{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/",
        "slug": "dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/"
        },
        "title": "Treat an Azure subscription directory transfer as an identity rebuild",
        "summary": "Resolve role-loss and encryption-key dependencies before authorizing a subscription's Entra directory transfer.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:44+00:00",
        "modified_at": "2026-09-10T00:52:39+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Azure subscriptions being considered for transfer to another Microsoft Entra directory.",
        "dse_recommendation": "Require an approved identity reconstruction and key-dependency plan before any directory transfer.",
        "primary_source": {
            "name": "Transfer an Azure subscription to a different Microsoft Entra directory | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/role-based-access-control/transfer-subscription",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Transferring a subscription to another Entra directory permanently removes its source-directory Azure RBAC role assignments and custom roles; they do not transfer to the target directory. Microsoft warns that the original role assignments cannot be restored after the transfer.</p>\n<p>Microsoft also warns of potentially unrecoverable outcomes when encrypted resources depend on a key vault being transferred. Its impact list is not comprehensive, and some transfers require downtime. This is not a routine resource-group move. <a href=\"https://learn.microsoft.com/en-us/azure/role-based-access-control/transfer-subscription\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this as a pre-transfer stop check, not a complete transfer procedure. Inventory the subscription&#8217;s actual services and identities, and establish whether its subscription type supports changing directories before planning execution.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends an owner-approved reconstruction plan for required roles and identities, plus a separate assessment of every encryption-key dependency. Do not authorize the transfer while either inventory is incomplete. Require service owners to identify additional dependencies beyond the documentation&#8217;s examples, and agree on a maintenance and recovery plan appropriate to the actual workloads.</p>\n<h2>Verification</h2>\n<p>Before production approval, review exported role definitions and assignments, target identities, and the key-dependency map with their owners. Rehearse applicable service recovery in an isolated representative environment. Record unresolved dependencies as blockers rather than assuming a reverse directory change will restore the old authorization state.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/role-based-access-control/transfer-subscription\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Transfer an Azure subscription to a different Microsoft Entra directory</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nTransferring a subscription to another Entra directory permanently removes its source-directory Azure RBAC role assignments and custom roles; they do not transfer to the target directory. Microsoft warns that the original role assignments cannot be restored after the transfer.\nMicrosoft also warns of potentially unrecoverable outcomes when encrypted resources depend on a key vault being transferred. Its impact list is not comprehensive, and some transfers require downtime. This is not a routine resource-group move. Microsoft Learn.\nApplicability\nUse this as a pre-transfer stop check, not a complete transfer procedure. Inventory the subscription’s actual services and identities, and establish whether its subscription type supports changing directories before planning execution.\nDSE recommendation\nDSE recommends an owner-approved reconstruction plan for required roles and identities, plus a separate assessment of every encryption-key dependency. Do not authorize the transfer while either inventory is incomplete. Require service owners to identify additional dependencies beyond the documentation’s examples, and agree on a maintenance and recovery plan appropriate to the actual workloads.\nVerification\nBefore production approval, review exported role definitions and assignments, target identities, and the key-dependency map with their owners. Rehearse applicable service recovery in an isolated representative environment. Record unresolved dependencies as blockers rather than assuming a reverse directory change will restore the old authorization state.\nOfficial references\nMicrosoft Learn: Transfer an Azure subscription to a different Microsoft Entra directory. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nTransferring a subscription to another Entra directory permanently removes its source-directory Azure RBAC role assignments and custom roles; they do not transfer to the target directory. Microsoft warns that the original role assignments cannot be restored after the transfer.\n\nMicrosoft also warns of potentially unrecoverable outcomes when encrypted resources depend on a key vault being transferred. Its impact list is not comprehensive, and some transfers require downtime. This is not a routine resource-group move. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/role-based-access-control/transfer-subscription).\n\n## Applicability\n\nUse this as a pre-transfer stop check, not a complete transfer procedure. Inventory the subscription’s actual services and identities, and establish whether its subscription type supports changing directories before planning execution.\n\n## DSE recommendation\n\nDSE recommends an owner-approved reconstruction plan for required roles and identities, plus a separate assessment of every encryption-key dependency. Do not authorize the transfer while either inventory is incomplete. Require service owners to identify additional dependencies beyond the documentation’s examples, and agree on a maintenance and recovery plan appropriate to the actual workloads.\n\n## Verification\n\nBefore production approval, review exported role definitions and assignments, target identities, and the key-dependency map with their owners. Rehearse applicable service recovery in an isolated representative environment. Record unresolved dependencies as blockers rather than assuming a reverse directory change will restore the old authorization state.\n\n## Official references\n\n[Microsoft Learn: Transfer an Azure subscription to a different Microsoft Entra directory](https://learn.microsoft.com/en-us/azure/role-based-access-control/transfer-subscription). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Treat an Azure subscription directory transfer as an identity rebuild",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/",
                "headline": "Treat an Azure subscription directory transfer as an identity rebuild",
                "description": "Resolve role-loss and encryption-key dependencies before authorizing a subscription's Entra directory transfer.",
                "abstract": "Resolve role-loss and encryption-key dependencies before authorizing a subscription's Entra directory transfer.",
                "articleBody": "Source facts\nTransferring a subscription to another Entra directory permanently removes its source-directory Azure RBAC role assignments and custom roles; they do not transfer to the target directory. Microsoft warns that the original role assignments cannot be restored after the transfer.\nMicrosoft also warns of potentially unrecoverable outcomes when encrypted resources depend on a key vault being transferred. Its impact list is not comprehensive, and some transfers require downtime. This is not a routine resource-group move. Microsoft Learn.\nApplicability\nUse this as a pre-transfer stop check, not a complete transfer procedure. Inventory the subscription’s actual services and identities, and establish whether its subscription type supports changing directories before planning execution.\nDSE recommendation\nDSE recommends an owner-approved reconstruction plan for required roles and identities, plus a separate assessment of every encryption-key dependency. Do not authorize the transfer while either inventory is incomplete. Require service owners to identify additional dependencies beyond the documentation’s examples, and agree on a maintenance and recovery plan appropriate to the actual workloads.\nVerification\nBefore production approval, review exported role definitions and assignments, target identities, and the key-dependency map with their owners. Rehearse applicable service recovery in an isolated representative environment. Record unresolved dependencies as blockers rather than assuming a reverse directory change will restore the old authorization state.\nOfficial references\nMicrosoft Learn: Transfer an Azure subscription to a different Microsoft Entra directory. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:29:44+00:00",
                "dateModified": "2026-09-10T00:52:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Treat an Azure subscription directory transfer as an identity rebuild"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Transfer an Azure subscription to a different Microsoft Entra directory | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/role-based-access-control/transfer-subscription"
                }
            }
        ]
    }
}