# Treat an Azure subscription directory transfer as an identity rebuild

> Resolve role-loss and encryption-key dependencies before authorizing a subscription's Entra directory transfer.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:44+00:00
- Modified: 2026-09-10T00:52:39+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Resolve role-loss and encryption-key dependencies before authorizing a subscription's Entra directory transfer.

## Potentially affected

Azure subscriptions being considered for transfer to another Microsoft Entra directory.

## DSE recommendation

Require an approved identity reconstruction and key-dependency plan before any directory transfer.

## Article

## Source facts

Transferring a subscription to another Entra directory permanently removes its source-directory Azure RBAC role assignments and custom roles; they do not transfer to the target directory. Microsoft warns that the original role assignments cannot be restored after the transfer.

Microsoft also warns of potentially unrecoverable outcomes when encrypted resources depend on a key vault being transferred. Its impact list is not comprehensive, and some transfers require downtime. This is not a routine resource-group move. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/role-based-access-control/transfer-subscription).

## Applicability

Use this as a pre-transfer stop check, not a complete transfer procedure. Inventory the subscription’s actual services and identities, and establish whether its subscription type supports changing directories before planning execution.

## DSE recommendation

DSE recommends an owner-approved reconstruction plan for required roles and identities, plus a separate assessment of every encryption-key dependency. Do not authorize the transfer while either inventory is incomplete. Require service owners to identify additional dependencies beyond the documentation’s examples, and agree on a maintenance and recovery plan appropriate to the actual workloads.

## Verification

Before production approval, review exported role definitions and assignments, target identities, and the key-dependency map with their owners. Rehearse applicable service recovery in an isolated representative environment. Record unresolved dependencies as blockers rather than assuming a reverse directory change will restore the old authorization state.

## Official references

[Microsoft Learn: Transfer an Azure subscription to a different Microsoft Entra directory](https://learn.microsoft.com/en-us/azure/role-based-access-control/transfer-subscription). Source retrieved September 9, 2026.

## Primary reference

- Name: Transfer an Azure subscription to a different Microsoft Entra directory | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/role-based-access-control/transfer-subscription
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat an Azure subscription directory transfer as an identity rebuild,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-132-treat-an-azure-subscription-directory-transfer-as-an-identity-rebuild/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
