Hi @Khushi , you can follow these steps and it should work well for your use case:
- Create a new tenant: This will provide a separate set of administrators, configurations, and resources.
- Migrate on-premises services: For your on-premises services like multi-forest design, account management, and GPO, you'll need to plan and execute a migration strategy to split these services between the two tenants.
- Configure cross-tenant access: Use External Identities cross-tenant access settings to manage collaboration between the two Azure AD organizations through B2B collaboration.
- Migrate cloud services: For cloud services like Exchange Online, M365 suite, and Intune MDM, you'll need to plan and execute a migration strategy to split these services between the two tenants.
- Implement Azure Lighthouse: For cross-tenant management of Azure resources, consider implementing Azure Lighthouse.
- Configure Azure AD B2B collaboration: Configure Azure AD B2B collaboration in the new tenant to allow only identities from the corporate environment to be onboarded using Azure B2B allow/deny lists.
- Identity isolation: If needed, consider identity isolation through multiple tenants for business-critical resources that require a highly defensive approach.
Please let me know if you have any questions and I can help you further.
If this answer helps you please mark "Accept Answer" so other users can reference it.
Thank you,
James