Exchange Server to Microsoft 365 Migration Checklist
Moving from on-premises Exchange Server to Microsoft 365? Use this checklist to assess server health, identity, mailboxes, shared mailboxes, public folders, applications, security, DNS and cutover before decommissioning Exchange.
Moving from on-premises Exchange Server to Microsoft 365? Use this checklist to assess server health, identity, mailboxes, shared mailboxes, public folders, applications, security, DNS and cutover before decommissioning Exchange.
Exchange Server decommissioning is irreversible. Do not retire the server until mail flow, shared mailboxes, public folders, SMTP relays and backup are confirmed working in Microsoft 365.
Business Case
- □ Define the reason for migration (end of support, cost, cloud strategy)
- □ Identify the executive sponsor
- □ Confirm critical dates and dependencies
- □ Record contractual obligations and compliance requirements
Source Server Health
- □ Confirm Exchange Server version (2016, 2019 or other)
- □ Review Windows Server version and patch level
- □ Check available disk space and CPU load
- □ Review event logs for recurring errors
- □ Confirm database health and replication status
- □ Record any existing connectors and transport rules
Tenant Ownership
- □ Confirm Microsoft 365 Global Administrator access
- □ Confirm domain and DNS control
- □ Verify target Microsoft 365 licensing plan
- □ Record delegated supplier responsibilities
Identity
- □ Confirm whether Active Directory is in use
- □ Confirm Microsoft Entra Connect (or Entra Cloud Sync) status
- □ Inventory on-premises user accounts to be migrated
- □ Inventory external contacts and distribution lists
- □ Map on-premises UPNs to Microsoft 365 sign-in addresses
- □ Confirm password synchronisation or pass-through authentication method
Mailboxes
- □ Inventory all user mailboxes and measure size
- □ Identify large mailboxes requiring staged migration
- □ Record archive mailboxes
- □ Review mailbox permissions (Send As, Send on Behalf, Full Access)
- □ Identify litigation holds and retention policies
- □ Confirm target Exchange Online plan supports required features
Shared Mailboxes
- □ Inventory all shared mailboxes
- □ Record shared mailbox permissions
- □ Identify which users require access after migration
- □ Confirm shared mailbox licensing requirements
Public Folders
- □ Inventory public folders and measure total size
- □ Review public folder permissions
- □ Decide whether to migrate or replace public folders (Teams, SharePoint)
- □ Test public folder access during the pilot
Applications and SMTP Relay
- □ Inventory line-of-business applications that send or receive email
- □ Identify printers, scanners and devices using SMTP relay
- □ Plan replacement SMTP relay for each application or device
- □ Record application dependencies on Exchange Web Services (EWS)
- □ Test application mail flow before cutover
Security
- □ Enable multi-factor authentication for all migrated accounts
- □ Configure Microsoft Defender for Office 365 or equivalent
- □ Review and configure anti-spam and anti-malware policies
- □ Confirm Microsoft 365 backup or retention is in place
- □ Remove or restrict on-premises administrator accounts post-migration
Email Authentication and DNS
- □ Plan MX record cutover timing
- □ Configure SPF record for Microsoft 365
- □ Configure DKIM signing in Exchange Online
- □ Configure DMARC policy
- □ Remove or update legacy SPF entries for on-premises Exchange
- □ Confirm Autodiscover DNS record update
Pilot
- □ Select representative pilot users across departments
- □ Migrate pilot mailboxes and test mail flow
- □ Test calendar, contacts and shared mailbox access
- □ Test public folder access if retained
- □ Confirm Outlook, OWA and mobile client connectivity
- □ Gather feedback and resolve issues before full cutover
Cutover
- □ Confirm cutover date and communicate to all users
- □ Update MX records to point to Exchange Online
- □ Update Autodiscover DNS record
- □ Confirm all in-flight messages are delivered
- □ Update SMTP relay settings for applications and devices
- □ Remove on-premises Exchange from send connectors
Validation
- □ Confirm mail flow in and out of Exchange Online
- □ Test shared mailboxes and calendar permissions
- □ Test public folders or replacement solution
- □ Confirm application and SMTP relay mail flow
- □ Test backup and restore
- □ Run Microsoft 365 mail flow reports
Decommissioning
- □ Confirm no mail is queued on the on-premises server
- □ Preserve backup of Exchange databases before decommissioning
- □ Remove or disable Exchange Server following Microsoft guidance
- □ Remove on-premises Exchange objects from Active Directory cleanly
- □ Obtain written sign-off before server retirement
- □ Document final state for compliance records
Plain-English Takeaway
Exchange Server decommissioning is irreversible. Confirm mail flow, shared mailboxes, public folders, SMTP relays, email authentication and backup before retiring the on-premises server.
Downloadable guide
Exchange Server to Microsoft 365 Migration Checklist
Download this checklist as a printable PDF to use with your team or migration partner.
Download PDF ChecklistFree to download. No registration required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Microsoft 365 Tenant Migration Readiness Checklist
A structured checklist for planning a move between Microsoft 365 tenants. Covers business case, tenant control, identities, Exchange, OneDrive, SharePoint, Teams, applications, devices, security, delivery, validation and decommissioning — with key reminders on identity mapping, compliance holds and source-tenant closure.
View guideGoogle Workspace to Microsoft 365 Migration Checklist
A structured checklist for planning a move from Google Workspace to Microsoft 365. Covers business case, tenant ownership, users, email and calendars, files, applications, target design, security, pilot, cutover, validation and controlled decommissioning — with key reminders on permissions, backup and retention.
View guideVulnerability Patch Wave Readiness Checklist
A structured checklist for assessing whether your organisation can prioritise, test and deploy security patches as AI-assisted vulnerability discovery increases the volume and frequency of updates. Covers assets, exposure, updates, prioritisation, testing, deployment, exceptions and unsupported systems.
View guide