In This Article
- The producers are the asset, and the cutover is the risk to the asset
- Three answers to "what happens to their tenant?"
- How the link works: four Microsoft 365 pieces
- Four things that happen before the link
- If you consolidate the Microsoft 365 tenants after the acquisition
- Records stay with whoever holds the obligation
- Where ABT fits
- Frequently Asked Questions
When one lender buys another lender's production team, the loan officers are the asset. Their pipelines, their referral partners, and the borrowers they have in flight are what the acquirer paid for. The technology cutover is the risk to that asset, and it's usually handled as a back-office task scheduled for a weekend.
A producer mid-pipeline doesn't care which Microsoft 365 tenant holds their mailbox. They care that their email history is there on Monday, that referral partners can still reach them, that their documents open, and that their laptop works. A conventional day-one cutover changes every one of those things at once: new account, new multifactor registration, rebuilt Outlook profile, re-synced OneDrive, laptop re-enrolled. It lands during the weeks when the producers are most likely to be recruited away.
There's a way to run this transition that changes nothing on the producer's desk on day one and leaves every end state open. Microsoft calls it by two names, Microsoft Entra cross-tenant synchronization and a multitenant organization in Microsoft 365. ABT, a Tier-1 Microsoft Cloud Solution Provider managing Microsoft 365 tenants for more than 750 financial institutions, has run it for lenders through recent acquisitions. This article covers what linking does, what has to happen before it, and what changes if you decide to consolidate later.
If you are three weeks from close, the next three lines are the article.
The short orientation
Who this is for: an executive, IT director, or integration lead at a mortgage lender, bank, or credit union that is acquiring another institution, or being acquired, where both companies run Microsoft 365.
What linking is: both tenants stay running. Microsoft Entra cross-tenant synchronization places each person in the other directory automatically, and a multitenant organization in Microsoft 365 makes those people members in Teams rather than guests. Everyone keeps signing in where they sign in today.
What to do first: baseline the acquired tenant's configuration with retention policies and holds documented; put a Windows LAPS local administrator credential on every managed device while it is still under current management; inventory existing guest accounts and every reference to the domain that will eventually move.
The producers are the asset, and the cutover is the risk to the asset
Acquisitions are back on the calendar for lenders, banks, and credit unions alike. The National Credit Union Administration (NCUA) approved 157 credit union mergers in 2025, and in KPMG's 2026 Banking Technology Survey, 77 percent of U.S. bank executives said technology is a primary driver or one of several key factors in their acquisition strategy. The same executives ranked cybersecurity and identity access management second among the biggest technology integration risks, at 55 percent, behind only the core banking platform. Where both institutions run Microsoft 365, each of those deals ends with two tenants and a decision about what to do with the second one, and identity is the part of that decision that lands on every employee's desk on day one.
In a retail lender acquisition, that decision has a clock on it. The producers who came across are on every competitor recruiter's list, and the weeks after close are when those calls land. Take away their mailbox, their laptop, or their sign-in for even a few days in that window and the producer starts returning the calls.
The producer opens a laptop that was re-enrolled over the weekend, signs in with a new user name, registers a new authenticator, waits for Outlook to rebuild against a moved mailbox, and re-syncs OneDrive. The old mailbox is gone from the source tenant. Referral partners replying to last week's thread reach an address that forwards or bounces. The help desk takes one call per producer, at minimum.
The producer opens the same laptop and signs in with the same user name, password, and authenticator. The entire email history is in the same mailbox, in the same folders. Files, calendar, and contacts are intact. They chat, call, and meet with colleagues at the acquiring company as members of the same organization. The help desk has a quiet morning.
That second Monday is the whole argument. Two companies operate as one from the first week while each keeps its own Microsoft 365 tenant running underneath. Nobody stops producing so the technology can be made tidy, and the integration risk those bank executives ranked second, identity and access, comes off the list before anyone's first Monday, because nobody's sign-in changes.
Producers get the attention because a retail acquisition is priced on them and they are the people recruiters call first. The same Monday holds for every underwriter, processor, closer, and support person who comes across: same laptop, same sign-in, same mailbox, and no week lost to a rebuilt profile.
The people are the asset. The transition is the risk to the asset. Link the tenants first, and the risk moves to a date you choose.
Three answers to "what happens to their tenant?"
There are three ways to answer the question, and only one of them keeps the other two available.
| Option | What the producer experiences | What it keeps open | The right choice when |
|---|---|---|---|
| Link the tenants and decide the end state later | Same laptop, same sign-in, same mailbox. Colleagues at the other company appear in Teams and people search as members. | Consolidate later, stay separate, or both over time | You want the producers working without interruption while the business settles |
| Cut over to the acquirer's tenant now | New account, new multifactor registration, rebuilt Outlook, re-synced OneDrive, laptop re-enrolled, all in the same week | One end state, on a fixed date | The acquirer needs a single tenant by a date and accepts the disruption as the price |
| Keep the acquired tenant permanently | Same as linking, indefinitely | Linking with the decision made in advance | The acquired brand, its licensing footprint, or its regulatory posture is worth keeping distinct |
Cutting over now is the conventional approach and the one most acquirers reach for first. It works, and it lands every change on every producer at once. Keeping the acquired tenant permanently is a legitimate end state, and it is the linked arrangement with the decision made in advance. Linking first makes the hard decision reversible and moves it to a moment when the acquirer has information rather than pressure. Our guide to Microsoft 365 tenant-to-tenant migration for credit union and bank mergers covers the consolidation cutover in detail. This article is about the step before it.
For an acquirer that buys more than once, the linked arrangement is worth more than one transition, and some keep it permanently. A parent company with several Microsoft 365 tenants under it can treat each acquisition on its own terms: one acquired company stays independent for a brand, a regulatory footprint, or terms the seller negotiated; another is absorbed at once; most start independent and merge when it suits the business. Licensing is sized per tenant. If a book of business is sold later, its tenant goes with it, data and all, as a hand-off rather than an extraction project. One architecture covers all of it, and the choice stays open on every deal.
How the link works: four Microsoft 365 pieces
Four supported Microsoft capabilities do the work. Each is named here the way Microsoft names it, so your technical reviewer can pull the documentation and check every claim.
Microsoft Entra cross-tenant synchronization
Keeps the two directories in step: each person in one tenant is created in the other automatically, kept updated, and removed when they leave. Cycles start every 40 minutes.
Multitenant organization in Microsoft 365
Tells Microsoft 365 the two tenants belong to one company. Synchronized people become members rather than guests, which is what Teams requires for chat, calls, and meetings across tenants.
Multitenant organization calendar sharing
A separate setting that shows free/busy time across the two companies. It runs on an Exchange Online organization relationship today, and both tenants have to switch it on.
Microsoft Entra ID P1
The license both capabilities depend on: one per synchronized user in their home tenant, and at least one in every tenant of the multitenant organization.
Cross-tenant synchronization is the directory link. Microsoft describes it as automating the creation, update, and deletion of business-to-business (B2B) collaboration users across the tenants in an organization. With automatic redemption switched on in both tenants, each person is provisioned into the other directory without an invitation email or a consent prompt. When a producer leaves either company, the synchronized account is removed on the next cycle, which makes the link an offboarding control rather than an offboarding liability. Each synchronized user needs a Microsoft Entra ID P1 license in their home tenant; check which of your existing plans already carry it, starting with our comparison of Microsoft 365 E3, E5, and Business Premium.
Everyone keeps authenticating against their own tenant. This is the sentence that makes the whole approach work, and Microsoft states it directly in the same document: cross-tenant synchronization isn't a migration tool, because the source tenant is required for synchronized users to authenticate. No mailbox or file is copied. Nothing is moved. The producer's password, multifactor method, and Conditional Access policies stay exactly where they are, which is why nothing changes for the user and why their mail and files stay put.
The multitenant organization is what makes the experience native rather than external. Microsoft provisions synchronized users as B2B collaboration users with a user type of member rather than guest, and Teams requires the member type. Microsoft's launch announcement describes calls, chats, and meetings across tenants without the barriers of meeting lobbies, with immediate access to meeting content, on the new Teams desktop client. One timing detail belongs in the project plan: Microsoft documents that it might take up to seven days for a synchronized user to appear in search, so the synchronization starts ahead of the date producers are given.
Calendar availability is its own switch. Free/busy across the two companies is a multitenant organization calendar setting that Microsoft's documentation says runs on organization relationships in Exchange Online and has to be switched on by both tenants. One wrinkle, current as of Microsoft's September 2026 documentation: Microsoft is replacing that mechanism with Microsoft 365 Cross-Tenant Access Policy because it depends on Exchange Web Services, which Microsoft is deprecating, and the replacement may not have reached your tenant yet. Build the calendar link on what your tenant supports today and plan the policy migration as part of managing the linked environment.
One constraint shapes who does the work. Microsoft doesn't allow a multitenant organization between a Cloud Solution Provider and its customer tenants. The two lenders form the organization with each other, and ABT configures both sides.
The link fails in the project plan before it fails in the tenant. The common miss is starting synchronization the week producers are given a date, which leaves people search still filling in when the first calls come. ABT starts it early, pilots from both companies, and treats the link as the standard first step for every deal an acquirer brings us. The first link is a project. The fifth is routine.
Four things that happen before the link
Each of these is ordinary work when it's done in advance and a problem when it's discovered afterwards. One of them has a closing window.
Three of the four can be done at any point before the link. The third can't wait, because it depends on management that's about to change hands.
The item with a closing window
Microsoft's guidance for unjoining a Microsoft Entra joined device says to make sure you have an offline local administrator account or create one, and to provide that account's credentials when the disconnect prompts for them. On a tenant hardened to ABT's M365 Guardian baseline, no user has that account, by design. Windows LAPS manages and rotates one and stores the password in Microsoft Entra ID, on the devices it reaches while the current management is still in place. In our experience, once management of the fleet changes hands, the credential that would have made a later move a ten-minute task is usually gone, and reprovisioning the device becomes the fallback. Our guide to risk-based device security with Microsoft Intune covers the baseline this sits inside.
With those four done, the link itself is a short configuration and pilot period. This is the order ABT follows on every linked-tenant engagement, and the order matters more than the speed.
If you consolidate the Microsoft 365 tenants after the acquisition
Microsoft's native cross-tenant mailbox migration and cross-tenant OneDrive migration move content, never identities, and both require the user to exist in the target tenant first. The mailbox move copies only user-visible content, the email, contacts, calendar, tasks, and notes, and then deletes the source mailbox. Microsoft's wording is that under no circumstances is the source mailbox available, discoverable, or accessible in the source tenant afterwards. Any mailbox on any type of hold is blocked from moving at all, and the same block applies to a OneDrive account under a hold policy. Users rebuild their Outlook profile with a new user principal name and primary address on the other side.
For a regulated lender with multi-year record retention, both of those behaviors are close to disqualifying. A mortgage company that has been in business more than a few years has mailboxes on hold, and releasing a hold is a decision for counsel, never a migration convenience. The approach that fits is a copy-based migration that reads the source and leaves it intact and readable while the retention clocks run out. The source tenant becomes a read-only archive of record rather than a casualty of the move.
Devices are joined to a tenant, so consolidation means each laptop rejoins. Stage those rejoins in waves ahead of the cutover date, against identities created in the acquirer's tenant, so the day the business moves is a sign-in name change and nobody's machine is rebuilt the morning their mailbox changes. The domain-reference inventory is what lets the domain move on a scheduled window, because a domain can be verified in only one Microsoft Entra tenant at a time.
Records stay with whoever holds the obligation
Record retention obligations attach to the company that holds them. In an acquisition, some follow the loan files to the acquirer and some stay with the entity that originated them. Which is which is a question for counsel, and the answer determines how long the acquired tenant has to remain readable, whichever end state the acquirer chose.
Retention policies and holds are tenant configuration. A Microsoft Purview retention policy in the acquired tenant covers nothing in the acquirer's tenant, and the native migration carries user-visible content only, so the policies are rebuilt on the other side from the baseline captured before the link. That's the practical reason the baseline documents retention first. Our guide to Microsoft 365 data retention for financial institutions covers what a defensible policy set looks like.
Microsoft also supports retaining a former employee's mailbox as discoverable without a paid seat. Apply a Microsoft 365 retention policy to the mailbox, confirm the hold has taken effect, then delete the account. The mailbox becomes an inactive mailbox, its contents stay searchable and exportable by people with eDiscovery permissions, and Microsoft states that the Exchange Online license associated with the deleted account becomes available to assign to someone else. Two cautions from Microsoft's own documentation: apply the hold before the deletion, and use a retention policy rather than an eDiscovery case hold, because an inactive mailbox held only by a case is permanently deleted when the case closes. Searching those mailboxes is covered in our article on Microsoft Purview eDiscovery for financial institutions.
Producers keep producing because the link changes nothing on their desk. The link stays governed because each tenant keeps enforcing its own controls and the cross-tenant access settings, Conditional Access, and logging in both tenants are reviewed before it forms. And the records stay defensible when retention and holds are documented before anything moves and rebuilt from that record on the other side.
Where ABT fits
ABT manages Microsoft 365 tenants for more than 750 financial institutions as a Tier-1 Microsoft Cloud Solution Provider, and has run this transition pattern for lenders with thousands of users across multiple tenants under one parent. On one recent acquisition, the linked architecture is what let every producer keep working while the acquirer took its time on the end state.
The work starts with the baseline, because the retention and hold documentation is what the record-keeping plan depends on, and it includes the four pre-link items above. Cross-tenant synchronization and the multitenant organization are then stood up against both tenants with a pilot group from each company before any producer depends on them. ABT manages the linked environment for as long as the linking is in place: identity, mail flow, licensing, synchronization health, and security posture, with a monthly breakdown by organization so each side sees what belongs to it. When the acquirer decides, ABT runs the consolidation the same way, in waves, with the source left readable.
Acquiring a lender, or being acquired, with two Microsoft 365 tenants to reconcile?
Bring us the deal timeline and we will bring the pilot plan. ABT manages Microsoft 365 tenants for more than 750 banks, credit unions, and mortgage companies, and M365 Guardian keeps both tenants hardened and monitored for as long as they are linked. The first call covers the four pre-link items and which of your licenses already carry Microsoft Entra ID P1.
The short version
In a lender acquisition the producers are the asset and the cutover is the risk to the asset. Link the two Microsoft 365 tenants first with Microsoft Entra cross-tenant synchronization and a multitenant organization in Microsoft 365, so every producer keeps the same laptop, sign-in, and mailbox on day one. Before the link, baseline the configuration with retention and holds documented, inventory the guests and domain references, and put a Windows LAPS credential on every managed device while you still can. Consolidate later if you choose, with a copy-based migration that leaves the source readable.
Frequently Asked Questions
Linking keeps both tenants running and connects them. Microsoft Entra cross-tenant synchronization creates each person in the other directory automatically, and a multitenant organization in Microsoft 365 makes them members in Teams rather than guests. Everyone keeps authenticating against their own tenant, so nothing is copied or moved. Migration moves mailboxes, OneDrive content, and devices into one tenant; the other tenant is then retired or kept as a read-only archive of record, depending on the retention plan. Microsoft states that cross-tenant synchronization is not a migration tool, because the source tenant is required for synchronized users to authenticate.
No. They sign in with the same user name, password, and multifactor method they use today, on the same laptop, into the same mailbox. What changes is that colleagues at the other company appear in Teams and people search as members of the same organization, with chat, calls, and meetings across the two tenants. Microsoft documents that it can take up to seven days for a synchronized person to appear in search, so the synchronization is started before producers are given a date.
Microsoft Entra ID P1 or above. Each user synchronized with cross-tenant synchronization needs a Microsoft Entra ID P1 license in their home tenant, and the multitenant organization feature requires Microsoft Entra ID P1 or above in every tenant that joins it. Microsoft states that only one P1 license is required per employee per multitenant organization, and that the target tenant needs no additional license for the synchronization itself. Many Microsoft 365 plans already include Microsoft Entra ID P1, so check what you hold before buying.
Two of its documented behaviors are a problem for a regulated lender. Microsoft's native move deletes the source mailbox on success, so it is no longer available, discoverable, or accessible in the source tenant, and it blocks any mailbox that is on any type of hold. A lender with multi-year record retention has held mailboxes and needs the source to stay readable. A copy-based migration reads the source, leaves it intact, and keeps the release of a hold a decision for counsel rather than a step in a migration plan.