Exchange Online Tenant-to-Tenant Migration Guide for 2026
Moving Exchange Online mailboxes between Microsoft 365 tenants is no longer just an export-and-import project. A successful 2026 tenant-to-tenant migration requires identity matching in Microsoft Entra ID, domain cutover planning, mailbox coexistence, licensing checks, security controls, and a tested migration runbook.
When Exchange Online tenant-to-tenant migration is needed
Exchange Online tenant-to-tenant migration is the process of moving mailbox services and related email configuration from one Microsoft 365 tenant to another. It is commonly required during mergers, acquisitions, divestitures, rebrands, regional tenant consolidation, private equity carve-outs, and Microsoft 365 standardization projects.
The useful core of the process has not changed: you still need to identify what must move, prepare the destination tenant, migrate data in controlled batches, cut over mail flow, and validate user access. What has changed is the preferred approach. In 2026, Microsoft-native cross-tenant mailbox migration is often the first option to evaluate, while third-party migration platforms remain useful for complex coexistence, broader workload migration, reporting, or scenarios that Microsoft-native tooling does not fully cover.
Choose the right migration approach
There are four common approaches:
Microsoft-native cross-tenant mailbox migration. This uses Exchange Online cross-tenant mailbox move capabilities, migration endpoints, organization relationships, application consent, mailbox matching, and migration batches. It is usually preferable when source and target tenants can be prepared according to Microsoft requirements and when mailbox moves are the main scope.
Third-party migration tools. These are often selected when the project includes complex coexistence, advanced scheduling, archive handling, public folders, reporting, large-scale permission mapping, or multiple workloads such as Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, and Microsoft 365 Groups.
Partner-assisted cutover migration. This is a practical option for organizations that need a controlled cutover window, MX spooling, reduced risk of non-delivery reports, helpdesk coordination, and experienced troubleshooting during the domain transition.
PST export and import. PST-based migration should be reserved for exceptional cases such as legal exports, isolated mailboxes, or recovery scenarios. It is not the preferred method for a modern Microsoft 365 tenant-to-tenant project because it can lose fidelity, adds security risk around exported files, and does not provide the same operational control as mailbox moves or migration platforms.
Current prerequisites for a Microsoft-native mailbox migration
Before migration, confirm the technical, licensing, and governance prerequisites. At minimum, you should plan for:
- Administrative access to both source and target Microsoft 365 tenants.
- Appropriate Exchange Online roles in both tenants, with least-privilege access rather than broad standing Global Administrator permissions whenever possible.
- Microsoft Entra ID identity matching between source and target users.
- Prepared target objects, commonly target mail users before mailbox moves are finalized.
- Correct source and target ExchangeGuid, archive GUID, proxy address, and legacyExchangeDN/X500 preservation where applicable.
- Accepted domains, target delivery/routing domains, and mail routing design.
- Organization relationships and required cross-tenant application consent.
- Migration endpoints and Exchange Online PowerShell configuration.
- Destination licensing for users and mailboxes, including Exchange Online service plans and any Microsoft cross-tenant user data migration add-on licensing that applies to the chosen migration method, tenant eligibility, and purchasing channel.
- New Commerce Experience (NCE) subscription planning if licenses are purchased through CSP. Because NCE commitments, cancellation windows, and seat reduction rules can affect cost, target licenses should be planned before staging and cutover.
- Pilot mailbox validation before production batches.
Do not assume that the same custom SMTP domain can simply be active in two tenants at the same time. Microsoft 365 custom domains generally cannot be verified and used simultaneously across two tenants. Most projects require a temporary target routing domain, staged recipient preparation, careful domain removal and addition sequencing, and a planned cutover window.
Discovery: decide exactly what must move
Exchange Online migration is more than primary user mailboxes. During discovery, document each object and setting that affects mail delivery, access, compliance, or the user experience:
- Primary user mailboxes.
- Online archive mailboxes and large archives.
- Shared mailboxes.
- Room and equipment mailboxes.
- Mailbox permissions, Full Access, Send As, Send on Behalf, delegates, and calendar permissions.
- Distribution groups, dynamic distribution groups, Microsoft 365 Groups, and mail-enabled security groups.
- Contacts and mail users.
- Public folders.
- Mail flow rules, connectors, accepted domains, remote domains, and transport settings.
- Exchange Online Protection and Microsoft Defender for Office 365 policies.
- Retention labels, retention policies, litigation hold, eDiscovery requirements, and inactive mailboxes.
- Journaling, disclaimers, signatures, and third-party mail security gateways.
- SMTP relay applications, multifunction devices, line-of-business systems, CRM tools, and ticketing systems.
- DKIM, SPF, DMARC, MX, Autodiscover, and other DNS records.
This scope drives tooling, timing, licensing, test cases, rollback planning, and user communication.
Recommended 2026 migration workflow
A modern Exchange Online tenant-to-tenant migration usually follows this sequence:
Assess and design. Inventory mailboxes, archives, permissions, groups, mail flow, compliance requirements, DNS, third-party integrations, and user locations. Define success criteria and rollback triggers.
Prepare identities. Create or synchronize target users in Microsoft Entra ID, map source-to-target identities, and verify that user principal names, primary SMTP addresses, aliases, and immutable references are handled correctly.
Plan licensing. Assign the required Microsoft 365 and Exchange Online licenses in the destination tenant. Validate any cross-tenant user data migration add-on requirements and NCE subscription constraints before production staging.
Prepare Exchange Online. Configure accepted domains, temporary routing domains, target mail users or mailboxes as required by the migration approach, organization relationships, migration endpoints, and application permissions.
Configure coexistence and mail routing. Decide how mail will flow before, during, and after cutover. For complex projects, use staged routing, connectors, forwarding, coexistence domains, or an MX spooler to reduce bounced mail during the transition.
Run a pilot. Move a small group of representative users, including executives, delegates, shared mailbox users, archive users, mobile users, and users with heavy calendars. Validate mail flow, Outlook, mobile access, permissions, calendar behavior, and archive access.
Migrate in batches. Use migration batches aligned to business units, locations, VIP groups, or support capacity. Monitor batch status, move reports, throttling, transient failures, and user impact.
Final sync and cutover. Complete delta synchronization, freeze risky changes where needed, move the SMTP domain, update DNS, and switch MX, Autodiscover, SPF, DKIM, and DMARC records according to the approved runbook.
Remediate clients. Prepare for Outlook profile changes, mobile device reconfiguration, cached credentials, add-ins, shared mailbox mappings, and user support tickets.
Validate and clean up. Confirm mail send and receive, delegate access, archives, shared mailboxes, mail flow rules, connectors, compliance settings, and third-party integrations before decommissioning the source tenant.
Domain cutover and DNS planning
Domain planning is one of the highest-risk parts of an Exchange Online tenant-to-tenant migration. The custom SMTP domain usually has to be removed from the source tenant before it can be added and verified in the target tenant. That means the cutover must be choreographed carefully.
Plan the following before the cutover window:
- Which temporary target delivery domain will be used before the final SMTP domain is attached.
- How users will be matched if the production domain is not yet available in the target tenant.
- When MX records will be changed.
- Whether an MX spooler or mail continuity service is needed to avoid non-delivery reports during DNS propagation and domain movement.
- Autodiscover behavior for Outlook and mobile clients.
- SPF record changes for all systems that send mail as the domain.
- DKIM key creation and enablement in the target tenant.
- DMARC alignment and reporting impact.
- Third-party mail gateway routing changes.
- SMTP relay updates for applications and devices.
A successful mailbox migration can still feel like a failed project if DNS, Autodiscover, and mail authentication are not ready.
Security and governance requirements
Modern tenant-to-tenant migrations should avoid legacy authentication patterns and unmanaged privileged accounts. Recommended controls include:
- Use least-privilege administrative roles and time-bound elevation where possible.
- Prefer app-based or certificate-based authentication for automation instead of long-lived passwords.
- Keep MFA and Conditional Access policies enabled, but test migration service accounts and migration applications so legitimate automation is not blocked unexpectedly.
- Review and approve cross-tenant application consent deliberately.
- Monitor audit logs, sign-in logs, mailbox audit events, and migration reports during the project.
- Limit access to exported data if third-party tools or PST files are used.
- Encrypt and securely delete temporary files after validation.
- Document who can access source and target mailbox data during the migration.
- Align migration actions with retention, eDiscovery, litigation hold, and data residency requirements.
Security planning should be part of the migration design, not an afterthought during cutover weekend.
Operational challenges and common issues
Common issues include mailbox throttling, failed migration batches, permission mismatches, missing X500 addresses, unexpected Outlook profile behavior, mobile device reauthentication, mail-enabled group gaps, and application relay failures.
Special cases require additional planning:
- Hybrid Exchange environments, where on-premises directory and Exchange attributes may still control cloud objects.
- Inactive mailboxes and mailboxes under litigation hold.
- Very large primary mailboxes or archives.
- Public folders.
- Microsoft 365 Groups and Teams-connected calendars.
- Delegated executive mailboxes and shared calendars.
- Teams meeting links and calendar dependencies.
- Cross-tenant collaboration remnants, guest users, and external sharing relationships.
- Third-party journaling, backup, signature, archiving, CRM, or security services.
Build time for retry logic, Microsoft 365 service health checks, move report review, and helpdesk escalation. Even well-designed migrations can encounter transient Exchange Online service throttling or data-specific failures that require analysis.
Post-migration validation checklist
After mailbox moves and domain cutover, validate more than mailbox count. Recommended checks include:
- Users can send and receive internal and external email.
- MX, Autodiscover, SPF, DKIM, and DMARC are correct.
- Outlook opens the correct mailbox and can create new mail, meetings, and searches.
- Mobile devices can connect after reauthentication or profile recreation.
- Shared mailboxes are visible and permissions work.
- Delegates can manage calendars and mailboxes as expected.
- Archive mailboxes are accessible.
- Room and equipment mailboxes process bookings.
- Distribution groups and mail-enabled security groups deliver correctly.
- Mail flow rules, connectors, disclaimers, and routing policies work.
- Microsoft Defender for Office 365 and Exchange Online Protection policies are active.
- SMTP relay applications and devices send successfully.
- Third-party integrations are reconnected.
- Retention, hold, and compliance settings are verified.
- Source tenant forwarding, temporary routing, and migration permissions are cleaned up only after validation.
Do not rush source tenant decommissioning. Keep the source tenant available until legal, compliance, technical, and business owners have confirmed that the migration is complete.
How IT Partner can help
IT Partner can assist with Exchange Online tenant-to-tenant migration planning and execution, including cutover mailbox migration, archive migration, Microsoft Entra ID transition planning, distribution list and group transition, DNS and mail flow planning, and MX spooling to reduce the risk of bounced email during domain cutover.
For broader tenant consolidation projects, Exchange Online should be coordinated with SharePoint Online, OneDrive, Microsoft Teams, Microsoft 365 Groups, Microsoft Entra ID users and groups, Entra External ID/B2B collaboration, application registrations, devices, Microsoft Forms, and Microsoft Viva Engage where those workloads are in scope.
Key takeaways
- Microsoft-native cross-tenant mailbox migration should be evaluated first for many 2026 Exchange Online tenant-to-tenant projects, but third-party tools and partner-led cutovers are still valuable for complex scopes.
- A custom SMTP domain usually cannot be active in two Microsoft 365 tenants at the same time, so domain removal, verification, MX cutover, Autodiscover, SPF, DKIM, and DMARC require a precise runbook.
- Migration planning must include identity mapping in Microsoft Entra ID, target object preparation, licensing under current Microsoft 365 and NCE rules, coexistence, security controls, pilot testing, and rollback planning.
- Mailbox data is only part of the scope. Archives, shared mailboxes, room mailboxes, permissions, groups, public folders, mail flow rules, connectors, compliance settings, and third-party integrations may all require separate handling.
- Post-migration validation should cover mail flow, Outlook and mobile access, delegates, archives, DNS, security policies, transport configuration, and application relay before the source tenant is decommissioned.
Planning an Exchange Online tenant-to-tenant migration? IT Partner can help you assess the source tenant, design the cutover, prepare Microsoft Entra ID and Exchange Online, migrate mailboxes and archives, and use MX spooling to reduce the risk of bounced email during the transition.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.