Every chapter, every chart, and the full methodology in one file. One email address.
Loading form…
06
How IT teams plan, tool, and run Microsoft 365 migrations in 2026
94% of organizations moved something in the past two years. Only 7% would do it the same way again.
of the biggest migrations were driven by org change, not technology strategy
want identity prep inside their migration tool. 11% have it
Shadow IT doubles between teams running one migration and teams running three
Most teams are running more than one migration at a time and starting the next one before the last finishes. This chapter is about what that costs, what teams wish they'd done differently, and which step reliably hurts the most.
Cloud migration has a finish line. Corporate change doesn't. Mergers, divestitures and restructures keep starting tenant-to-tenant work, and they arrive on someone else's timetable with a deadline already attached.
83% want identity preparation handled inside their migration tool. 11% have it there. That's the widest want-versus-reality gap in this data, and it sits on the step teams already name as the hardest part of a tenant move.
Third-party tool use runs from 41% among teams doing one kind of migration to 79% among teams doing three or more. The same pattern holds inside every company size band. The teams doing the most are also the most likely to say they should have bought sooner.
Every stat on this page comes from the IT operations survey (n=943). Full methodology →
This is Chapter 6 of The State of Microsoft 365, a report on how organizations run, secure, and migrate in 2026. Learn more →
The M365 Governance Index scores the estate it lands in, from visibility and tenant control to incident resilience, against 943 IT pros. Then it tells you what the most effective teams do differently.
Migration is the most misunderstood work in this report, because almost everyone still describes it as a project. Projects end. This doesn't.
Once compliance clears the path, the work becomes movement CH 5Compliance→. And the movement does not stop. Organizations acquire, divest, restructure, consolidate, and modernize on a rolling basis, and each of those events produces a migration. The data shows teams working through several, finishing one and starting another, and consistently wishing they'd treated it as a capability the first time round.
What types of migrations has your organization completed, started, or planned in the past 24 months?
Teams run ~2.5 migration types every two years. One-and-done is a myth.
IT operations survey94% of organizations migrated something in the past two years, and those that did averaged 2.5 migration types completed, underway, or planned across the 24-month period. 6% stood still. Of the teams that moved anything, 81% ran two or more kinds of migration inside the same 24 months and half ran three or more. That's the case for treating migration as an operating capability rather than an event: the average team isn't between migrations, it's working through two or three of them.
Laura Rogers sees the same pattern from inside the projects.
Most teams still treat migration as something with a finish line. Move the content, move on. The successful ones build the ownership and the processes that make the next change easier, because there's always a next change.”

Which of the following best describes your organization's most significant migration project in the past 24 months, the one that consumed the most time, budget, or attention?
Half are still the classic lift to the cloud. But a quarter of the most significant projects were a merger, acquisition, or divestiture. That's the move that restarts the migration, governance, and cost clocks at once.
IT operations survey · the 889 who ran a migrationNearly a quarter of organizations say their biggest migration was driven by a merger, acquisition, or divestiture. The cost chapter found that cost pressure is a moderate or major driver of migration and consolidation for 88% of organizations, and duplicate M&A tenants are among the largest cost lines in the estate CH 2The AI reckoning→. The two findings describe the same cycle from different ends. Add consolidation and restructure work and 35% of the most significant projects were driven by organizational change rather than technology strategy.
This is the structural reason migration never ends. Cloud migration has a finish line, at least in principle. Corporate change does not. As long as organizations keep buying, selling, and reorganizing, tenant-to-tenant work keeps arriving. It arrives on someone else's timetable, with a deal deadline attached.
Constant motion leaves a trace. Teams that ran three or more kinds of migration in the past two years are more likely to report a governance incident than teams that ran one: 83% against 68%. The sharpest split is shadow IT and shadow AI, where people pick up tools, apps or automations outside IT's line of sight. That one doubles.
Sixteen percent of teams running a single migration reported it. Thirty-two percent of the heaviest movers did.
IT operations surveyThe survey can't tell you which way that runs. Repeated migration may leave sprawl behind, or the teams generating the most sprawl may be the ones restructuring most often. Both are plausible, and the pattern shows up in all five company size bands. What it does establish is that heavy migration activity and governance debt turn up in the same places.
We asked the MVPs why that debt accumulates rather than clears. David Drever put it down to change management rather than tooling.
The organizations that do this well take the time to get compliance-ready, then move into a controlled environment and keep it that way. Where it fails is where compliance was pushed onto people without anyone explaining why. Then all that work quietly decays, because nobody understands what they are maintaining.”

Decay is the right word for it. 77% of organizations reported a governance incident in the past year, and the teams moving most often are the ones furthest into that number CH 3Governance→.
Planning benchmarks matter when the timeline is set by a deal rather than by IT.
How long did this project take from kickoff to completion?
Half land in the three-to-six month window. But 36% run longer than that and one in ten past a year, long enough for the estate to change underneath them.
IT operations survey · the 889 who ran a migrationMost projects land in the 3 to 6 month band, but more than a third take seven months or more, including 10% that exceed a year. Read that against the M&A finding and the tension is obvious: a significant share of migrations are triggered by transactions whose integration deadlines are set in a boardroom, and the typical project takes half a year. Teams who haven't pre-built the capability are being asked to compress a six-month process into whatever the deal timeline allows.
| Most significant project | n | Ran seven months or longer |
|---|---|---|
| On-prem to cloud | 435 | 34% |
| Merger, acquisition, or divestiture | 214 | 39% |
| On-prem to on-prem | 136 | 35% |
| Consolidation or restructure | 96 | 41% |
| Other | 8 | 75% |
| Sample average | 889 | 37% |
Last year's report asked the same question of M&A migrations, so that's the one group where the two years compare. One band moved enough to mention.
The fast M&A migration is thinning out: 23% → 12% finish inside three months.
Treat that as a direction rather than eleven exact points: last year's figure comes from a dedicated M&A module of 520 people, this year's from the 214 whose biggest project was a deal. The other bands drifted a few points each and none of them says much on its own. What thinned out is the quick one.
Teams could name up to three reasons. One of them is new this year.
What drove the need for this migration project? (choose up to three)
Security still leads, but AI readiness is now a named reason to move (28%).
IT operations surveySecurity and scalability remain the top two, as they were last year, though they've swapped places: in 2025 scalability led at 65% with security a point behind at 64%. Every driver scores lower in absolute terms this year, which likely reflects a change in how the question was asked rather than a collapse in motivation, so read the ranking rather than the levels. The newcomer worth watching is AI readiness, now a named driver for more than a quarter of organizations.
Two years ago AI readiness wouldn't have appeared on this list. It's now cited more often than end-of-support deadlines, and it connects this chapter directly to the first: content has to be somewhere Copilot can reach it, governed well enough that reaching it is safe CH 1Confidence ≠ control→.
Mike Maadarani described what that looks like at the moment of the move.
Migrate stale content into a tenant with Copilot switched on and it will be indexed unless you have deliberately excluded it. You are not just moving old data, you are deciding what to feed your AI.”

Scoping a tenant move starts with this list, and it runs longer than most teams expect.
What workloads were (or will be) included in this tenant-to-tenant migration?
The 'mailbox move' is now a whole-estate move.
IT operations survey · the 310 running a tenant-to-tenant move⚠ SMALL SAMPLE (n=) — READ AS DIRECTIONAL
Power Platform tops the list. That should reset the scoping conversation. The assumption that tenant-to-tenant work is mostly mail and files is out of date, and it's the assumption most likely to produce a mid-project surprise. Apps, flows, and connectors are the most commonly in-scope workload, they hold their own permissions and connections, and they're frequently owned by someone outside IT who built them for a purpose nobody documented. The estate chapter covers what this says more broadly CH 4The estate→.
A third of these projects also involve Google Workspace, which is worth noting for anyone assuming cross-platform work is a niche case.
Power Automate flows are also the example named in the shadow IT question earlier in this chapter, the incident type that nearly doubles as migration volume rises. The workload teams most often have to move is the one they're least likely to have documented.
Most teams don't pick a tool. They pick several.
Native tooling went up, not down. Third-party use rose alongside it rather than instead of it.
IT operations survey · 2026 n=889 · 2025 n=636That's the shape of a field where teams are stacking approaches rather than swapping them, which is what you'd expect from teams running two or three kinds of migration every two years. Native tools are the floor almost everyone builds on. What changes is what gets added on top, and how soon.
We asked the teams who'd already finished one what they'd change.
Looking back, what would you have done differently? (choose up to two)
Planning earlier tops the list. But buying real tooling sooner is right behind it, and cleaning up first is level with that.
IT operations survey⚠ SMALL SAMPLE (n=) — READ AS DIRECTIONAL
Only 7% would change nothing. The top three regrets are all the same shape: plan earlier, tool earlier, clean up earlier. Hindsight is the most honest advice in any survey, because the person giving it has already paid for the lesson. Three of the top four answers describe work that should have happened before the project started.
Not the size of the company. How much migration it runs.
Run one kind of migration and it's a coin flip. Run three or more and it's close to a certainty.
Used at least one third-party migration tool.
IT operations surveyThe obvious objection is that this is really a story about company size. Bigger companies run more migrations and buy more software. It isn't. The same pattern shows up inside every size band in the study, and it's widest in the largest one.
Among companies with 3,000+ employees, buying runs from 21% at one migration type to 73% at three or more. Those companies are 25% of the one-type group and 23% of the three-or-more group, so the mix barely moves.
IT operations surveyThe regret climbs the same way. Among teams that ran one kind of migration, 27% wish they'd bought tooling sooner. At three or more, 43%. Over the same range, the share saying nothing went wrong halves.
| Migration types run | n | Used a third-party tool | Wish they'd bought sooner | Nothing went wrong |
|---|---|---|---|---|
| Ran one migration type | 166 | 41% | 27% | 10% |
| Ran two types | 279 | 63% | 36% | 6% |
| Ran three or more types | 442 | 79% | 43% | 5% |
| Sample average | 943 | 63% | 38% | 7% |
Split the same question by what teams actually bought and the answer lands in a place worth sitting with.
| Group | n | Wish they'd bought sooner |
|---|---|---|
| Native tools only | 162 | 25% |
| Any third-party tool | 427 | 45% |
| ShareGate users | 201 | 47% |
| Sample average | 629 | 38% |
The M365 Governance Index ranks your widest gaps by how far they sit behind the field, so you can work the list before the next migration instead of after it.
Ask what actually hurts in a tenant-to-tenant move and identity surfaces immediately.
How difficult is (or was) the identity preparation step—ensuring users exist and are properly configured in the destination tenant before moving workloads like mailboxes?
36% find it difficult or the single hardest part. Only a quarter found it easy.
IT operations surveyHow important is it that your migration tool can handle identity preparation as part of the same workflow as content and mailbox migration?
83% want it in the same workflow. Set that against the 43% who still prepare identities by hand.
IT operations survey36% find identity preparation difficult or the single hardest part. Another 40% call it manageable while noting it could be easier, which is a polite way of saying it works but costs more than it should. More than four in five want identity preparation handled inside the migration tool rather than bolted on. Now the number that turns that preference into a gap.
The widest want-versus-reality gap in the migration data, and the reason the difficulty scores sit where they do.
Teams who called a unified workflow critical or very important, against teams whose actual method is a migration tool with identity prep built in. Both questions went to the 310 teams that ran tenant-to-tenant work.
IT operations surveyWhen preparing for this tenant-to-tenant migration, how did your organization handle identity preparation (creating users, mapping groups, assigning licenses in the destination tenant)?
Microsoft's cross-tenant tools lead. But 43% still assemble identities manually, by script, or with no defined process at all. 83% say they want it inside the migration tool.
IT operations survey · the 310 running a tenant-to-tenant moveThat gap explains the difficulty scores above. More than four in ten teams are doing identity prep in a separate Microsoft tool, and another 41% are doing it by hand in the admin center or with scripts. The step teams find hardest is the step most often handled outside the workflow that everything else runs in.
| Identity preparation method | n | Difficult/Hardest | Easy |
|---|---|---|---|
| Using Microsoft's cross-tenant migration tools | 128 | 34% | 19% |
| Manually through the Microsoft 365 admin center or Azure portal | 86 | 35% | 33% |
| Using a third-party migration tool that includes identity migration | 34 | 32% | 38% |
| Using PowerShell scripts | 42 | 41% | 17% |
| Relying on an external partner / consultant | 14 | 29% | 29% |
| We don't have a defined process, it's ad hoc | 5 | 80% | 0% |
| Not sure | 1 | 100% | 0% |
| Sample average | 310 | 36% | 25% |
The difficulty does track with the method, though the bases get small quickly. Teams using PowerShell scripts report the most difficulty, while the small group with identity built into their migration tool reports the highest ease. That last group is only 34 people, so read it as a direction, not a decimal.
What were the biggest challenges during this project? (choose up to two)
Complexity, downtime and compliance validation lead. Permissions work sits well down the list, and it is the thing teams say blows up timelines. That gap is worth asking about.
IT operations survey · the 889 who ran a migration projectWhat were the biggest challenges during this project? (choose up to two)
Identity and permissions take two of the top three spots on the deal-driven challenge list, on a timeline set by a transaction rather than by IT.
IT operations survey · the 318 whose biggest project was a deal⚠ SMALL SAMPLE (n=) — READ AS DIRECTIONAL
Identity and permissions occupy two of the top three. M&A projects also run longer. 39% pass the six-month mark against 34% of on-premises-to-cloud moves, on timelines usually set by a transaction rather than by IT.
The planned, happy-path portion of a migration, the part every tool demos well, rarely breaks a project. What breaks projects is everything that wasn't fully scoped: the customization nobody documented, the permission that doesn't map, the Power Platform flow that surfaces halfway through, the coexistence window that runs longer than planned.
What are the biggest challenges you face (or faced) specifically with the mailbox migration portion of this project? (choose up to two)
Downtime leads, but destination identity prep (38%) and coexistence (36%) come straight after it. Those are the two things nobody puts on the plan.
IT operations survey · the 126 whose project included a mailbox moveSHOWING EVERYONE — NO SPLIT FOR THIS CHART
The mailbox picture reinforces it: identity prep is the second-largest challenge, and coexistence, which is largely an identity and routing problem, is third. Which reframes what tooling is actually for. Automating the predictable steps has value, but the predictable steps were never the risk. The tooling that earns its cost is the tooling that absorbs the exceptions, and it earns it repeatedly, because a team running 2.5 migration types every two years will meet those exceptions again.
Every migration I've seen go sideways went sideways in the last ten percent. The content moves fine. Then you find the workflow nobody documented, the group that doesn't map, the mailbox with twelve years of delegation on it. Teams budget for the ninety percent because that's the part you can estimate, and then the exceptions eat the timeline. The tooling question isn't "can it move the data". Everything moves data. It's "what happens when something doesn't fit".”

Visibility and tenant control are two of the ten dimensions the M365 Governance Index scores. Answer the same questions these 943 IT pros answered and see which of yours sit furthest behind theirs.
Did you involve an external partner (IT consultant, VAR, or MSP) in this project?
77% ran their most significant migration entirely in-house. Fewer than one in ten brought a partner into both planning and implementation.
IT operations survey · the 889 who ran a migrationSHOWING EVERYONE — NO SPLIT FOR THIS CHART
How likely is your organization to engage an external partner to conduct an AI governance assessment before scaling AI use?
86% are likely to. Only 4% rule it out.
AI governance surveySHOWING EVERYONE — NO SPLIT FOR THIS CHART
77% of teams handled their biggest migration entirely in-house. Ask the same kind of question about AI governance and 86% say they'd bring in a partner.
Two surveys, two questions, so this isn't anyone changing their mind. But it's a clean read on what teams think they've got covered. AI governance is new, so it gets help. Migration is familiar, so it doesn't.
Familiar is doing a lot of work in that sentence. Only 7% of teams would run their last project the same way again. 45% of the ones who bought tooling wish they'd bought it sooner. 29% of that same AI group has already had an exposure incident CH 1Confidence ≠ control→. And when teams do bring a partner in, they rarely do it for one phase. It's planning and implementation together, or the whole thing, which is what you'd expect from work that turned out to be bigger than it looked.
Not what you're migrating now. What's coming: the acquisition in diligence, the tenant you inherited and never consolidated, the file shares still sitting behind the last project, the workloads that hit end of support next.
Most teams have never written this list down, which is precisely why each migration feels like a surprise. A single page changes the conversation from "how do we get through this one" to "what capability do we need". For each likely migration, capture the trigger and target date, source and destination, workloads and approximate scale, identity and domain dependencies, compliance constraints, business owner, confidence in scope, and current planning stage.
83% want identity handled inside the tool and only 11% have it there. That's the widest want-versus-reality gap in this data. If your process still involves a separate admin center or script stack for identity mapping, that's the highest-value thing to consolidate, especially if deal-driven work is in your future, where identity and permissions take two of the top three reported challenges.
Pair it with content cleanup, which 36% of teams wish they'd done more of beforehand. Sorting before you move usually beats sorting after: you move less, you move cleaner, and you don't carry a decade of permission debt into a fresh tenant. It also serves the AI readiness that 28% of teams now name as a reason to migrate.
Just don't turn it into its own project. A cleanup that runs long will hold up a deal that has a date on it, and deleting isn't always yours to choose. Retention schedules, legal holds and records rules all have a say. Sort into three piles instead. Retire what nobody needs, archive what has to be kept but not used, and move what still earns its place.
94% of organizations migrated something in the past two years and 35% of the biggest projects were driven by organizational change, which isn't going to stop. Treating each move as a bespoke project means paying the setup cost every time and relearning the same lessons.
A capability means: a standard approach documented and owned, tooling that handles identity and exceptions rather than only the happy path, the permissions and delegation layer in scope from the start rather than discovered mid-project, pre-migration cleanup as a standing step, and post-migration verification that proves what moved and what didn't. The verification piece is the one most often skipped and the one auditors ask about first.
The teams that build this stop treating the next acquisition as an emergency. It becomes a process with known stages, explicit assumptions, and a more defensible range for duration and risk. That's the difference between a migration capability and a migration crisis.
Migrate covers the whole arc, not just the move. Surface the identities, permissions and conflicts before anything runs, move Entra ID, mailboxes, SharePoint, Teams and OneDrive in one workflow with permissions and version history intact, then validate what landed and save the plan for the next wave.
Discover ShareGate Migrate →