MigrationWiz Tenant-to-Tenant Source Endpoint Permissions That Need to Exist Before Day One

Are you finding out 48 hours before cutover that your source tenant is missing RBAC permissions MigrationWiz needs to run?

For Microsoft 365 tenant-to-tenant migrations, MigrationWiz requires specific RBAC assignments on both the source and destination sides before any jobs are launched. On the source tenant, the migration service account needs ApplicationImpersonation scoped at the organization level in Exchange Online. If the project includes OneDrive or SPO workloads, it also needs SharePoint Administrator. In addition, you need a conditional access exclusion so non-interactive OAuth flows can succeed.

On the destination tenant, you need the same ApplicationImpersonation configuration for Exchange Online, SharePoint Admin for OneDrive writes, and Exchange Online licenses assigned to every destination UPN before MigrationWiz begins writing mailbox data.

After setting up MigrationWiz environments from scratch across two acquisition migration programs, the permissions checklist became the very first document created, before endpoints, before user uploads, and before scheduling. Each permission was verified with a test account prior to building the full project.

Are you confirming both source and destination RBAC permissions with a test account before you build out the full MigrationWiz project?

#BitTitan #MigrationWiz

Leave a Reply

Your email address will not be published. Required fields are marked *