Security questions to answer before Microsoft 365 migration
A focused security and governance guide for tenant boundaries, permissions, data handling, logging, exceptions, and release trust.
Security planning begins with boundaries: whose tenant, whose data, whose approval, and whose responsibility. Use the following questions to expose assumptions early.
Access and identity
- Which accounts and roles can access source and destination tenants?
- What is the minimum permission required for each migration activity?
- How are privileged sessions approved, protected, monitored, and removed?
Data handling
- What data is read, staged, transformed, logged, or retained?
- Where does migration data travel and where can it persist?
- How are legal holds, retention, sensitive data, and residency addressed?
Exceptions and evidence
- Who can approve exceptions, and when do they expire?
- Which events and decisions are logged?
- What evidence supports validation and acceptance?
Application distribution
For a desktop application, publish the exact version, SHA-256 checksum, code-signing publisher, operating-system support, prerequisites, release notes, and a safe support route. Do not ask customers to bypass security warnings.