Thank you for your post and I apologize for the delayed response!
I understand that you currently have an on-prem domain abc.com
and plan to move your users and devices to a new Azure AD tenant with a different domain name xyz.com
. After this move, you'd like to know if there's any possibility for the users and devices to access the resources from the previous tenant abc.com
. To hopefully help point you in the right direction or resolve your issue, I'll share my findings below.
Findings:
I wasn't able to find any information on if this scenario is supported in the resource / forest model of Azure AD DS. However, when it comes to Azure AD DS, please keep in mind that it replicates identity information from Azure AD, so it works with Azure AD tenants that are cloud-only or synchronized with an on-premises AD DS environment. For more info.
When it comes to your users and devices in tenant xyz.com
accessing all the resources from abc.com
, this should be possible through the use of cross-tenant synchronization.
Cross-tenant synchronization automates creating, updating, and deleting B2B collaboration users. Users created with cross-tenant synchronization are able to access both Microsoft applications (such as Teams and SharePoint) and non-Microsoft applications (such as ServiceNow, Adobe, and many more), regardless of which tenant the apps are integrated with.
I hope this helps!
If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.