- Joined
- May 21, 2026
- Messages
- 4
- Reaction score
- 0
Title: Disabling Multi-Company Mode with one live tenant and one pre-launch — what should I be watching for?
Body:
Looking for experience from anyone who's flipped Multi-Company Mode off on a system that wasn't symmetrical between tenants.
Our setup: shared 3CX instance for us and a sister company. We're currently in Multi-Company Mode (multi-tenant). One of the two companies is live and in daily production use — extensions, queues, DIDs, recordings, the works. The other is configured but hasn't gone live yet, so it's still malleable.
The problem MCM is creating for us is the tenant isolation itself. Staff at the two entities need to transfer calls between departments and see each other for BLF/directory purposes, and that's exactly what multi-tenant is designed to prevent. Per 3CX's own docs, tenants in MCM cannot communicate with each other, which is the opposite of what we need. A dedicated-instance-per-company split isn't on the table, so we're weighing switching back to single-tenant mode where departments are mutually visible and transferable.
Because only one side is live, my risk surface is asymmetric and I want to make sure I'm thinking about it correctly:
Running v20, recent update. Both companies are small (well within the SMB sweet spot MCM was designed for). The driver is purely the cross-entity collaboration requirement.
Any war stories appreciated, especially anything that wasn't on the official pre-switch checklist.
Body:
Looking for experience from anyone who's flipped Multi-Company Mode off on a system that wasn't symmetrical between tenants.
Our setup: shared 3CX instance for us and a sister company. We're currently in Multi-Company Mode (multi-tenant). One of the two companies is live and in daily production use — extensions, queues, DIDs, recordings, the works. The other is configured but hasn't gone live yet, so it's still malleable.
The problem MCM is creating for us is the tenant isolation itself. Staff at the two entities need to transfer calls between departments and see each other for BLF/directory purposes, and that's exactly what multi-tenant is designed to prevent. Per 3CX's own docs, tenants in MCM cannot communicate with each other, which is the opposite of what we need. A dedicated-instance-per-company split isn't on the table, so we're weighing switching back to single-tenant mode where departments are mutually visible and transferable.
Because only one side is live, my risk surface is asymmetric and I want to make sure I'm thinking about it correctly:
- The live tenant is where any fallout actually hurts. Extensions, DIDs, recordings, voicemail, queue history, integrations — all real. The pre-launch tenant I can rebuild or reconfigure freely. So my main question is: what survives the switch cleanly on the live side, and what gets re-scoped or orphaned? Specifically I'd want recordings, voicemail, call history, and DID-to-extension mappings to come through untouched.
- One-user-one-department enforcement goes away. Has anyone seen the View-tab permissions or department assignments get into a weird state after switching back, where users technically work but admins have to clean up stale scoping?
- Extension ranges. The live tenant's range is set in stone for obvious reasons. Once we drop MCM, can I just treat the pre-launch tenant's range as a normal department range and build into it, or are there artifacts from the ranges having been tenant-bound that cause issues later (auto-provisioning, dial plan, etc.)?
- Per-tenant phonebooks and company prompts. The live tenant has its own. What happens to them on the way back to single-tenant — merged into the main company phonebook, demoted to a department phonebook, or lost?
- Group Owner roles on the live tenant. If we've delegated any management to a Group Owner scoped to that tenant, does that role degrade gracefully or do those users effectively lose their elevated access?
- Integrations. MCM blocks CRM, M365, and Teams integrations, so they're off today. Once we flip back, re-enabling those against a live tenant — any gotchas with users having been provisioned under MCM rules first?
- The privacy conversation. Single-tenant means the not-yet-live company's users will be visible to the live company's users in chat, BLF, and phonebook search the moment they're added. That's actually what we want, but I'd like to hear from anyone who's done this whether anything leaked that shouldn't have — call recordings, voicemail, reports becoming visible to admins who previously couldn't see them, etc.
- Sequencing. Does it matter whether we flip MCM off before or after building out the second company? Instinct says do the switch first while the pre-launch side is still empty (less to migrate, less to clean up), then build the second company as a normal department in single-tenant mode from scratch. But I'd love a sanity check from someone who's done it either way.
- Rollback realism. Docs say you can switch back to MCM at any time. On a system with one live tenant, has anyone actually round-tripped it and had the live side come out unscathed?
Running v20, recent update. Both companies are small (well within the SMB sweet spot MCM was designed for). The driver is purely the cross-entity collaboration requirement.
Any war stories appreciated, especially anything that wasn't on the official pre-switch checklist.
Last edited: