The problem
After an acquisition, the parent company had to absorb an entire Azure tenant: subscriptions, identities, workloads, runbooks, and mailboxes. The legacy tenant had been built clickwise: Logic Apps, Storage Accounts, SQL resources, and runbooks all configured through the portal with no IaC representation. The cutover needed to be fast, auditable, and reversible.
The approach
I led the architecture and execution end-to-end. PowerShell drove the inventory and identity work. An Azure-to-Terraform export utility scaffolded the legacy resources into Terraform definitions, which were then refactored, reviewed, and applied against the parent tenant. Every resource that had been portal-built came across as code.
New provisioning in the destination tenant, including Logic Apps, Storage Accounts, SQL, and runbooks, went straight into Terraform from the start. No more portal configurations to import later.
Identity work ran in parallel: tenant-to-tenant migration of users and groups, with Microsoft Graph queries to verify policy coverage and find orphaned resources before cutover.
The outcome
The cutover ran on schedule with the new infrastructure fully under IaC. The portal-clicking habit died with the migration. Every subsequent change went through PR review.