every machine in your fleet. 

They don’t transfer between tenants. Commercial licenses stay in the Commercial tenant and run until the end of their term. The new GCC or GCC High environment is licensed separately, sized for what’s needed there. 

Yes, a planned cutover window. Mail moves into a sandbox during cutover, so messages sent or received in that window are retained, not lost; access is restored once validation completes. Desktop applications like Outlook or Word can take a few days longer to catch up, even after account and web access are already restored. 

The Tenant You Migrate Into Matters More Than How You Get There.

A migration that only moves data is half the job. Let’s talk about what building and hardening the target tenant looks like for your environment.