Exchange Migration Knowledge BaseCategory: Mailbox Migration QuestionsPermission required for tenant to tenant migration
Vicky asked 3 years ago

What is the least permission required during cross tenant migration of mailboxes where users and their mailboxes are already created in source and target tenant.

Eriq VanBibber Staff replied 3 years ago

Tenant-to-Tenant migrations require that an account has FullAccess rights to each mailbox to be migrated. This will require 2 accounts, one to access the source mailbox and another to access the target mailbox. These 2 accounts would be considered “application accounts” and would be standard mailboxes, one in each tenant. Once created, the accounts would be given FullAccess rights to the user mailboxes to be migrated.

If this is a part of a larger migration, there may also be a need to sync the on-premises Active Directory objects between the environments in order to bring the Global Address List (GAL) from the source into the target. Our Priasoft Collaboration Suite tool can handle the ground-to-ground GAL sync and then the target Active Directory would sync to Office 365 using Microsoft’s Azure AD Connect tool (AADC).

Outlook profiles are also an important consideration. Outlook does not have code to properly respond to a tenant-to-tenant migration. Our profile update utility can facilitate a clean transition for Outlook users.