Regional Data Separation in Microsoft 365 Without a Tenant Split
Skip to content
Lines overlay image

How a healthcare provider kept regional data local in Microsoft 365

When a leading healthcare provider needed regional separation inside Microsoft 365, Kocho delivered it without forcing a tenant split. Identity, data residency, collaboration controls and application readiness were brought together in one programme that kept the wider environment intact.

At a glance:

  • Regional users transitioned to a local domain within the existing Microsoft 365 tenant.
  • Regional user data aligned to local datacentres through Microsoft 365 Multi-Geo and Preferred Data Location settings.
  • Restrictions introduced to prevent data from different regions from being accessed, moved or combined unintentionally while remaining in the same tenant.
  • Identity changes, collaboration controls, application remediation and Information Barriers delivered as one programme to make the separation work in practice.

Regional separation without a tenant split

Following a wider international business change, one regional user population needed to move to a local domain, their data needed to remain in local datacentres, and controls were required to keep regional data, access and collaboration appropriately separated.

That included preventing information from being accessed, moved or combined unintentionally, and using Information Barriers to stop unmoderated cross-region interactions that could create conflicts of interest.

That had to happen inside the existing Microsoft 365 tenant. The organisation wanted regional separation without the cost, duplication and disruption of building a second environment.

Kocho was engaged to make that work.

quote icon

The requirement was to create effective separation inside the environment, including controls over collaboration, while keeping the wider business on one Microsoft 365 estate.

Alex Kingston, Senior Consultant, Kocho

Building separation into the platform

Kocho began with discovery workshops to confirm the regional user population, validate residency and access requirements, and identify exceptions that would need controlled handling.

That shaped a delivery plan built around identity, data location, collaboration controls and application readiness.

Identity aligned to region

Regional users were moved to a local domain structure, with Entra ID, Exchange and related identity mappings updated so authentication and directory behaviour stayed aligned.

Kocho also assessed application dependencies in advance, defining remediation paths before the switch where UPN changes could affect access.

Data placed where it needed to be

Kocho then used Microsoft 365 Multi-Geo and Preferred Data Location settings to place Exchange, OneDrive, SharePoint and Microsoft 365 Group data in the required regional datacentres.

From there, Information Barriers were applied to restrict sharing and collaboration between regional user groups inside the same tenant.

Exceptions handled without weakening control

The design also had to support controlled exceptions.

Some teams still needed carefully governed cross-region access, so Kocho built exception handling into the Information Barrier model to reflect how the business actually operates.

That included ensuring moderated Teams meetings could still take place where needed, including town halls and selected third-party meetings, without weakening the wider control framework.

What Kocho delivered

Kocho brought the programme together as one coordinated piece of delivery, covering the changes needed across identity, data residency, collaboration controls and migration readiness.

Ebony and green lightbulb inside head on transparent background

Discovery and design for regional separation inside a shared tenant.

Ebony and green person with lines icon on transparent background.

Local domain and identity alignment for in-scope users.

Application impact assessment and remediation planning.

Ebony and green tick shield and globe icon on transparent background

Multi-Geo and Preferred Data Location configuration for regional data residency.

Ebony and green file padlock icon on transparent background

Information Barriers to restrict cross-region access and sharing.

Ebony and green shield tick and motion arrows icon on transparent background

Pilot testing, staged migration, go-live support and validation.

Outcomes

The result was a Microsoft 365 environment that reflected the organisation’s regional requirements without forcing the business into a second tenant.

  • Regional users transitioned to a local domain inside the existing Microsoft 365 tenant
  • Exchange, OneDrive, SharePoint and Microsoft 365 Group data aligned to the required regional datacentres
  • Controls introduced to keep regional data separate across access, sharing and discoverability
  • Application impacts identified ahead of migration, reducing disruption at go-live
  • A unified Microsoft 365 environment retained across the wider business

A model for regional control inside Microsoft 365

Many organisations now face regional requirements around data location, access and governance while still relying on shared Microsoft 365 environments. This project shows what can be achieved when those requirements are handled through careful design rather than duplication.

For this healthcare provider, that meant regional separation without fragmenting the wider estate. For Kocho, it demonstrated the ability to combine identity, data residency, collaboration controls and delivery discipline into one coherent Microsoft 365 programme.

Wide angle shot of two people in canoe paddling away
tag icon

Secure Business Change

Change the business, not your security standards

Secure identity, data and collaboration through mergers, regional expansion and business transformation.