Most Exchange to Exchange Online migrations fail not at the cutover, but during hybrid setup and mail-routing assumptions. Here's the sequence we use on financial-services and government tenants.
Phase 1 — Discovery
- Inventory mailboxes by type (user, shared, room, equipment, archive)
- Map distribution groups, dynamic DLs, public folders, journaling
- Document third-party integrations: Proofpoint, Mimecast, journaling, MFP scan-to-mail
- Confirm AD attribute hygiene (UPN match, proxyAddresses, mailNickname)
Phase 2 — Hybrid Configuration
- Run latest Hybrid Configuration Wizard (HCW) — minimal or full hybrid as required
- Validate Autodiscover, OAuth, free/busy lookup, and TLS chain
- Enable Modern Hybrid agent only if perimeter publishing is restricted
Phase 3 — Mailbox Migration
- Pilot 20–50 mailboxes across personas
- Schedule migration batches by department or load profile
- Set MaxConcurrentMigrations and bad-item limit appropriately
- Run staged cutover for archive mailboxes separately
Phase 4 — Mail Flow & Routing
- Decide centralized mail transport posture (EOP-first vs hybrid-first)
- Update Proofpoint or third-party gateway connectors
- Re-align SPF, DKIM, DMARC after MX cutover
- Test mail trace from external, internal, and journaled paths
Phase 5 — Validation & Decommission
- Confirm Outlook, mobile, OWA, MAPI/HTTP, and EWS clients function
- Move public folders last (if applicable)
- Decommission on-prem Exchange only after AD attribute management is solved (Exchange Management Tools server, or Microsoft's modern method)
CloudPair runs Exchange migrations during weekend and after-hours change windows — minimizing user impact for production environments.