Microsoft 365 Migration Challenges and How to Solve Them
Microsoft 365 migrations often seem easy on paper. Move email, files, users from one environment to another, change DNS records & you’re done. In reality, every migration project has its own set of challenges that can turn a simple migration into complex troubleshooting exercise in no time.
Over the past few years I have been part of many Microsoft 365 migration projects including Exchange Server, SharePoint, OneDrive, Teams and tenant consolidation.
Although every customer environment is different, the same challenges appear repeatedly. In this article, I’ll share some of the most common Microsoft 365 migration challenges I have encountered and the practical solutions that helped us complete these projects successfully.
1. Broken Entra ID Connect Synchronization
One of the most complex migration projects I worked on involved an organization running Exchange Server 2016 on-premises.
At first glance, the migration seemed straightforward. However, after the initial assessment, we discovered that the organization already had a Microsoft 365 tenant to which users had been synchronized from Active Directory years earlier.
The main problems were:
- Entra ID Connect synchronization had been broken for over a year.
- Nobody knew where Azure AD Connect, now Microsoft Entra Connect Sync, was installed.
- Some users were already using Microsoft Teams and Microsoft 365 Apps.
- The tenant had been used only for testing, resulting in inconsistent user identities.
- Documentation for the existing environment was almost nonexistent.
Why This Was a Challenge
Because the users had originally been synchronized from Active Directory, Microsoft 365 treated them as directory-synchronized accounts. Initially, we decided to create a new tenant, remove the domain from the old Microsoft 365 tenant, add it to the new tenant, and migrate all the mailboxes to the new tenant.
The organization’s primary email domain was already verified and attached to the old tenant. Since a custom domain cannot be transferred to another Microsoft 365 tenant if it is linked to the original tenant, we were unable to transfer the domain to another tenant unless it was first detached from the original tenant.
But we could not detach the domain since it was in use by synchronized users.
This created a circular dependency:
- The domain could not be removed because synchronized users were still using it. Because the users were synchronized, we could not change their account properties directly in the Microsoft Entra admin center or Exchange Online. We first had to change their UPNs to the tenant’s fallback domain.
- The users could not be converted because directory synchronization was broken.
- Nobody knew where the synchronization server was located.
How We Solved It
After a detailed investigation, we decided not to create a brand-new tenant.
Instead, we:
- Reinstalled Microsoft Entra Connect Sync on a domain controller.
- Reconnected the on-premises Active Directory environment to Microsoft 365.
- Resolved the synchronization conflicts.
- Validated all user identities and UPN mappings.
- Re-established a healthy hybrid identity environment.
Once synchronization was working correctly, the mailbox migration became significantly easier.
Using a migration tool, we migrated the mailboxes from Exchange Server 2016 to Exchange Online and completed the migration with minimal disruption.
The customer now operates in a hybrid identity model in which:
- Users are created in Active Directory.
- Accounts are synchronized automatically to Microsoft 365.
- Users can use the same identity to access Exchange Online, Teams, OneDrive, and Microsoft 365 Apps.
With successful validation, the organization was able to decommission its on-premises Exchange Server.
Key Lesson
Identity related issues are usually more complicated than the move itself. It is necessary to verify the health of Entra ID Connect, user sync health, domain ownership, User Principal Names (UPNs) and Hybrid dependencies before starting any migration process.
Microsoft recommends to think about identity mapping and domain transfer needs before tenant or workload migration.
2. Domain Verification and Tenant Conflicts
Another common problem is domain ownership dispute.
A lot of organizations create Microsoft 365 tenants for testing purposes and then lose track of them. Years later, when a migration project begins, administrators may discover that the production domain has already been verified in another tenant.
You cannot add the same domain to a second tenant in Microsoft 365 unless it has been completely removed from the first tenant.
Common Issues
- Directory-synchronized users still using the domain
- Old mailboxes referencing the domain
- Distribution groups and mail contacts using the domain
- Administrators no longer having access to the original tenant
Best Practice
Before planning a migration:
- Identify every Microsoft 365 tenant associated with the organization.
- Verify domain ownership.
- Audit synchronized users and groups.
- Document dependencies before making DNS changes.
A simple domain assessment can save you days, or even weeks, of troubleshooting later. Domain Planning is an important pre-requisite for Tenant to Tenant Migration.
3. Permission Issues After Data Migration
One of the most common customer complaints after a successful migration is:
Customer Concern
“My data migrated successfully, but users cannot access it.”
This is a common problem when doing mailbox, SharePoint, OneDrive, file server and NAS migrations.
Why It Happens
Permissions are frequently stored as references to source users, groups or security identifiers.
When data is moved to Microsoft 365:
- Some permission entries may not map correctly.
- External users may be excluded.
- Legacy groups may no longer exist.
- SharePoint and OneDrive permissions may require remapping.
How We Solve It
We typically use migration tools that include permission migration capabilities.
These tools can:
- Preserve SharePoint permissions
- Map source users to destination users
- Maintain access through Microsoft 365 groups
However, we always validate permissions after migration because automated permission migration is rarely perfect.
Best Practice
Never assume that permissions have migrated correctly.
Always perform:
- Pilot migrations
- Permission validation
- User acceptance testing
- Access reviews after cutover
4. Large SharePoint and File Repository Migrations
Storage is another major challenge.
One recent project involved migrating approximately 5 TB of data from Box to Microsoft 365.
The customer expected SharePoint Online to be the destination for all content.
The Challenge
Microsoft 365 storage is not unlimited.
The customer’s SharePoint storage allocation was insufficient for the entire migration, and purchasing additional SharePoint storage would have significantly increased costs. We therefore suggested storing the archive data in a dedicated OneDrive account.
How We Solved It
After reviewing the available licensing options, we identified a more cost-effective solution.
We:
- Created a dedicated migration account.
- Assigned a Microsoft 365 Business Premium license.
- Added a OneDrive Plan 2 license.
- Increased the OneDrive storage allocation from the default 1 TB to up to 5 TB.
- Structured access by using Microsoft 365 groups.
Instead of assigning permissions directly to individual users, we granted access through groups.
This provided:
- Easier management
- Better scalability
- Simpler future administration
Key Lesson
Storage assessments should be part of migration projects early in the planning phase. Take into account SharePoint storage needs, OneDrive size, growth expectations, licensing costs and access needs. A good storage strategy can make a big difference to your ongoing operational costs.
Recommended Assessment Areas
- Active Directory
- Exchange Server
- Entra ID Connect
- DNS records and custom domains
- SharePoint, OneDrive, and Teams environments
- Third-party applications
- Mail flow connectors
- User authentication methods
- Gmail, Google Drive, and Shared Drives
- Microsoft 365 source and destination tenants
- File servers and NAS drives
- File sizes, file types, permissions, and folder structures
- Storage capacity and migration requirements
The more thoroughly you understand the source and destination environments before the migration begins, the fewer surprises you will encounter during the project.
Final Thoughts
Moving to Microsoft 365 is not just a data move. In most projects the biggest challenges are identity management, synchronization problems, permissions, domain ownership and storage planning. The Exchange Server 2016 migration project above is a good example of an important lesson: it’s often more important to fix identity and synchronization issues than it is to move the mailboxes themselves. Organizations that focus on discovery, planning, pilot testing, identity validation and permission verification will greatly reduce the risks of migration and present a more seamless experience for end users.
Final Thought
A successful Microsoft 365 migration is not about how quickly data is migrated. The measure is how well the users can keep working when the migration is done.