EdbMails EDB Recovery and Migration software
  • Products
    EdbMails
    All-in-one Recovery and Migration
    • EDB Recovery and Migration
    • OST, PST, MBOX, NSF, EML, MSG
    • Office 365, Exchange Migration
    • SharePoint, OneDrive & Teams
    • Google Workspace Migraton
    • IMAP Migration
    • Duplicate Remover
    • Windows Data Recovery
    • Backup Solutions
    • All ProductsAll Products

    EDB Recovery and Migration

    EdbMails lets you recover corrupted, damaged, and offline Exchange EDB files, convert EDB mailboxes to PST format, and directly migrate mailbox data to Office 365 and live Exchange Server.

    EDB to PST
    EDB to PST
    Recover corrupted, damaged, offline EDB files and convert Exchange EDB mailboxes to PST file format
    Public Folder to Exchange
    Public Folder to Exchange
    Migrate public folders from an Exchange offline EDB file to live Exchange Server
    EDB to Live Exchange Migration
    EDB to Live Exchange Migration
    Directly migrate offline Exchange database (EDB) files to live Exchange server
    Archive Mailbox to Office 365
    Archive Mailbox to Office 365
    Migrate archive mailboxes from offline EDB files directly to Office 365
    EDB to Office 365 Migration
    EDB to Office 365 Migration
    Directly migrate offline Exchange database (EDB) files to Office 365
    Public Folder to Office 365
    Public Folder to Office 365
    Migrate public folders from an offline Exchange EDB file to Office 365

    OST, PST, MBOX, NSF, EML, MSG Export and Migration

    EdbMails lets you to recover OST and PST files, export OST, PST, MBOX, NSF, EML, and MSG files to PST files, and directly migrate OST, PST, MBOX, and NSF mailbox data to Office 365 and live Exchange Server.

    OST Recovery and Migration
    OST Recovery and Migration
    Recover offline OST files, convert OST to PST, and migrate OST to Office 365 and Exchange Server
    PST Recovery and Migration
    PST Recovery and Migration
    Recover Outlook PST files , Export PST to PST, migrate PST to Office 365 and Exchange Server
    MBOX Export and Migration
    MBOX Export and Migration
    Export MBOX to PST, migrate MBOX to Office 365 and Exchange Server
    NSF Export and Migration
    NSF Export and Migration
    Export NSF to PST, migrate NSF to Office 365 and Exchange Server
    EML to PST Export
    EML to PST Export
    Convert EML files to Outlook PST files
    PST to MSG Export
    PST to MSG Export
    Convert Outlook PST file to MSG file format
    MSG to PST Export
    MSG to PST Export
    Export MSG files to Outlook PST files

    Office 365, Exchange Migration

    EdbMails lets you securely migrate mailboxes across Microsoft 365, Exchange, Google Workspace (Google Workspace Migraton), and IMAP-supported servers such as Outlook, Gmail, Zimbra, Zoho Mail, and cPanel, ensuring zero downtime.

    Office 365 Backup
    Office 365 Migration
    Migrate between Office 365 tenants, Office 365 to Exchange, Office 365 to PST, PST files to Office 365.
    Exchange Server Backup
    Exchange Migration
    Migrate between any Exchange Servers, Exchange to Office 365, Exchange to PST, PST files to Exchange.
    Tenant to Tenant Migration
    Tenant to Tenant Migration
    Migrate Mailboxes, Public Folders, Archive Mailboxes between Office 365 Tenants.
    Exchange to Office 365
    Exchange to Office 365
    Migrate Mailboxes, Public Folders, Archive Mailboxes from live Exchange server to Office 365.
    Office 365 to IMAP
    Office 365 to IMAP
    Migrate Office 365 to IMAP, Office 365 to Gmail, Office 365 to Outlook, Office 365 to Zoho etc.
    Exchange to IMAP
    Exchange to IMAP
    Migrate from live Exchange Server to IMAP servers such as Gmail, Outlook, and Zoho Mail.
    Public Folder to Office 365
    Public Folder to Office 365
    Migrate Public Folders between Office 365 tenants with complete folder hierarchy and mailbox data integrity.
    Exchange to PST
    Exchange to PST
    Export live Exchange Server mailboxes, public folders, and archive mailboxes to Outlook PST files.

    SharePoint, OneDrive & Microsoft Teams Migration

    EdbMails lets you migrate SharePoint sites, OneDrive data, Microsoft Teams, teams, channels, chats, permissions, and documents between Microsoft 365 tenants while maintaining the existing folder structure and data integrity.

    SharePoint, OneDrive & Teams Backup
    SharePoint Online Migration
    Migrate documents, lists, files and folders from SharePoint sites.
    OneDrive for Business Migration
    OneDrive for Business Migration
    Migrate documents, lists, files, folders, private chats from OneDrive.
    Microsoft Teams Migration
    Microsoft Teams Migration
    Migrate Teams, chats, channels, documents, files and folders etc.

    Google Workspace / G Suite Migration

    EdbMails Google Workspace Migration Tool migrates emails, calendars, contacts, and more from Google Workspace to Office 365, Exchange, and IMAP using a Google Admin account without requiring individual user credentials.

    G Suite Migration
    Google Workspace Migration
    Migrate emails, calendars, contacts, tasks from G Suite to Office 365, G Suite to Exchange, G Suite to IMAP Servers
    G Suite to Office 365
    Google Workspace to Office 365
    Migrate emails, calendars, contacts, tasks from Google Workspace / G Suite to Office 365
    G Suite to Exchange Server
    Google Workspace to Exchange Server
    Migrate emails, calendars, contacts, tasks from Google Workspace / G Suite to on-Premise Exchange Server
    G Suite to IMAP
    Google Workspace to IMAP
    Migrate emails, calendars, contacts, tasks from Google Workspace / G Suite to IMAP, Outlook, Zimbra, Zoho etc.

    IMAP Migration

    EdbMails IMAP Migration tool lets you easily migrate emails from IMAP servers such as Outlook, Gmail, Zoho Mail, Zimbra, cPanel, and more. Supports IMAP to IMAP, Office 365, Exchange Server, PST, and bulk PST to IMAP migration.

    IMAP Email Backup & Migration
    IMAP Email Backup & Migration
    Backup and migrate emails from IMAP servers to PST, Office 365, and On-Premises Exchange Server
    IMAP to Office 365
    IMAP to Office 365
    Migrate emails, folders, and attachments from IMAP servers to Office 365
    IMAP to Exchange
    IMAP to Exchange
    Migrate emails, folders, and attachments from IMAP servers to on-premises Exchange Server
    IMAP to PST
    IMAP to PST
    Export emails, folders, and attachments from IMAP servers to Outlook PST files for backup
    PST to IMAP
    PST to IMAP
    Migrate emails, folders, and attachments from bulk PST files to IMAP servers

    Duplicate Remover

    EdbMails Duplicate Remover lets you easily remove duplicate items from Office 365 and Exchange Server, and from IMAP, Outlook, Gmail, Zimbra, Zoho Mail, etc., ensuring a clean and organized mailbox.

    Remove Duplicates
    Remove Duplicates
    Easily clean up your Office 365, Exchange, Outlook and IMAP accounts by removing duplicate emails.
    Remove Duplicates from Office 365
    Remove Duplicates from Office 365
    Remove duplicate emails, calendars, contacts, journal tasks, etc. from Office 365.
    Remove Duplicates from Exchange Server
    Remove Duplicates from Exchange Server
    Remove duplicate emails, calendars, contacts, journal tasks, etc. from live Exchange Server.
    Remove Duplicates from IMAP, Outlook
    Remove Duplicates from IMAP, Outlook
    Remove duplicate emails, attachments from IMAP, Outlook, Gmail, Zimbra, Zoho Mail etc.

    Exchange, SharePoint, OneDrive, Teams and Office 365 Backup

    EdbMails enables secure, automated backup and recovery for Microsoft 365 services including Exchange Online, SharePoint, OneDrive, Teams, and Live Exchange Server with complete data protection and restore flexibility.

    Office 365 Backup
    Office 365 Backup
    Incremental, Granular, Encrypted and Compressed Office 365 Mailboxes Backup
    Exchange Server Backup
    Exchange Server Backup
    Incremental, Granular, Encrypted and Compressed Exchange Mailboxes Backup
    SharePoint, OneDrive & Teams Backup
    SharePoint, OneDrive & Teams Backup
    Backup Online site collections, Team sites, Office 365 groups, all documents etc.

    Windows Data Recovery

    EdbMails Windows Data Recovery Software lets you recover permanently deleted data, including photos, videos, documents, and archived files, from partitions on hard drives, SSDs, USB drives, SD cards, and external storage devices.

    Windows Data Recovery
    Windows Data Recovery
    Recover and restore permanently deleted data from hard drives, SSDs, USB drives, SD cards, and etc.
    Whitepaper Whitepaper
    Request a Demo Request a Demo
    Sign Up Sign Up
  • Features
  • FAQ
  • Offers
  • Pricing
  • Download
  • Support
  • Sign in
User’s Manual
Office 365 Migration

User Manual

User Manual

  • Office 365 Migration Overview
  • System Requirements
  • Migration Scenarios
  • Software Setup
    • EdbMails Installation Process
    • Upgrading the Software
  • Understanding the Application
    • Software's Main Components
    • Understanding the Migration
  • FAQ
    • General
    • Migration Free Trial / Demo
    • Migration License
    • Before Migration
    • Migration - Steps
    • After Migration
  • Videos
    • Office 365 to Office 365
    • Office 365 to Exchange
    • Office 365 to IMAP
    • Office 365 to PST
    • Public Folder to Office 365
    • Archive Mailbox to Office 365
    • Public Folder to Exchange
    • Archive Mailbox to Exchange
    • Restore Bulk PST files to Office 365
    • Automatically Create Office 365 Mailboxes
    • Export Office 365 user to CSV file
  • Screenshots
    • Office 365 to Office 365
    • Office 365 to Exchange
    • Office 365 to PST
  • How it works?
    • Office 365 to Office 365
    • Office 365 to Exchange
    • Office 365 to IMAP
    • Office 365 to PST
    • Public Folder to Office 365
    • Public Folder to Exchange
    • Public Folder to Shared Mailbox
    • Archive Mailbox to Office 365
    • Archive Mailbox to Exchange
    • Office 365 to Hosted Exchange
    • Multiple PST to Office 365
    • Office 365 to Gmail Migration
    • Office 365 Shared mailbox to Exchange
    • Office 365 Public folders to PST
    • Office 365 archive mailbox to PST
    • Office 365 Shared mailbox to PST
    • Office 365 shared mailbox to Public folder
    • Office 365 Archive mailbox to Shared mailbox
    • Office 365 Shared mailbox to Archive mailbox
  • Connect to source Office 365
  • Connect to target Office 365
  • Modern Authentication Using OAuth 2.0
    • Microsoft 365 modern authentication
    • Automatic Registration
    • Manual Registration
  • Connect to Exchange server
  • Knowledge Base
    • Migrate between Office 365 tenants
    • Migrate Office 365 mailbox
    • Public folder migration
    • Office 365 to Exchange Migration
    • Office 365 Migration with same Domain
    • Office 365 Group Migration
    • Selective Mailbox Migration
    • Migration to Exchange 2007, 2010, 2013, 2016 and 2019
    • User-Defined Mailbox/Folder Mapping
    • Export Office 365 users to CSV
    • GoDaddy to Microsoft 365 migration
    • Rackspace to Office 365 migration
    • Office 365 migration methods
    • Office 365 migration checklist
    • Migrate Shared mailbox to Office 365
    • Office 365 migration best practices
    • Office 365 migration challenges
    • Convert shared mailbox to regular mailbox
    • Office 365 to Exchange 2019 migration
    • Office 365 multiple mailbox migration
    • Office 365 Server to Server Migration
    • Cross-Tenant Office 365 migration
    • Office 365 to iCloud migration
    • Office 365 to Yahoo Mail migration
    • Office 365 to cPanel Migration
    • Office 365 to SmarterMail Migration
    • Office 365 to IceWarp migration
    • Create an Office 365 Migration Endpoint
    • Validate Office 365 Mailbox Migration
    • Office 365 Migration Network Requirements
    • Microsoft 365 Migration URLs & Endpoints
    • Office 365 Migration Firewall Ports
    • DNS Changes After Office 365 Migration
    • Autodiscover Troubleshooting After Migration
    • Post-Migration MX Record Validation
    • Office 365 Mail Flow Troubleshooting
    • Mailbox Permission Validation
    • EdbMails vs CodeTwo vs MigrationWiz vs Native Tools
    • Calendar Permission Migration Issues
    • Folder Permission Troubleshooting
    • Large Mailbox Migration Best Practices
    • Archive Mailbox Sync Issues
    • Office 365 Migration Coexistence
    • Cross-Tenant Mailbox Permissions
    • Cross-Tenant Calendar Migration
    • Migration Using App-Only Authentication
    • Office 365 Mailbox Mapping Errors
    • Exchange Online Migration Limits
    • Mailbox Integrity After Migration
    • Security Best Practices for Migration
  • Migration Types
    • Cutover Migration
    • Staged Migration
  • Set Exchange Server Impersonation rights
  • Map the Mailboxes
  • Migration Walkthrough
    • Office 365 tenant to tenant migration
    • Office 365 to Exchange migration
    • Office 365 to PST Export
  • Multifactor Authentication
    • Enable MFA in Office 365
    • Create App password for MFA
    • Disable Security Defaults
  1. Home
  2. Office 365 Migration
  3. Folder Permission Migration Troubleshooting | EdbMails
Download Buy Now

Folder Permission Migration Troubleshooting

Folder permission migration is the process of transferring mailbox folder access permissions from a source Exchange environment to a target Exchange or Microsoft 365 tenant during mailbox migration. These permissions determine which users or groups can access folders such as Inbox, Calendar, Contacts, Tasks, Notes, custom folders, shared mailboxes, and public folders. Preserving folder permissions ensures that delegated access, collaboration workflows, and mailbox sharing continue to function after migration.

Folder permission migration involves more than copying Access Control Entries (ACEs). During migration, permission identities must be mapped to valid recipients in the destination environment while maintaining the original permission levels. This process depends on mailbox availability, recipient resolution, folder hierarchy consistency, and supported Exchange permission models. Any mismatch between the source and destination environments can prevent permissions from being migrated correctly.

Permission migration failures commonly occur when destination objects cannot be resolved, folder paths differ between environments, delegated users have not yet been migrated, or Exchange APIs return incomplete permission data. Differences between Exchange Server versions, Exchange Online, hybrid deployments, and cross-tenant migrations can also affect how permissions are retrieved and applied.

Before migrating folder permissions in EdbMails Office 365 Migration Tool, verify that all required mailboxes, shared mailboxes, mail-enabled security groups, and distribution objects exist in the destination tenant. Performing these validation checks before migration significantly reduces permission-related errors and minimises the need for post-migration remediation.

  1. Common Causes of Folder Permission Migration Issues

    1. Missing Destination Mailbox or User Objects

    Folder permissions are assigned to security principals such as user mailboxes, shared mailboxes, mail-enabled security groups, and mail contacts. During migration, these identities must be matched with corresponding objects in the destination environment. If a referenced mailbox or recipient does not exist, Exchange cannot apply the permission entry because the security identifier (SID) or Microsoft Entra ID object cannot be resolved.

    Common scenarios include:

    • Delegated mailbox has not yet been migrated.
    • User account has been deleted or disabled.
    • Mail contact is missing.
    • Guest account is unavailable.
    • Mail-enabled security group has not been created.

    2. Folder Hierarchy Mismatch

    Folder permissions are associated with specific mailbox folders rather than the mailbox itself. If the destination mailbox contains a different folder hierarchy, Exchange cannot associate the permission with the intended folder.

    Hierarchy inconsistencies can occur when:

    • Custom folders were not migrated.
    • Folder names were renamed.
    • Folder paths differ between source and destination.
    • Folder creation order changed during migration.
    • Parent folders are missing.

    3. Unsupported Permission Levels

    Exchange supports a defined set of mailbox folder permission roles, including predefined roles such as Reviewer, Author, Editor, Publishing Editor, Publishing Author, Nonediting Author, Owner, and custom permissions based on individual access rights. During migration, unsupported or incompatible permission configurations may not translate correctly between environments.

    This is more common when migrating:

    • Between different Exchange Server versions.
    • From Exchange Server to Exchange Online.
    • Between separate Microsoft 365 tenants.

    In some cases, custom permission combinations are converted to the closest supported permission level or require manual reassignment after migration. Administrators should review folders that use customised access rights before beginning the migration.

    4. Shared Mailbox Permission Dependencies

    Shared mailboxes frequently contain delegated access for multiple users across departments. Folder permissions can only be restored if both the shared mailbox and every delegated user are available in the destination environment.

    Permission migration may fail when:

    • The shared mailbox is migrated after user mailboxes.
    • Delegated users have not yet been created.
    • Mailbox GUID mapping is incomplete.
    • Shared mailbox conversion has not completed.

    A recommended migration sequence is:

    • Create or migrate shared mailboxes.
    • Provision delegated user accounts.
    • Synchronise directory objects.
    • Apply folder permissions.

    Following this order ensures that Exchange can resolve all permission references during migration.

    5. Cross-Tenant Identity Mapping Limitations

    Cross-tenant migrations introduce additional complexity because source object identifiers are not preserved in the destination Microsoft 365 tenant. Although user principal names (UPNs), SMTP addresses, or mapping files can be used to associate users, Exchange cannot automatically translate every security principal from one tenant to another.

    Common examples include:

    • Different UPN suffixes.
    • Renamed user accounts.
    • Recreated mailboxes.
    • Missing external identities.
    • Tenant-specific object identifiers.

    Without accurate identity mapping, folder permissions referencing source users cannot be recreated automatically. Administrators should verify recipient matching before running the permission migration phase.

    6. Public Folder Permission Inconsistencies

    Public folders use a permission model that differs from standard mailbox folders. In addition to folder-level permissions, organisations often implement nested public folder hierarchies, mail-enabled public folders, and inherited access permissions.

    Migration issues commonly occur when:

    • Public folder hierarchy is incomplete.
    • Parent folders were not migrated.
    • Mail-enabled public folders are missing.
    • Legacy permissions reference deleted users.
    • Folder replicas are inconsistent.

    Because public folders often contain historical permission entries accumulated over several years, administrators should audit permissions before migration and remove obsolete or unresolved entries where possible.

    7. Mail-Enabled Security Group Resolution Failures

    Organisations commonly assign folder permissions to mail-enabled security groups instead of individual users. This simplifies permission management but introduces additional validation requirements during migration.

    Permission restoration can fail if:

    • The security group has not been synchronized.
    • Group membership is incomplete.
    • The group was recreated with a different object identity.
    • Mail-enabled attributes are missing.

    Even if the group name appears identical, Exchange validates the destination recipient rather than relying solely on the display name. Administrators should verify that all mail-enabled security groups are synchronized and fully functional before migrating folder permissions.

    8. Microsoft Graph and Exchange API Limitations

    Folder permission migration relies on Exchange Web Services (EWS), Microsoft Graph, or Exchange administrative APIs to enumerate mailbox folders and retrieve permission entries. Depending on the migration scenario, these interfaces may impose throttling policies, pagination limits, or permission scope restrictions.

    Examples include:

    • Temporary API throttling during large-scale migrations.
    • Incomplete permission enumeration due to insufficient administrative roles.
    • Delayed visibility of recently provisioned mailboxes.
    • Transient service errors when querying Exchange Online.

    To reduce API-related failures, ensure that the migration account has the required Exchange administrative permissions, allow sufficient time for directory synchronization, and perform migrations in manageable batches where appropriate.

    9. Permission Inheritance and Legacy Entries

    Mailbox folders can contain explicitly assigned permissions as well as inherited or legacy access entries accumulated over years of administrative changes. Some folders may reference users or groups that no longer exist in the organization.

    These legacy entries can lead to:

    • Unresolved security principals.
    • Invalid permission records.
    • Skipped permission assignments.
    • Partial migration results.

    Before migrating, review folder permissions and remove obsolete delegates, deleted users, or unsupported permission entries. Cleaning the source environment helps ensure that only valid permissions are transferred and reduces post-migration troubleshooting.

  2. Troubleshooting Folder Permission Migration

    When folder permissions are not migrated as expected, administrators should follow a structured troubleshooting process to identify whether the issue is related to the source environment, destination environment, identity mapping, or Exchange service limitations. Validating each component individually helps isolate the root cause and prevents repeated migration failures.

    1. Verify Destination Recipient Availability

    The first step is to confirm that every mailbox, shared mailbox, mail-enabled security group, and mail contact referenced in the source permissions exists in the destination environment.

    Verify the following:

    • User mailbox is provisioned and licensed (Exchange Online).
    • Shared mailbox exists and is accessible.
    • Mail-enabled security groups have synchronized successfully.
    • Mail contacts and guest users have been created where applicable.
    • User Principal Name (UPN) or primary SMTP address matches the intended destination recipient.

    If a recipient cannot be resolved, Exchange cannot apply the corresponding folder permission, and the migration application typically reports the entry as skipped or unresolved.

    2. Validate the Mailbox Folder Hierarchy

    Folder permissions are applied to specific mailbox folders. Even a minor difference in the destination folder structure can prevent permission assignment.

    Verify that:

    • All mailbox folders were migrated successfully.
    • Parent folders exist before child folders.
    • Folder names match exactly.
    • Folder paths remain unchanged.
    • Custom folders have been recreated correctly.

    3. Review Migration Logs for Permission-Related Errors

    Migration logs provide the most reliable method for determining why a permission entry was not migrated.

    Review the migration report for errors such as:

    • Recipient not found.
    • Folder not found.
    • Permission assignment failed.
    • Access denied.
    • Object resolution failed.
    • Insufficient permissions.
    • Throttling detected.
    • API timeout.

    Rather than focusing only on the overall migration status, review the detailed log entries associated with each mailbox. A mailbox may complete successfully while still containing skipped or failed permission entries. When using EdbMails, review the migration log after each migration batch to identify permission-related warnings before proceeding with additional mailbox migrations.

    4. Verify Administrative Permissions

    Folder permission migration requires administrative privileges to read permissions from the source environment and write permissions to the destination mailbox.

    Depending on the migration scenario, verify that the migration account has appropriate Exchange administrative roles.

    Examples include:

    • Full Access to the mailbox when required.
    • Exchange Organisation Management (Exchange Server).
    • Exchange Administrator role (Microsoft 365).
    • Application permissions when using Microsoft Graph.
    • Appropriate EWS access policies if Exchange Web Services is used.

    Insufficient permissions may allow mailbox data to migrate while preventing folder permissions from being enumerated or restored.

    5. Confirm Identity Mapping Accuracy

    Cross-tenant and hybrid migrations rely on accurate identity mapping between source and destination recipients.

    Verify that:

    • Source UPN matches the destination user.
    • Primary SMTP addresses are correct.
    • Mailbox aliases are unique.
    • User mapping files (if used) contain accurate values.
    • Duplicate recipient objects do not exist.

    Incorrect identity mapping is one of the most common causes of missing delegated access after migration. If recipients have been renamed during tenant consolidation, update the mapping information before rerunning the permission migration.

    6. Check Shared Mailbox Configuration

    Shared mailboxes should be fully operational before folder permissions are restored.

    Verify that:

    • The shared mailbox exists.
    • The mailbox has completed provisioning.
    • Delegated users exist.
    • Mailbox type is correctly configured as a shared mailbox.
    • Exchange Online synchronization has completed.

    Attempting to restore permissions before the shared mailbox becomes available may result in incomplete permission assignments.

    7. Validate Public Folder Permissions Separately

    Public folders use a different permission model from mailbox folders and should be validated independently.

    Confirm that:

    • The complete public folder hierarchy exists.
    • Parent folders were migrated first.
    • Mail-enabled public folders were recreated where applicable.
    • Legacy permission entries have been removed.
    • Replication has completed across Exchange servers, if applicable.

    Do not assume mailbox permission validation also confirms public folder permissions.

    8. Monitor Exchange Throttling and Service Limits

    Large-scale migrations may trigger Exchange Online throttling policies or API request limits.

    Common indicators include:

    • Temporary migration pauses.
    • Retry operations.
    • Delayed permission application.
    • Service unavailable responses.
    • Request timeout errors.

    If throttling occurs:

    • Reduce the number of concurrent mailbox migrations.
    • Migrate permissions in smaller batches.
    • Allow retry operations to complete.
    • Schedule migrations during lower activity periods where possible.

    Transient throttling errors often resolve automatically without requiring manual intervention.

    9. Perform Post-Migration Permission Verification

    After the migration completes, validate that permissions have been restored correctly rather than relying solely on migration reports.

    Verify the following:

    • Users can access delegated folders.
    • Calendar delegates retain their assigned access.
    • Shared mailbox folders open successfully.
    • Custom folder permissions match the source mailbox.
    • Public folder permissions are preserved.
    • Mail-enabled security groups continue to provide the expected access.
    • No folders display missing delegate information.

    Where practical, compare a representative sample of source and destination mailbox permissions to ensure that permission levels and assigned users are identical.

  3. Best Practices Before Folder Permission Migration

    Performing validation before migrating folder permissions significantly reduces permission mapping failures and minimises post-migration administrative effort. The following recommendations help ensure that the source and destination environments are prepared for a successful migration.

    • Verify recipient readiness: Confirm that all user mailboxes, shared mailboxes, mail-enabled security groups, distribution groups (where applicable), and mail contacts referenced in folder permissions exist in the destination environment.
    • Complete directory synchronisation: In hybrid deployments, ensure that Microsoft Entra Connect (or the applicable synchronisation solution) has completed successfully and that all recipient objects are synchronised before migrating permissions.
    • Migrate mailbox content before permissions: Folder permissions should be migrated only after mailbox folders and their hierarchy have been successfully copied. Missing folders can prevent permissions from being applied.
    • Review existing folder permissions: Audit mailbox folders to identify obsolete delegates, deleted users, unresolved security principals, and duplicate permission entries. Removing invalid permissions before migration improves migration accuracy.
    • Validate custom folder structures: Ensure that custom folders, nested folders, and non-default mailbox folders are included in the migration scope. Folder path discrepancies can prevent permission assignment.
    • Confirm administrative access: Verify that the migration account has sufficient Exchange administrative permissions to enumerate source permissions and write permissions to destination mailboxes.
    • Plan mailbox migration order: Where delegated access exists, migrate dependent mailboxes in a logical sequence. For example, migrate shared mailboxes and delegated user accounts before restoring folder permissions.
    • Perform a pilot migration: Test folder permission migration with a small set of representative mailboxes before processing the entire migration batch. A pilot migration helps identify mapping or configuration issues early.
  4. Best Practices After Folder Permission Migration

    After permissions have been migrated, perform validation to confirm that users retain the expected level of access and that no permission entries were skipped or incorrectly mapped.

    • Review migration reports for warnings, skipped permission entries, or unresolved recipients.
    • Compare a representative sample of source and destination folder permissions.
    • Verify delegated access for Calendar, Inbox, Contacts, Tasks, and custom folders.
    • Confirm that shared mailbox permissions have been restored correctly.
    • Validate public folder permissions separately from mailbox folder permissions.
    • Check that mail-enabled security groups continue to grant the intended access.
    • Remove obsolete permission entries that are no longer required.
    • Document any manually recreated permissions for future administrative reference.
    • Allow sufficient time for Exchange Online directory replication before performing final validation, particularly after large-scale migrations.
    • Retain migration logs until administrator validation is complete.

Conclusion

Folder permission migration is a critical component of Exchange and Microsoft 365 mailbox migrations because it preserves delegated access to mailbox folders, shared mailboxes, and public folders. Unlike mailbox data migration, permission migration depends on successful recipient resolution, consistent folder hierarchy, supported permission models, and adequate administrative privileges.

Most permission migration issues can be traced to unresolved destination recipients, missing mailbox folders, identity mapping inconsistencies, incomplete directory synchronisation, or Exchange service limitations. Following a structured troubleshooting approach—beginning with recipient validation, folder hierarchy verification, migration log analysis, administrative permission checks, and post-migration testing—allows administrators to identify and resolve issues efficiently.

Before running Folder Permission Migration in EdbMails, ensure that the source environment has been audited, destination recipient objects are fully provisioned, and mailbox data has been migrated successfully. After migration, validate delegated access using migration reports and functional testing to confirm that permissions have been accurately restored and that users retain uninterrupted access to the folders required for their daily operations.

 In this manual

IntroductionCommon CausesTroubleshootingBest Practices

Office 365 Migration

100 Mailboxes $299 Only

Buy Now

Need help?

24/7 Customer support

Contact us on Live chat

Personalized Demo

Book a personalized demo

Still need help?

Email us / Call us

@edbmails.com All rights are reserved Privacy Policy | Terms of Use | GDPR | Security | Press Releases

hidden msg
Live Chat

Hi, May I help you?

Hide Chat Now