Checklist

The Microsoft 365 tenant-to-tenant migration checklist.

A tenant-to-tenant migration is five workload migrations wearing one project name. Identity, Exchange, SharePoint, OneDrive, and Teams each have their own prerequisites, exclusions, and cutover mechanics — this checklist sequences them so the dependencies are handled in order.

Sequencing ruleIdentity first, always. Every other workload resolves permissions and membership through the identity mapping — content migrated before mappings are final is content migrated twice.
Stage 1

Program pre-flight.

Close these items before any content moves. Most tenant-to-tenant schedule slips trace back to this list.

  • Confirm destination tenant licensing covers migrated users, mailboxes, and storage from day one
  • Inventory verified domains and plan the domain move window — a domain can exist in only one tenant at a time
  • Build and validate the identity mapping: every source user, group, and guest resolved to a destination principal or explicitly excluded
  • Register and consent the migration application in both tenants with least-privilege Graph scopes
  • Agree the coexistence period, mail-flow plan, and freeze windows with business owners
  • Define per-workload acceptance criteria and who signs off on each
Stage 2

Workload checkpoints.

Each workload has different fidelity boundaries. Verify what moves, what is reconstructed, and what must be recreated manually — before promising dates.

WorkloadChecklist itemsWatch for
Entra IDUsers, groups, and devices created or matched; B2B guests invited; app definitions recreated where selected.Anchor conflicts with Entra Connect-mastered objects; app secrets and consent grants are never copied.
Exchange OnlineBaseline mailbox copy, delta passes per mailbox, per-mailbox verification, DNS readiness report (MX, SPF, DKIM, DMARC).On-premises mailboxes need a supported Microsoft path first; DNS publishing stays with the customer change owner.
SharePoint & OneDriveAssessed scope frozen; sites and drives mapped; resumable transfer with delta passes; permissions applied via identity mappings.Sharing links are not portable; complex lists, workflows, and custom apps need a separate remediation plan.
Microsoft TeamsTeam and channel structure reconstructed; membership mapped; settings, tabs, and tags applied; message import where approved.Channel-message import is conditional on Microsoft protected-API approval; apps, connectors, and webhooks are recreated by owners.
Stage 3

Cutover gates.

Cutover is a sequence of gates, each with an owner and a rollback point — not a weekend.

Content baselineBulk passes complete; reconciliation reviewed per workload.
FreezeSource declared read-only under the change plan.
Final deltaDelta passes flagged as cutover runs; warnings dispositioned.
Domain moveDomain removed from source, verified in destination, DNS republished.
ReleaseUsers land on validated workspaces; hypercare begins.
Stage 4

Validation and evidence.

Completion is proven, not declared. Collect this evidence while the program is still staffed.

  • Per-workload reconciliation: mailbox verification, item counts, membership integrity, permission spot checks
  • Disposition for every failed or skipped item — retried, remediated manually, or accepted as excluded
  • Destination service checks: mail flow, sign-in, file access, Teams functionality for representative users
  • Manual remediation acceptance from application and content owners
  • Exported audit evidence and completion records for security and compliance review
  • Source-tenant retirement plan with a defined retention window

Get the checklist scored against your tenants.

A scoped assessment turns this list into findings for your actual environment: mappings, collisions, workload readiness, and a recommended first wave.

Request an assessment