Moving to Microsoft 365: a migration checklist for small businesses
Most Microsoft 365 migrations that go wrong fail on preparation, not technology: a forgotten shared mailbox, files copied into the wrong place, or a Monday morning where half the office cannot find their email. Whether you are moving from Google Workspace, an old on-premises server or another email host, this is the checklist we work through.
1. Take stock before you move anything
- Every mailbox, including shared mailboxes such as accounts@ and info@, aliases and distribution lists.
- How much mail and how many files each person has, so you know how long the copy will take.
- Where files live today: a server, Dropbox, Google Drive, desktops and USB drives.
- Which licence each person needs. The plans differ in their security features, not just their apps, so choose deliberately rather than buying one plan for everyone.
2. Plan the email cutover
Email moves in two parts: copying the existing mail across, and switching where new mail is delivered, which is a change to your domain's MX record. A day or two before the switch, lower the time-to-live on that record so the change takes effect quickly. Copy most of the mail in advance, make the switch at a planned time, usually outside business hours, then copy across anything that arrived in between. Done this way, nobody loses mail and nobody notices much beyond a new sign-in.
3. Design the file structure before you copy
Personal working files belong in each person's OneDrive. Shared files belong in SharePoint, usually one site or library per team or function, and Teams uses the same SharePoint storage underneath. Decide the structure and who can see what before copying anything, because copying an untidy server share into SharePoint unchanged simply moves the mess, including permissions nobody remembers granting.
4. Switch on the security that is off by default
- Multi-factor authentication for every account, with no exceptions for the boss or the shared accounts.
- Block legacy sign-in methods that cannot do multi-factor authentication. Microsoft's security defaults do this; conditional access gives finer control.
- Separate admin accounts from everyday accounts, and keep the number of admins small.
- Check that audit logging is on, so you can find out what happened if an account is ever compromised.
5. Sort out email authentication for your domain
Once Microsoft 365 is sending your email, update your SPF record to include Microsoft, turn on DKIM signing for your domain, and publish a DMARC record. Without these, your legitimate emails are more likely to land in spam, and it is easier for someone to send emails pretending to be you.
6. Get every device ready for the first morning
Plan how Outlook, OneDrive and Teams will be set up on each computer and phone, and have someone available on the first morning to help people sign in. A short written note for staff, covering what changes and who to call, prevents most of the questions.
7. Back up Microsoft 365 separately
Microsoft keeps the service running, but protecting your data is your responsibility, and deleted items are only kept for a limited time. A separate Microsoft 365 backup, with restores tested, is what protects you from ransomware, a compromised account or a mistaken deletion.
After the cutover
- Send and receive test emails with outside addresses, including a check that replies to old threads arrive.
- Confirm shared mailboxes and calendars work for everyone who needs them.
- Keep the old system available, read-only, for a few weeks before cancelling it.
- Check your sign-in logs in the first week for anything unexpected.
We migrate small businesses to Microsoft 365 regularly, including from Google Workspace and old on-premises servers, and set up the security as part of the move. If you are planning a migration, book a free IT review and we will map out the steps for your business.
Want your setup checked against this? Book a free IT review or call 07 5631 4365.