Moving to a new Microsoft tenant
When your organisation moves to a new Microsoft 365 tenant, or changes its email domain, every link between Vizito and Microsoft breaks at the same time: Teams notifications stop, the Entra ID synchronisation fails, the calendar integration no longer recognises your meetings, and colleagues who sign in with Microsoft cannot get in. Work through this checklist in order on the day of the migration.
Before the migration
- Note which of these you use. All of them are under “Account settings” > “Integration” in the Vizito backoffice: “MS Teams integration”, “Azure Synchronization”, “Meeting integration (iCal)” and the SAML settings.
- Make sure at least one Global admin can sign in with an email address and a password rather than with Microsoft, so you keep access to the backoffice while the sign in through Microsoft is broken. Add one under “Administration” > “Manage users” if needed. See User roles.
Teams notifications
- Under “Account settings” > “Integration”, in the “MS Teams integration” section, click “Delete”.
- In the old tenant, remove the consent for the Vizito enterprise application and uninstall the Vizito app from Teams. Both steps are described under “Removing Microsoft Teams integration” in Teams notifications.
- Wait five minutes for Microsoft to process the removal.
- Sign in to the backoffice as an administrator of the new tenant, click “Add to MS Teams” again and install the Vizito bot in a team of the new tenant.
- Check the email addresses of your hosts. Teams delivers a notification to the address of the host, so if the domain changed, every host needs their new address. See “Hosts and their email addresses” below.
Entra ID synchronisation
- Create a new app registration in the new tenant with the same permissions, and note the new Tenant ID, Client ID, Client secret and the Object ID of the group to synchronise. See Azure Synchronization.
- Under “Account settings” > “Integration” > “Azure Synchronization”, replace the four values and click “Save”.
- Click “Synchronize” and check that the status reads “Success”.
- Look at “Manage hosts” and “Manage users”. The synchronisation matches people on their email address, so an employee whose address changed from name@old-domain.com to name@new-domain.com is a new person to it: the old entry is removed and a new one created. Roles you set by hand on the old entries have to be set again.
Calendar integration
- Under “Meeting integration (iCal)”, click “Add domain”, add the new domain and verify it with the TXT record. See Calendar / Meeting integration.
- Delete the old domain once no meetings are organised from it any more. Visitors that were pre-registered before the migration stay as they are.
- Check that meeting@vizito.be is still an attendee of the recurring meetings that were migrated. Some migrations drop external attendees.
Sign in and user logins
- Sign in with Microsoft. A colleague who signs in with Microsoft is
identified by their email address, so after a change of address Vizito no
longer recognises them. You cannot change the address of an existing user:
“Email / login” is greyed out in “User details”, because it is the address
the user signs in with and where reset links go. What has to happen depends
on how the user was created:
- Users created by the Entra ID synchronisation are replaced for you. Once the synchronisation has run against the new tenant, it has added a user for each new address, with the role the synchronisation assigns, and removed the synchronised user with the old address.
- Users you added by hand have to be replaced one at a time. Under “Administration” > “Manage users”, click “Add” and create the user with the new address, the same “Role” and, where it applies, the same “Host CN”. Once the new user can sign in, open the old user and click “Delete”. The new user receives an email with a link to complete the registration. Deleting the old user signs that person out and removes their access; the visitor log stays as it is. You cannot delete your own user: sign in as your new user, or ask another administrator, to delete your old one. There is no way to replace several users at once, so with many users added by hand this takes time. If those colleagues are in a group that the Entra ID synchronisation synchronises as users, it adds their new user for you and only deleting the old one is left.
- SAML. Replace the “Entry Point” and the “Certificate” with the values of the new tenant, and add the new domain to the SAML domains. See Single Sign-On via SAML.
- Passwords. A password login is not affected by a tenant change, only by a change of email address. See Login and password problems.
Hosts and their email addresses
Hosts you keep by hand under “Manage hosts” keep their old email address until you change it, and notifications keep going to the old address. Change them one by one, or export the list, correct the addresses in the file and import it again. See Import hosts.
Something still not working after the checklist? Contact us through the chat in the backoffice or at info@vizito.eu, and mention the old and the new domain.