By Jim Ruder · July 21, 2026
COO, LeadThem Consulting
We migrated a 365-user semiconductor acquisition across tenants with one major complication: the source environment had Microsoft Purview sensitivity labels applied broadly, which meant AIP-encrypted mailboxes, OneDrive, Teams, and SharePoint all arrived encrypted. Add federal export-control obligations on engineering files and shared factory-floor PCs, and the migration became a three-front problem that most teams underestimate.
The real friction wasn't user count. It was the interaction between three constraints hitting simultaneously. Purview-encrypted OneDrive content tripled our expected sync windows because AIP payloads have to decrypt and re-encrypt across tenant boundaries. The ITAR file servers required exact permission fidelity, not approximations, or we'd create a compliance finding. And the factory floor didn't have per-user workstations, it had shift-shared PCs under a single login model, which made standard workstation cutover impossible.
Most migration partners treat those as three separate problems. We treated them as one sequence. We used Quest Secure Copy to migrate ITAR files with full NTFS permission fidelity, but only after mapping source security principals to their destination equivalents in a spreadsheet and getting compliance sign-off. We extended the OneDrive sync timeline to account for the 3x encryption overhead instead of pretending it wasn't there. And we worked with SCCM to reprovision the shared factory-floor PCs against the destination tenant without disrupting shifts. The identity layer moved through Quest Migrator Pro for Active Directory with SID history intact, so file permissions resolved correctly the moment users authenticated in the new tenant.
The full write-up covers the weekly timeline, why the Purview feature flag matters, how to prevent permission reversals on regulated files, and what we'd do differently on the next one. [Read the full case study: how we migrated a 365-user semiconductor acquisition with encrypted data and ITAR compliance intact →](https://leadthemconsulting.com/case-studies/semiconductor-acquisition-purview-encrypted)
#Microsoft365Migration#ActiveDirectory#SemiconductorIT#TenantToTenant
Full case study
Read the full case study →