Troubleshooting Microsoft Entra ID to Microsoft Entra ID Device Migrations
General troubleshooting guidance for Microsoft Entra ID (Azure AD) to Microsoft Entra ID device migrations using Cloudiway. The procedure to follow depends primarily on which phase of the migration failed.
Before you change anything on the device
Overview
During a device migration, the Cloudiway Migration Agent performs multiple operations to transition the device from the source Microsoft Entra ID tenant to the target tenant.
If a migration fails, identifying the exact migration phase is important because the recovery procedure differs depending on the current state of the device — whether it is still joined to the source tenant, already joined to the target tenant, or joined to neither.
The general troubleshooting flow
Step 1 — Review the Cloudiway migration logs
Before performing any troubleshooting on the device, review the migration logs in the Cloudiway portal. Identify the last successful operation and determine whether the migration failed:
- •Before the first reboot
- •After the first reboot — see Scenario 1
- •After the second reboot — see Scenario 2
The logs provide important information about what Cloudiway was attempting to perform when the migration stopped.
Reference — migration phases and log messages
Once you have identified the migration phase, follow the appropriate section below.
Scenario 1 — Migration failed after the first reboot
If the migration fails after the first reboot, the device may still be connected to the source tenant, or may have been disconnected from the source tenant without successfully completing the next migration phase.
Step 1 — Log in with the Cloudiway local administrator account
Attempt to log in to the affected device using the local administrator account created by the Cloudiway Migration Agent. This account is created during the migration process to provide administrative access to the device if the source or target user's credentials cannot be used.
Once logged in, verify the current Microsoft Entra ID registration status of the device.
Step 2 — Check the current tenant connection
Open Command Prompt as Administrator and run:
dsregcmd /status Review the output, particularly the Device State section. For a Microsoft Entra ID joined device, you would normally expect to see information such as:
AzureAdJoined : YES Also review the tenant information to determine whether the device is currently associated with the source tenant or the target tenant. Based on the result, proceed with the appropriate scenario below.
Scenario 1A — Device is still connected to the source tenant
If the device is still correctly connected to the source Microsoft Entra ID tenant, the migration can generally be attempted again. Perform the following steps:
- Log in to the device.
- Verify that the device is correctly connected to the source tenant.
- Verify that the Cloudiway Migration Agent is installed and running correctly.
- Re-run the Cloudiway Migration Agent if required.
- Restart the device migration from the Cloudiway portal.
- Monitor the migration logs for any errors.
If the same error occurs again
Scenario 1B — Device is not connected to either tenant
If dsregcmd /status or the Windows account configuration
shows that the device is no longer connected to either the source or target Microsoft Entra ID tenant, the
device should first be returned to a valid source state. Perform the following steps:
- Log in using the Cloudiway local administrator account.
- Verify that the device is not currently joined to either tenant.
- Reconnect the device to the source Microsoft Entra ID tenant.
- Verify that the source tenant connection is successful.
- Confirm the device appears correctly in the source Microsoft Entra ID tenant.
- Re-run the Cloudiway Migration Agent.
- Restart the migration from the Cloudiway portal.
- Monitor the migration logs.
Do not restart the migration from an unknown state
Scenario 2 — Migration failed after the second reboot
A different troubleshooting approach should be followed when the migration fails after the second reboot, particularly when the user cannot log in using either:
- •The source user's credentials, or
- •The target user's credentials.
At this stage, it is important to determine whether the device was successfully added to the target tenant during the migration.
Step 1 — Check the target Microsoft Entra ID audit logs
Sign in to the target Microsoft Entra admin center and review the device audit logs. Navigate to:
Microsoft Entra admin center → Devices → Audit Logs
Search for events related to the affected device around the time the migration was performed. Look for events indicating that the device was:
The objective is to determine whether Cloudiway successfully added the device to the target tenant before the failure occurred.
Scenario 2A — Device was never added to the target tenant
If there is no indication in the target Microsoft Entra ID logs that the device was successfully added, review the Cloudiway migration logs for the registration/join failure. Potential areas to investigate include:
- •Migration/package account configuration
- •Authentication failures
- •Microsoft Entra ID permissions
- •Device enrollment restrictions
- •Intune enrollment restrictions
- •Conditional Access requirements
- •MFA requirements
- •Target tenant device configuration
Resolve first, retry after
Scenario 2B — Device was added and subsequently removed
If the Microsoft Entra ID audit logs confirm that the device was successfully added to the target tenant but was later deleted or removed, this indicates that the target registration initially succeeded.
In this situation, investigate the target Microsoft environment to determine what caused the device to be removed. Review configurations such as:
- •Microsoft Intune device enrollment policies
- •Device compliance policies
- •Conditional Access policies
- •Microsoft Entra ID device restrictions
- •Automated device cleanup policies
- •Enrollment limits
- •User/device licensing
- •Security policies affecting newly registered devices
The Microsoft Entra ID audit logs should be used to identify the operation and, where available, the service or account responsible for removing the device.
When to escalate
Recover the device after identifying the root cause
Once the underlying issue has been identified and corrected, attempt to access the affected device using the Cloudiway local administrator account.
If the device is currently disconnected from both tenants and the migration had already progressed to the target registration phase, you may need to manually connect the device to the target Microsoft Entra ID tenant.
After connecting the device
- Verify that the device appears in the target Microsoft Entra ID tenant.
- Confirm that the device remains registered and is not automatically removed.
- Check the device status using
dsregcmd /status. - Verify the expected Microsoft Entra ID join state.
- Confirm that the target user can log in successfully.
- Verify that applicable Intune and compliance policies are being applied correctly.
Troubleshooting decision tree
Use the following flow to quickly determine the appropriate troubleshooting procedure.
Migration failed
↓
Check Cloudiway migration logs
↓
Failed after the FIRST reboot?
→ Log in using the Cloudiway local administrator account
→ Run dsregcmd /status
→ Determine the current tenant connection
│
├─ Device still connected to source
│ → Verify source connection
│ → Re-run Cloudiway Migration Agent
│ → Restart migration
│
└─ Device connected to neither tenant
→ Log in using Cloudiway local administrator
→ Reconnect device to source tenant
→ Verify source registration
→ Re-run Cloudiway Migration Agent
→ Restart migration
Failed after the SECOND reboot?
→ Review target Microsoft Entra ID Audit Logs
│
├─ Device was never added to target
│ → Review Cloudiway logs
│ → Check authentication/account configuration
│ → Check enrollment restrictions and target tenant policies
│ → Correct the underlying issue before retrying
│
└─ Device was added and later removed
→ Cloudiway successfully completed the target join operation
→ Review Microsoft Entra ID/Intune logs and policies
→ Determine why the device was removed
→ Correct the target tenant configuration
→ Log in using the Cloudiway local administrator account
→ Manually connect the device to the target tenant if required Information to collect before contacting Cloudiway Support
If the issue persists after performing the above troubleshooting, collect the following information before opening or updating a Cloudiway Support ticket:
- •Device name
- •Source user
- •Target user
- •Approximate migration date and time
- •Migration phase where the failure occurred
- •Complete Cloudiway migration error
- •Screenshot of the latest migration logs
- •Output/status from
dsregcmd /status - •Whether the device is currently connected to the source, target, or neither tenant
- •Whether login using the Cloudiway local administrator account is possible
- •Screenshot/details from the target Microsoft Entra ID audit logs
- •Confirmation whether the device was ever successfully added to the target tenant
Providing this information will help the Support team identify the migration state and determine the appropriate next troubleshooting steps.
Important considerations
Do not assume a missing device means the target join failed
If the device is currently missing from the target tenant, always review the Microsoft Entra ID audit logs. The device may have been successfully added during migration and subsequently removed by a policy or process within the target environment.
If the audit logs confirm that the device was successfully added to the target tenant, this is important information when determining whether the issue occurred during the Cloudiway migration process or afterward within the Microsoft environment.
Review target tenant policies
Microsoft Entra ID, Intune, Conditional Access, compliance, and enrollment policies are controlled by the customer environment. If the device was successfully added by Cloudiway and subsequently removed or blocked by one of these policies, the applicable Microsoft 365 / Intune administrator should investigate and correct the policy.
Avoid repeated migration attempts without identifying the failure
Repeatedly restarting a device migration without first determining the current device state may make troubleshooting more difficult.
Always: Review logs → Determine device state → Resolve root cause → Retry/recover
References
For additional information, refer to the following Cloudiway Help Center articles: