How IT teams plan, tool, and run Microsoft 365 migrations in 2026

94% of organizations moved something in the past two years. Only 7% would do it the same way again.

Chapter 6 in brief
35%

of the biggest migrations were driven by org change, not technology strategy

83%

want identity prep inside their migration tool. 11% have it

2x

Shadow IT doubles between teams running one migration and teams running three


What this chapter covers Migration as a standing condition, not a project.

Most teams are running more than one migration at a time and starting the next one before the last finishes. This chapter is about what that costs, what teams wish they'd done differently, and which step reliably hurts the most.

Why it matters more now A quarter of the biggest projects came from a deal.

Cloud migration has a finish line. Corporate change doesn't. Mergers, divestitures and restructures keep starting tenant-to-tenant work, and they arrive on someone else's timetable with a deadline already attached.

The gap worth closing Identity is the step teams most want inside the tool.

83% want identity preparation handled inside their migration tool. 11% have it there. That's the widest want-versus-reality gap in this data, and it sits on the step teams already name as the hardest part of a tenant move.

What predicts buying a tool How much you move, not how big you are.

Third-party tool use runs from 41% among teams doing one kind of migration to 79% among teams doing three or more. The same pattern holds inside every company size band. The teams doing the most are also the most likely to say they should have bought sooner.

Every stat on this page comes from the IT operations survey (n=943). Full methodology →

This is Chapter 6 of The State of Microsoft 365, a report on how organizations run, secure, and migrate in 2026. Learn more →

See where you stand

Migration keeps arriving.

The M365 Governance Index scores the estate it lands in, from visibility and tenant control to incident resilience, against 943 IT pros. Then it tells you what the most effective teams do differently.

Get your score

Migration is the most misunderstood work in this report, because almost everyone still describes it as a project. Projects end. This doesn't.

Once compliance clears the path, the work becomes movement Compliance. And the movement does not stop. Organizations acquire, divest, restructure, consolidate, and modernize on a rolling basis, and each of those events produces a migration. The data shows teams working through several, finishing one and starting another, and consistently wishing they'd treated it as a capability the first time round.

Everyone's migrating something, and usually more than one thing

WE ASKED

What types of migrations has your organization completed, started, or planned in the past 24 months?

selection everyone
File shares to SPO/OneDrive66%
SP on-prem to SPO54%
Tenant-to-tenant49%
Exchange to EXO47%
Entra ID23%
No migrations6%

Teams run ~2.5 migration types every two years. One-and-done is a myth.

IT operations survey

94% of organizations migrated something in the past two years, and those that did averaged 2.5 migration types completed, underway, or planned across the 24-month period. 6% stood still. Of the teams that moved anything, 81% ran two or more kinds of migration inside the same 24 months and half ran three or more. That's the case for treating migration as an operating capability rather than an event: the average team isn't between migrations, it's working through two or three of them.

Laura Rogers sees the same pattern from inside the projects.

Most teams still treat migration as something with a finish line. Move the content, move on. The successful ones build the ownership and the processes that make the next change easier, because there's always a next change.”

A third of the biggest moves are organizational

WE ASKED

Which of the following best describes your organization's most significant migration project in the past 24 months, the one that consumed the most time, budget, or attention?

everyone
everyone
  • On-prem to cloud
  • On-prem to on-prem
  • M&A or divestiture
  • Consolidation or restructure
  • Other

Half are still the classic lift to the cloud. But a quarter of the most significant projects were a merger, acquisition, or divestiture. That's the move that restarts the migration, governance, and cost clocks at once.

IT operations survey · the 889 who ran a migration

Nearly a quarter of organizations say their biggest migration was driven by a merger, acquisition, or divestiture. The cost chapter found that cost pressure is a moderate or major driver of migration and consolidation for 88% of organizations, and duplicate M&A tenants are among the largest cost lines in the estate The AI reckoning. The two findings describe the same cycle from different ends. Add consolidation and restructure work and 35% of the most significant projects were driven by organizational change rather than technology strategy.

This is the structural reason migration never ends. Cloud migration has a finish line, at least in principle. Corporate change does not. As long as organizations keep buying, selling, and reorganizing, tenant-to-tenant work keeps arriving. It arrives on someone else's timetable, with a deal deadline attached.

Constant motion leaves a trace. Teams that ran three or more kinds of migration in the past two years are more likely to report a governance incident than teams that ran one: 83% against 68%. The sharpest split is shadow IT and shadow AI, where people pick up tools, apps or automations outside IT's line of sight. That one doubles.

Shadow IT doubles as the migration count climbs

Ran one migration type16%
Ran two types20%
Ran three or more types32%

Sixteen percent of teams running a single migration reported it. Thirty-two percent of the heaviest movers did.

IT operations survey
Each bar is the share of that group who reported a shadow IT or shadow AI incident in the past year, meaning someone picked up tools, apps or automations outside IT's visibility. The three groups are 166, 279 and 442 teams.

The survey can't tell you which way that runs. Repeated migration may leave sprawl behind, or the teams generating the most sprawl may be the ones restructuring most often. Both are plausible, and the pattern shows up in all five company size bands. What it does establish is that heavy migration activity and governance debt turn up in the same places.

We asked the MVPs why that debt accumulates rather than clears. David Drever put it down to change management rather than tooling.

The organizations that do this well take the time to get compliance-ready, then move into a controlled environment and keep it that way. Where it fails is where compliance was pushed onto people without anyone explaining why. Then all that work quietly decays, because nobody understands what they are maintaining.”

Decay is the right word for it. 77% of organizations reported a governance incident in the past year, and the teams moving most often are the ones furthest into that number Governance.

How long it takes

Planning benchmarks matter when the timeline is set by a deal rather than by IT.

A third run past six months

WE ASKED

How long did this project take from kickoff to completion?

selection everyone
Under 3 months16%
3–6 months47%
7–12 months26%
Over 12 months10%
Still in progress1%

Half land in the three-to-six month window. But 36% run longer than that and one in ten past a year, long enough for the estate to change underneath them.

IT operations survey · the 889 who ran a migration

Most projects land in the 3 to 6 month band, but more than a third take seven months or more, including 10% that exceed a year. Read that against the M&A finding and the tension is obvious: a significant share of migrations are triggered by transactions whose integration deadlines are set in a boardroom, and the typical project takes half a year. Teams who haven't pre-built the capability are being asked to compress a six-month process into whatever the deal timeline allows.

Projects running past six months, by what drove the migration
Most significant project n Ran seven months or longer
On-prem to cloud 435 34%
Merger, acquisition, or divestiture 214 39%
On-prem to on-prem 136 35%
Consolidation or restructure 96 41%
Other 8 75%
Sample average 889 37%
IT operations survey
Both deal-driven rows cover M365-to-M365 and Google Workspace-to-M365 moves. "Other" is 8 teams, too few to read.

Last year's report asked the same question of M&A migrations, so that's the one group where the two years compare. One band moved enough to mention.

The fast M&A migration is thinning out
23% 12% M&A migrations completing in under three months
20252026

The fast M&A migration is thinning out: 23% → 12% finish inside three months.

Treat that as a direction rather than eleven exact points: last year's figure comes from a dedicated M&A module of 520 people, this year's from the 214 whose biggest project was a deal. The other bands drifted a few points each and none of them says much on its own. What thinned out is the quick one.

Why teams move

Teams could name up to three reasons. One of them is new this year.

Why teams migrate, and AI just joined the list

WE ASKED

What drove the need for this migration project? (choose up to three)

selection everyone
Security improvements45%
Scalability42%
Regulatory/compliance39%
Consolidate tenants (cost)38%
Backup / DR34%
AI readiness28%
End of support20%
Consolidated security posture9%

Security still leads, but AI readiness is now a named reason to move (28%).

IT operations survey

Security and scalability remain the top two, as they were last year, though they've swapped places: in 2025 scalability led at 65% with security a point behind at 64%. Every driver scores lower in absolute terms this year, which likely reflects a change in how the question was asked rather than a collapse in motivation, so read the ranking rather than the levels. The newcomer worth watching is AI readiness, now a named driver for more than a quarter of organizations.

Two years ago AI readiness wouldn't have appeared on this list. It's now cited more often than end-of-support deadlines, and it connects this chapter directly to the first: content has to be somewhere Copilot can reach it, governed well enough that reaching it is safe Confidence ≠ control.

Mike Maadarani described what that looks like at the moment of the move.

Migrate stale content into a tenant with Copilot switched on and it will be indexed unless you have deliberately excluded it. You are not just moving old data, you are deciding what to feed your AI.”

What actually moves when a tenant moves

Scoping a tenant move starts with this list, and it runs longer than most teams expect.

Tenant-to-tenant touches everything

WE ASKED

What workloads were (or will be) included in this tenant-to-tenant migration?

selection everyone
Power Platform54%
SharePoint49%
OneDrive48%
Teams48%
Entra ID45%
Exchange41%
Google Workspace34%

The 'mailbox move' is now a whole-estate move.

IT operations survey · the 310 running a tenant-to-tenant move

⚠ SMALL SAMPLE (n=) — READ AS DIRECTIONAL

Power Platform tops the list. That should reset the scoping conversation. The assumption that tenant-to-tenant work is mostly mail and files is out of date, and it's the assumption most likely to produce a mid-project surprise. Apps, flows, and connectors are the most commonly in-scope workload, they hold their own permissions and connections, and they're frequently owned by someone outside IT who built them for a purpose nobody documented. The estate chapter covers what this says more broadly The estate.

A third of these projects also involve Google Workspace, which is worth noting for anyone assuming cross-platform work is a niche case.

Power Automate flows are also the example named in the shadow IT question earlier in this chapter, the incident type that nearly doubles as migration volume rises. The workload teams most often have to move is the one they're least likely to have documented.


What you buy follows how much you move

What teams use to move

Most teams don't pick a tool. They pick several.

Teams are adding tools, not swapping them

Native tooling went up, not down. Third-party use rose alongside it rather than instead of it.

IT operations survey · 2026 n=889 · 2025 n=636
Three of the options teams were offered, not all of them. Teams could pick as many as applied, which is why these don't total 100%.

That's the shape of a field where teams are stacking approaches rather than swapping them, which is what you'd expect from teams running two or three kinds of migration every two years. Native tools are the floor almost everyone builds on. What changes is what gets added on top, and how soon.

What teams would do differently

We asked the teams who'd already finished one what they'd change.

What they'd do differently

WE ASKED

Looking back, what would you have done differently? (choose up to two)

selection everyone
Plan earlier45%
Buy tooling sooner38%
Engage a partner earlier29%
Clean up first36%
Better change mgmt19%
Nothing, went well7%

Planning earlier tops the list. But buying real tooling sooner is right behind it, and cleaning up first is level with that.

IT operations survey

⚠ SMALL SAMPLE (n=) — READ AS DIRECTIONAL

Only 7% would change nothing. The top three regrets are all the same shape: plan earlier, tool earlier, clean up earlier. Hindsight is the most honest advice in any survey, because the person giving it has already paid for the lesson. Three of the top four answers describe work that should have happened before the project started.

What actually predicts buying a tool

Not the size of the company. How much migration it runs.

The more you move, the more likely you are to buy

Ran one migration type41%
Ran two types63%
Ran three or more types79%

Run one kind of migration and it's a coin flip. Run three or more and it's close to a certainty.

Used at least one third-party migration tool.

IT operations survey

The obvious objection is that this is really a story about company size. Bigger companies run more migrations and buy more software. It isn't. The same pattern shows up inside every size band in the study, and it's widest in the largest one.

Same pattern, inside the biggest companies only

Ran one migration type21%
Ran two types50%
Ran three or more types73%

Among companies with 3,000+ employees, buying runs from 21% at one migration type to 73% at three or more. Those companies are 25% of the one-type group and 23% of the three-or-more group, so the mix barely moves.

IT operations survey
Only 42 teams this size ran a single migration type, so 21% is the softest number on this page, and a bigger sample could move it either way. The 52-point gap to the three-or-more group is wide enough that the pattern holds regardless.

The regret climbs the same way. Among teams that ran one kind of migration, 27% wish they'd bought tooling sooner. At three or more, 43%. Over the same range, the share saying nothing went wrong halves.

Tool use and regret, by how much migration a team runs
Migration types run n Used a third-party tool Wish they'd bought sooner Nothing went wrong
Ran one migration type 166 41% 27% 10%
Ran two types 279 63% 36% 6%
Ran three or more types 442 79% 43% 5%
Sample average 943 63% 38% 7%
IT operations survey
Tool use is out of everyone in each group. The two hindsight columns are out of the 629 teams who answered that question — 113, 172 and 336 of them, group by group.

Split the same question by what teams actually bought and the answer lands in a place worth sitting with.

Regret about tooling, by what teams actually used
Group n Wish they'd bought sooner
Native tools only 162 25%
Any third-party tool 427 45%
ShareGate users 201 47%
Sample average 629 38%
IT operations survey
Out of the 629 teams who answered the hindsight question, not all 889 who ran a project. Groups overlap — most teams used more than one tool.
Hindsight, in advance

Hindsight is the most useful data in this chapter and the most expensive way to get it.

The M365 Governance Index ranks your widest gaps by how far they sit behind the field, so you can work the list before the next migration instead of after it.

Get your score

Identity as the hardest part

Ask what actually hurts in a tenant-to-tenant move and identity surfaces immediately.

Identity prep is the hardest step

WE ASKED

How difficult is (or was) the identity preparation step—ensuring users exist and are properly configured in the destination tenant before moving workloads like mailboxes?

selection everyone
Very difficult10%
Somewhat difficult26%
Manageable40%
Easy24%

36% find it difficult or the single hardest part. Only a quarter found it easy.

IT operations survey

They want it built in, not bolted on

WE ASKED

How important is it that your migration tool can handle identity preparation as part of the same workflow as content and mailbox migration?

selection everyone
everyone
everyone
  • Critical it's unified
  • Very important
  • Somewhat important
  • Not important

83% want it in the same workflow. Set that against the 43% who still prepare identities by hand.

IT operations survey

36% find identity preparation difficult or the single hardest part. Another 40% call it manageable while noting it could be easier, which is a polite way of saying it works but costs more than it should. More than four in five want identity preparation handled inside the migration tool rather than bolted on. Now the number that turns that preference into a gap.

83% want identity inside the tool. 11% have it.

Want identity prep handled inside the migration tool83%
Use a migration tool that actually includes it11%

The widest want-versus-reality gap in the migration data, and the reason the difficulty scores sit where they do.

Teams who called a unified workflow critical or very important, against teams whose actual method is a migration tool with identity prep built in. Both questions went to the 310 teams that ran tenant-to-tenant work.

IT operations survey

Four in ten prepare identities by hand

WE ASKED

When preparing for this tenant-to-tenant migration, how did your organization handle identity preparation (creating users, mapping groups, assigning licenses in the destination tenant)?

selection everyone
Microsoft cross-tenant tools41%
By hand in the admin centre28%
PowerShell scripts13%
Third-party tool with identity11%
External partner4%
Ad hoc, no defined process2%
Not sure1%

Microsoft's cross-tenant tools lead. But 43% still assemble identities manually, by script, or with no defined process at all. 83% say they want it inside the migration tool.

IT operations survey · the 310 running a tenant-to-tenant move

That gap explains the difficulty scores above. More than four in ten teams are doing identity prep in a separate Microsoft tool, and another 41% are doing it by hand in the admin center or with scripts. The step teams find hardest is the step most often handled outside the workflow that everything else runs in.

How hard identity prep feels, by how teams actually do it
Identity preparation method n Difficult/Hardest Easy
Using Microsoft's cross-tenant migration tools 128 34% 19%
Manually through the Microsoft 365 admin center or Azure portal 86 35% 33%
Using a third-party migration tool that includes identity migration 34 32% 38%
Using PowerShell scripts 42 41% 17%
Relying on an external partner / consultant 14 29% 29%
We don't have a defined process, it's ad hoc 5 80% 0%
Not sure 1 100% 0%
Sample average 310 36% 25%
IT operations survey

The difficulty does track with the method, though the bases get small quickly. Teams using PowerShell scripts report the most difficulty, while the small group with identity built into their migration tool reports the highest ease. That last group is only 34 people, so read it as a direction, not a decimal.

What went wrong on migration projects

WE ASKED

What were the biggest challenges during this project? (choose up to two)

selection everyone
Migration complexity29%
Downtime / disruption risk26%
Security & compliance validation25%
Budget constraints23%
Lack of internal expertise18%
Permissions during migration16%
Exec sponsorship / buy-in5%
Timeline pressure4%

Complexity, downtime and compliance validation lead. Permissions work sits well down the list, and it is the thing teams say blows up timelines. That gap is worth asking about.

IT operations survey · the 889 who ran a migration project
Everyone who ran a project saw this list.

On a deal-driven migration, identity is the problem

WE ASKED

What were the biggest challenges during this project? (choose up to two)

selection everyone
Security and compliance concerns35%
Managing user permissions and identity mapping across tenants30%
Preparing user identities in the destination tenant27%
Downtime and business disruption risk27%
Migration complexity—coexistence, permission conflicts24%
Lack of internal expertise or resources21%
Budget constraints18%
Timeline pressure from legal or regulatory deadlines11%

Identity and permissions take two of the top three spots on the deal-driven challenge list, on a timeline set by a transaction rather than by IT.

IT operations survey · the 318 whose biggest project was a deal

⚠ SMALL SAMPLE (n=) — READ AS DIRECTIONAL

The 318 teams routed here are those whose biggest project was a merger, acquisition or divestiture (214), a consolidation or restructure (96), or something else (8).

Identity and permissions occupy two of the top three. M&A projects also run longer. 39% pass the six-month mark against 34% of on-premises-to-cloud moves, on timelines usually set by a transaction rather than by IT.

The planned, happy-path portion of a migration, the part every tool demos well, rarely breaks a project. What breaks projects is everything that wasn't fully scoped: the customization nobody documented, the permission that doesn't map, the Power Platform flow that surfaces halfway through, the coexistence window that runs longer than planned.

The mailbox move breaks on more than downtime

WE ASKED

What are the biggest challenges you face (or faced) specifically with the mailbox migration portion of this project? (choose up to two)

Downtime / user disruption41%
Destination identity prep38%
Coexistence (routing, free/busy)36%
Volume / throttling29%
Compliance & data integrity22%
Licence assignment17%
Not part of this project3%
Other1%

Downtime leads, but destination identity prep (38%) and coexistence (36%) come straight after it. Those are the two things nobody puts on the plan.

IT operations survey · the 126 whose project included a mailbox move

SHOWING EVERYONE — NO SPLIT FOR THIS CHART

The mailbox picture reinforces it: identity prep is the second-largest challenge, and coexistence, which is largely an identity and routing problem, is third. Which reframes what tooling is actually for. Automating the predictable steps has value, but the predictable steps were never the risk. The tooling that earns its cost is the tooling that absorbs the exceptions, and it earns it repeatedly, because a team running 2.5 migration types every two years will meet those exceptions again.

Every migration I've seen go sideways went sideways in the last ten percent. The content moves fine. Then you find the workflow nobody documented, the group that doesn't map, the mailbox with twelve years of delegation on it. Teams budget for the ninety percent because that's the part you can estimate, and then the exceptions eat the timeline. The tooling question isn't "can it move the data". Everything moves data. It's "what happens when something doesn't fit".”
Before the next project

Most of what's on those lists is a condition of the tenant rather than an event in the project.

Visibility and tenant control are two of the ten dimensions the M365 Governance Index scores. Answer the same questions these 943 IT pros answered and see which of yours sit furthest behind theirs.

Get your score

Migration is a do-it-yourself job

WE ASKED

Did you involve an external partner (IT consultant, VAR, or MSP) in this project?

everyone
everyone
  • Entirely in-house
  • Partner: planning only
  • Partner: implementation only
  • Partner: planning + implementation
  • Partner: all phases

77% ran their most significant migration entirely in-house. Fewer than one in ten brought a partner into both planning and implementation.

IT operations survey · the 889 who ran a migration

SHOWING EVERYONE — NO SPLIT FOR THIS CHART

Almost everyone would bring a partner in for AI

WE ASKED

How likely is your organization to engage an external partner to conduct an AI governance assessment before scaling AI use?

selection everyone
Very likely39%
Somewhat likely47%
Somewhat unlikely10%
Very unlikely4%

86% are likely to. Only 4% rule it out.

AI governance survey

SHOWING EVERYONE — NO SPLIT FOR THIS CHART

77% of teams handled their biggest migration entirely in-house. Ask the same kind of question about AI governance and 86% say they'd bring in a partner.

Two surveys, two questions, so this isn't anyone changing their mind. But it's a clean read on what teams think they've got covered. AI governance is new, so it gets help. Migration is familiar, so it doesn't.

Familiar is doing a lot of work in that sentence. Only 7% of teams would run their last project the same way again. 45% of the ones who bought tooling wish they'd bought it sooner. 29% of that same AI group has already had an exposure incident Confidence ≠ control. And when teams do bring a partner in, they rarely do it for one phase. It's planning and implementation together, or the whole thing, which is what you'd expect from work that turned out to be bigger than it looked.

Your move

What to do about it

1 Quick win · This week

List what you'll have to migrate again in the next 18 months

Not what you're migrating now. What's coming: the acquisition in diligence, the tenant you inherited and never consolidated, the file shares still sitting behind the last project, the workloads that hit end of support next.

Most teams have never written this list down, which is precisely why each migration feels like a surprise. A single page changes the conversation from "how do we get through this one" to "what capability do we need". For each likely migration, capture the trigger and target date, source and destination, workloads and approximate scale, identity and domain dependencies, compliance constraints, business owner, confidence in scope, and current planning stage.

IT operations survey
2 Medium lift · This quarter

Pull identity preparation into the migration workflow, and clean up before the move

83% want identity handled inside the tool and only 11% have it there. That's the widest want-versus-reality gap in this data. If your process still involves a separate admin center or script stack for identity mapping, that's the highest-value thing to consolidate, especially if deal-driven work is in your future, where identity and permissions take two of the top three reported challenges.

Pair it with content cleanup, which 36% of teams wish they'd done more of beforehand. Sorting before you move usually beats sorting after: you move less, you move cleaner, and you don't carry a decade of permission debt into a fresh tenant. It also serves the AI readiness that 28% of teams now name as a reason to migrate.

Just don't turn it into its own project. A cleanup that runs long will hold up a deal that has a date on it, and deleting isn't always yours to choose. Retention schedules, legal holds and records rules all have a say. Sort into three piles instead. Retire what nobody needs, archive what has to be kept but not used, and move what still earns its place.

IT operations survey
3 Strategic investment · This year

Build migration as a repeatable capability with verification built in

94% of organizations migrated something in the past two years and 35% of the biggest projects were driven by organizational change, which isn't going to stop. Treating each move as a bespoke project means paying the setup cost every time and relearning the same lessons.

A capability means: a standard approach documented and owned, tooling that handles identity and exceptions rather than only the happy path, the permissions and delegation layer in scope from the start rather than discovered mid-project, pre-migration cleanup as a standing step, and post-migration verification that proves what moved and what didn't. The verification piece is the one most often skipped and the one auditors ask about first.

The teams that build this stop treating the next acquisition as an emergency. It becomes a process with known stages, explicit assumptions, and a more defensible range for duration and risk. That's the difference between a migration capability and a migration crisis.

IT operations survey
ShareGate Migrate

Migrate covers the whole arc, not just the move. Surface the identities, permissions and conflicts before anything runs, move Entra ID, mailboxes, SharePoint, Teams and OneDrive in one workflow with permissions and version history intact, then validate what landed and save the plan for the next wave.

Discover ShareGate Migrate →