Cross-tenant Mailbox Permission Migration
Cross-tenant mailbox permission migration requires administrators to identify mailbox access relationships in the source Microsoft 365 tenant and make sure the required permissions are correctly configured for the corresponding users and mailboxes in the target tenant. Common permission types include:
- Full Access permissions
- Send As permissions
- Send on Behalf permissions
- Folder-level shared access
During cross-tenant Office 365 migration, source and target identities belong to separate Microsoft 365 tenants. For that reason, mailbox content migration and target-side permission configuration should be planned and validated as separate parts of the project.
For the overall migration workflow, see Microsoft 365 tenant to tenant migration. Administrators who need the complete sequence can also follow the Office 365 tenant-to-tenant migration step-by-step guide.
Importance of Mailbox Permission Planning
Mailbox permissions often support shared mailboxes, delegated access, executive-assistant workflows, and team communication. If these relationships are not documented and validated during a tenant move, users may reach the target mailbox but still be unable to perform the actions they used in the source tenant.
- Full Access: Allows an authorized user to open and work with another mailbox. Confirm the required target user-to-mailbox assignments after migration.
- Send As: Allows a user to send a message that appears to come directly from another mailbox. Validate this permission separately in the target tenant.
- Send on Behalf: Allows a delegate to send on behalf of another mailbox or user. Check the corresponding target delegation after identities are available.
- Folder-level access: Review permissions on folders that are part of the business workflow and validate the required access in the target environment.
Challenges in Cross-Tenant Permission Migration
Permission planning becomes more complex when source identities, target identities, and mailbox relationships are not identical. Common considerations include:
- Separate tenant identities: A source user and a target user are different directory objects even when their names or addresses are similar.
- User mapping: Permission assignments depend on identifying the correct corresponding user or mailbox in the target tenant.
- UPN and address changes: Rebranding, domain changes, or different target naming conventions can make source-to-target matching less obvious.
- Complex delegation: Shared mailboxes and executive or departmental mailboxes may have several users with different permission types.
- Validation: Full Access, Send As, Send on Behalf, and folder-level access should be checked according to the permissions required in the target.
How to Handle Mailbox Permissions with an EdbMails Migration
EdbMails can be used for the mailbox migration workflow while administrators maintain clear source-to-target mappings and validate the required mailbox permissions in the destination. Treat mailbox data migration and Exchange Online permission configuration as related but separate tasks.
- Inventory source permissions: Record the source mailbox, assigned user or delegate, and permission type before migration. This provides a reference for target validation.
- Map source and target identities: Confirm that each relevant source mailbox and user corresponds to the intended target identity. Where applicable, use EdbMails mapping options, including user-defined mailbox mapping, to keep the migration scope aligned.
- Migrate supported mailbox data: Run the mailbox migration using the verified source-to-target mapping. Do not assume that migrating mailbox content automatically recreates every Exchange Online permission assignment.
- Configure required target permissions: After the corresponding target identities and mailboxes are available, configure the Full Access, Send As, Send on Behalf, delegate, or folder permissions required by the organization.
- Validate with target users: Test the actual actions that matter, such as opening a shared mailbox or sending with the required delegated identity. For a focused verification workflow, see mailbox permission validation.
- Use incremental migration for mailbox changes: The initial EdbMails migration is a full migration. Subsequent migrations using the same source and target from the previous migration on the same computer are incremental and process supported new or changed items according to the selected migration settings. Incremental mailbox migration should not be treated as automatic permission synchronization.
Prerequisites for Permission Migration
Before validating cross-tenant mailbox permissions, confirm the following:
- Administrative access required for the selected source and target Microsoft 365 migration workflow
- Corresponding target identities and mailboxes are available when permission assignments are configured
- Source-to-target mailbox and user mapping has been reviewed
- The required Exchange Online administrative permissions are available for target-side permission configuration
- Source permission assignments have been documented for comparison after migration
- Users selected for validation can sign in to the target environment and test the required delegated actions
Best Practices
- Export or document important source mailbox permission assignments before migration.
- Keep source and target user mapping consistent throughout the migration project.
- Test representative shared and delegated mailboxes before broad cutover.
- Avoid unnecessary identity changes while source-to-target mappings and permissions are being validated.
- Validate Full Access, Send As, and Send on Behalf independently because each permission enables a different action.
- After the initial full migration, run the migration again with the existing mapping close to cutover to capture supported new or changed mailbox items, and review the migration report before proceeding.
- Complete target permission checks before retiring the source environment.
Conclusion
Cross-tenant mailbox permissions need deliberate planning because source and target users are separate identities. A reliable process is to document source permission relationships, maintain accurate source-to-target mapping, migrate the supported mailbox data, configure the permissions required in the target, and validate those permissions with representative users. This keeps the permission-specific work aligned with the wider tenant migration without assuming that mailbox content migration automatically reproduces every delegation relationship.
