When a leading healthcare provider needed regional separation inside Microsoft 365, Kocho delivered it without forcing a tenant split. Identity, data residency, collaboration controls and application readiness were brought together in one programme that kept the wider environment intact.
At a glance:
- Regional users transitioned to a local domain within the existing Microsoft 365 tenant.
- Regional user data aligned to local datacentres through Microsoft 365 Multi-Geo and Preferred Data Location settings.
- Restrictions introduced to prevent data from different regions from being accessed, moved or combined unintentionally while remaining in the same tenant.
- Identity changes, collaboration controls, application remediation and Information Barriers delivered as one programme to make the separation work in practice.
Regional separation without a tenant split
Following a wider international business change, one regional user population needed to move to a local domain, their data needed to remain in local datacentres, and controls were required to keep regional data, access and collaboration appropriately separated.
That included preventing information from being accessed, moved or combined unintentionally, and using Information Barriers to stop unmoderated cross-region interactions that could create conflicts of interest.
That had to happen inside the existing Microsoft 365 tenant. The organisation wanted regional separation without the cost, duplication and disruption of building a second environment.
Kocho was engaged to make that work.
The requirement was to create effective separation inside the environment, including controls over collaboration, while keeping the wider business on one Microsoft 365 estate.
Building separation into the platform
Kocho began with discovery workshops to confirm the regional user population, validate residency and access requirements, and identify exceptions that would need controlled handling.
That shaped a delivery plan built around identity, data location, collaboration controls and application readiness.
Identity aligned to region
Regional users were moved to a local domain structure, with Entra ID, Exchange and related identity mappings updated so authentication and directory behaviour stayed aligned.
Kocho also assessed application dependencies in advance, defining remediation paths before the switch where UPN changes could affect access.
Data placed where it needed to be
Kocho then used Microsoft 365 Multi-Geo and Preferred Data Location settings to place Exchange, OneDrive, SharePoint and Microsoft 365 Group data in the required regional datacentres.
From there, Information Barriers were applied to restrict sharing and collaboration between regional user groups inside the same tenant.
Exceptions handled without weakening control
The design also had to support controlled exceptions.
Some teams still needed carefully governed cross-region access, so Kocho built exception handling into the Information Barrier model to reflect how the business actually operates.
That included ensuring moderated Teams meetings could still take place where needed, including town halls and selected third-party meetings, without weakening the wider control framework.
What Kocho delivered
Kocho brought the programme together as one coordinated piece of delivery, covering the changes needed across identity, data residency, collaboration controls and migration readiness.
Outcomes
The result was a Microsoft 365 environment that reflected the organisation’s regional requirements without forcing the business into a second tenant.
- Regional users transitioned to a local domain inside the existing Microsoft 365 tenant
- Exchange, OneDrive, SharePoint and Microsoft 365 Group data aligned to the required regional datacentres
- Controls introduced to keep regional data separate across access, sharing and discoverability
- Application impacts identified ahead of migration, reducing disruption at go-live
- A unified Microsoft 365 environment retained across the wider business
A model for regional control inside Microsoft 365
Many organisations now face regional requirements around data location, access and governance while still relying on shared Microsoft 365 environments. This project shows what can be achieved when those requirements are handled through careful design rather than duplication.
For this healthcare provider, that meant regional separation without fragmenting the wider estate. For Kocho, it demonstrated the ability to combine identity, data residency, collaboration controls and delivery discipline into one coherent Microsoft 365 programme.
Secure Business Change
Change the business, not your security standards
Secure identity, data and collaboration through mergers, regional expansion and business transformation.