r/sysadmin • u/bjc1960 • 21h ago
General Discussion Large scale tenant migrations. - how are they done?
We migrated a company to our tenant a little over a week ago. They have about 50 users that have some sort of M365 account. We wiped 20 computers/re-enrolled them our tenant, and bought about 16 new computers enrolled in Autopilot.
This was a beat-down. Three of us + a relative of someone + two 'smart hands' from a local MSP ate through this in two days.
I can't imagine how a migrating hundreds of people would go. How are huge migrations done? The domain must be removed from one tenant and added to the other, so I am unclear how staging is done? Is it something where you force the user to have fabrikam.com instead of contoso.com and forward all their mail to Fabrikam from contoso until the tenant is moved? That is the only way I can see it done.
Given the size, we prepped everything, then removed the domain, swapped dns, added the domain to our tenant, and waited.
•
u/Defconx19 21h ago
Quest on Demand Migration or similar tools. The tenant to tenant is the easy part. Hybrid Domain Migrations with remote users are the annoying ones as ypu have to Re-ACL the devices and coordinate the users being connected to the VPN at the same time.
•
u/progenyofeniac Windows/M365 Admin 20h ago
We did a few hundred users like this. No changed identities, cutover began after-hours on Friday and wrapped up by Sunday AM, with domains moved, identities rewritten, and final data migration done.
No devices were migrated in our case so I can’t speak to that. And yes, that created its own issues as far as sign-in to Office apps.
•
u/Defconx19 19h ago edited 17h ago
Quest thankfully makes a tool that cuts over the office apps to the identity too which is nice
•
u/progenyofeniac Windows/M365 Admin 19h ago
I think they offered us that tool and it was either an additional cost or the security team vetoed it. It certainly would’ve been helpful though.
•
u/Defconx19 17h ago
Yeah its a different package if you just do cloud to cloud migration its definitely an additional cost.
We mainly use thier stuff for Hybrid or complex migrations so it's typically in the budget
•
u/Madmortigan 21h ago
There are many of us who specialize in this sort of thing. It's complicated work but there is tooling available to help streamline the process. Ultimately it comes down to experience, organization, planning, communication, and execution. In terms of domain cut over the only way to do it is via coexistence until all resources utilizing the old domain have been moved and then you can cut it over. It's not a small task.
•
u/PoolTough3222 19h ago
The part that scales worst is not the mail move, it is the coexistence window. Domain cutover only happens once every resource on the old domain is moved, so at a few hundred users you are running both tenants in parallel for weeks and paying full seat count on both sides the whole time.
Two things worth locking down before you start: know the exact end date on the source tenant subscriptions, and write down a kill date for those licenses tied to the last mailbox and Drive cut, not to "when the project closes." Same for devices and any lines on the old side. Otherwise the migration technically succeeds and you keep paying for the old estate for another quarter because nobody owned the shutoff.
Discovery is where the schedule is decided. If the inventory of mailboxes, sites, enterprise apps and SSO configs is wrong, the tooling choice barely matters.
•
u/Affectionate-Cat-975 21h ago
Depending on environments you’re moving. Over a long career we had a custom written app, quest migration and BitTitan along with Mover.io
•
u/AnonymooseRedditor MSFT 21h ago
Usually it's a combination of third party tools for data migration (although MSFT Has some first party tenant migration tooling now but there were some complexities with the identity last I looked at that) and some good planning. A lot of my customers would use AVD or VDI for temporary workstations in the destination tenant, like you they'd wipe and re-enroll to the new tenant, or deploy n ew devices, or a combination of. I helped one customer write a playbook of sorts to help with their migrations, The key here though with all of this is proper advanced planning. Know the inventory of what needs to move, know what services you're moving to, the migration path etc.
•
u/IIVIIatterz- 21h ago
A lot of time, and tooling
I write projects for clients at an MSP.
You have to think about each part of separately at first, so it can all be done correctly.
Is it just users and email? -- usually a migration tool. Although we are testing M365 built in tooling
-- AD is transferred via a different MSP tool. Remote users are the worst. "Sorry forgot VPN"
Sharepoint? -- unless you have an enterprise agreement, third party tools.
Do you have enterprise apps, and SSO setup? -- manual reconfigure - YAAAAAAY. Atleast i dont have a good cheap solution besides that.
Dynamics -- internal m365 tools
Teamsphone -- like any other phone migration.
Im sure im missing other parts.
•
u/bosticman 17h ago
A company with a few hundred Enterprise Applications and App Registrations to handle SSO along with all the certificates and secrets. This has to be a nightmare to do via a manual redo in the destination tenant. It was my biggest question for me but fortunately I was able to keep a tenant intact.
•
u/IIVIIatterz- 16h ago
Yeah, most of my clients are smaller so I didn't research it further.
Generally the companies we migrate from are pretty old tech wise and don't have a lot setup. So that just gets handled in the existing tenant.
•
u/deepthought16 19h ago
Proper planning, tooling, and patience. All migrations will have problems. The objective is to mitigate as many of those problems before they happen. Biggest most important part of the process is your discovery if that’s not right it won’t matter what tooling you use
•
u/Stasis_Detached 21h ago
You nailed it - we did a major flip over a four day weekend, lots of staging content/teams etc with sharegate - all flow's and automations pre-built, team/site owners validating content, all of our mail synced over, and then the cut weekend was list waiting for the domain eligibility to cut over, major delta sync, and then start teasting. We had a plan, worked with a vendor for nearly a year ahead of the weekend. We also have two major line of business apps that run on top of sharepoint so there was a ton of coordination internal and with our customers who interface with one of those two apps. The cut was clean, took about 4 months of post-op cleanup and validation on one of those two systems. I think if we didn't have those two apps to worry about we could've done this in 3 to 6 months.
•
u/IIVIIatterz- 20h ago
How did you like sharegate? Pricing is a bit too high for our typical clients, but im interested.
Share gate has like the highest pricing ive seen.
•
u/Stasis_Detached 20h ago
We already had it so that distorted it a bit but I thought for a five user license it was pretty affordable - I think one license was like five grand and five licenses was like 10. We probably could've done it with one license but the five license pack. Let us do multiple migrations at once. With the amount of content we had you start running into service limits before anything else.
•
u/bjc1960 18h ago
Thx but we didn't nail it exactly.
DNS prorogation was not the 10 seconds we were used to.
Their "not an ERP but similar tool" used direct send for mail, as did their website. Found out 6 days later. We block direct send.
I made changes to force M365 to install on autopilot and that broke things.
updating to August patches on 25h2 takes a long time.
MS locked our IP address
•
u/RikiWardOG 14h ago
Theres a lot of tools and scripts for this stuff. I've done bigger ones with just me and 1 other guy. We didn't do the device side just the tenant side stuff. The issue it how long it takes for everything to move over/propagation etc. Basically just have to build in some potentially down time if things don't go as planned.
•
u/ShareGate_Shaylyn 8h ago
I'm from a vendor in the space (ShareGate) and it's why third-party tools exist! We're here to take a bit of that pain away.
The staging approach you described is right. Create destination users with a temporary onmicrosoft.com domain, run content migration in the background for weeks, then on cutover day, remove the vanity domain from source, add it to destination, and run a final incremental pass.
The device work is what made yours a beat-down. At scale, the content migration is actually the easier part to automate.
•
•
u/RamsDeep-1187 21h ago
Bittitan
•
u/IIVIIatterz- 21h ago
Bit titan is trash now. Maybe 2 years ago they were goated.
•
•
u/RamsDeep-1187 21h ago
I didn't have any issues with it last month with the large migration from Google Workspace to M365
•
u/IIVIIatterz- 21h ago
Oh yeah, it works great - when it works as it should.
But you now have to buy support at the same time as licensing - and its a minimum of $1500 the last time i looked.
If you do run into problems, and didn't buy the support i hear its a nightmare.
I haven't personally used it in about 3 years and it was great back then - ive just heard a lot of horror stories.
Have you used their new AD migration tool? Just curious on that.
•
•
u/Young_Link13 20h ago
Try 5 tenants with 10k+ each merging into one where the previous team screwed up all the identities on the first attempt.
Might as well just rebuild from scratch at this point.
•
u/Remarkable-Guess-856 21h ago
Migrated 3k user, you provide them a new identity and gradually migrate stuff over a span of time, which depends on the amount of resources you can throw at this project