The situation
Aremco ran mail on an on-premises Exchange estate that had accumulated two decades of mailboxes, distribution lists, shared calendars and rules. The hardware was out of warranty, the Exchange version was approaching the end of its support window, and the team carrying it had one person who genuinely understood the routing.
The business problem was not really the mail server. It was that a single unplanned failure would have taken out the company’s primary communication channel with no documented path back, and everybody knew it.
What we did
Discovery before anything moved. We inventoried every mailbox, shared mailbox, distribution group, public folder and mail-enabled application — including the three line-of-business systems nobody had remembered were relaying through Exchange. That last category is what turns a clean migration into a Monday morning incident.
Identity first. Microsoft 365 migrations fail at identity far more often than they fail at mail. We established directory synchronisation with Microsoft Entra Connect, cleaned up the duplicate and orphaned accounts that had built up over the years, and designed Conditional Access policies before a single mailbox moved.
Microsoft’s own migration service, not a third-party copy tool. Mailboxes moved in batches through the Exchange Online Migration Service, so each one arrived with its history, rules and delegate permissions attached rather than being re-created at the far end. Coexistence ran throughout rather than a hard cutover, so migrated and unmigrated users kept seeing each other’s calendars and mail flowed correctly in both directions. That is more work to set up, and it is the reason nobody noticed the migration happening around them.
Two rehearsals. We migrated a pilot group, reverted it, fixed what we found, then migrated it again. The written cutover runbook and its rollback were both tested rather than assumed.
The weekend itself. The cutover ran to the plan rehearsed twice beforehand, with coexistence in place throughout so no mailbox was ever unreachable. Nobody returned on Monday to an account they could not open.
The outcome
- Every mailbox migrated with full history, rules and delegate permissions intact
- Zero hours of user-visible downtime
- Mail-enabled applications re-pointed and tested before users returned on Monday
- The tenant now runs inside Aaira’s Microsoft 365 managed service, with patching, backup and Secure Score handled continuously
Why it went well
Two things, both unglamorous. We spent longer on discovery than the migration itself took, which is why nothing surprised us at the cutover. And we rehearsed the rollback — not because we expected to use it, but because a plan you have not tested is a hope rather than a plan.
What we would tell you if you are considering the same move
Budget for the identity work properly. Almost every difficult Microsoft 365 migration we have inherited from another provider went wrong at directory synchronisation and account hygiene, not at mail. If a supplier’s plan does not spend real time there, that is the plan’s weakest point.