Jump to content

Recommended Posts

Posted

As the title says. Has anyone ever done this or had to do this?

 

Its a full tenant migration.

 

Any 3rd party tools to consider? Processes, best practices?

 

Any guidance on this would be appreciated.

 

Thanks

Posted

I merged 6 tenants into 1 this summer. Used Codetwo o365 migration tool for emails (paid but very cheap and very easy to use).

 

Then use mover.io for OneDrive and SharePoint. (Free)

 

Couldn’t do teams without paying loads of money but as it was the summer we just started fresh with class teams

Posted

I've done projects total consideration of about 125k users. It sucks. MS don't care. There's MS tooling I think still in private preview but its poor

 

Check if there is a jarring differences in config between tenants, e.g. old tenants allow BYOD, new one doesnt.

 

3rd part Tooling is much-a-muchness especially around exchange. Much of teams is very poor to migrate, or not at all and if super important may sway a product decision

 

Depending on numbers and risk appetite determines how many people you can migrate at once,

 

You should consider reachback or reachforward (e.g. allowing migrated people guest access to old tenant to access not-yet-migrated resources). Try to avoid both! Figure out your identity approach and work from there.

For example three separate approaches I've used

 

1) Migrate a user then immediately delete their user account. Create a mail-enabled contact with the deleted users email addresses, forwarding to the migrated mailbox. This means that free/busy can still work and emails still get delivered. If group resources have not been migrated yet (sharepoint, teams) then invite the migrated user account into the source tenant)

 

 

2) Migrate the user, then dont touch the source account (perhaps disable the mailbox protocols so they are definetly not using the old mailbox). Put autoforward on old mailbox to new. Disable free/busy perms on old mailbox as now out-of-date. If users need to dip back to the old world they can use their old credentials, maybe in a second browser profile

 

 

3) Migrate all teams, sharepoin content first and guest the source users into the target tenant to access it. Then delete the gueest account, migrate the user and restablish permissions.

 

 

consider batching people by what shared mailboxes they access, what access they have to each other or what groups they are part of

 

On the client side, consider you have to migrate outlook profile, teams login, office pro plus license. Users will need to reconfigure smartphone apps. Even on a chunky network connection, lots of users downloading an OST at 9AM can cause things to creak.

 

Power suite (apps, BI, flow) are a real pain to migrate and whilst the bare bones can be exported and imported, anything connected will require skills. Of course the person that wrote it is still there....

  • Thanks 1
Posted (edited)
As the title says. Has anyone ever done this or had to do this?

 

Its a full tenant migration.

 

Any 3rd party tools to consider? Processes, best practices?

 

Any guidance on this would be appreciated.

 

Thanks

 

We do this continuously at my employer.

 

You’ve had good advice and good products already so I will try to add to that rather than repeat it.

 

So… domain names. Do you need to migrate these also? Perfectly possible but you will need to remove the domain from the old tenant before you can update it to be part of the new one. This will mean wanting to have DNS ready to update, and also that you will need to find and remove all references to the domain name in the old tenant’s objects before you can remove it there, and that you need to consider that the migrated users will need their upn updating twice (1st is old tenancy to new tenancy prior to domain name being moved, 2nd is updating them once you’ve properly added their ‘old’ domain name).

 

Have you determined if there will be any clashes between mailbox names or sharepoint site names, whatever? You will need a plan to migrate these.

 

Have you captured permissions? Who has access to what mailbox, Team or sharepoint site?

 

Have you looked at O365 groups, distribution groups, etc to determine if these should be migrated/recreated? Checked if users are using parts of O365 you might not have counted on? E.g. planner or flow or suchlike?

 

Are users issued with devices or provided with byod functionality that is connected to the AAD tenant? E.g. Intune or MFA? How will you update this? If they have AAD-joined devices how will you migrate these? How will you minimise disruption in the meantime?

 

How is spam filtering done? How are they using Conditional Access? 3rd party enterprise app registrations? Do they have anything that relies on, for example, legacy auth access to a mailbox that won’t work on your tenant because you disabled legacy auth?

Edited by Roberto
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...