Transend’s response to COVID-19

×

Home / Platform Considerations

Microsoft 365 Considerations

When performing a migration of bulk users using a service account (so that you don’t need end-user passwords), you will need to assign an Application Impersonation role to your administrative account in Microsoft 365 (formerly called Office 365).

On this page:

Authentication

Assign impersonation to your migration account using the Exchange Admin Center, or use Exchange PowerShell. Impersonation allows you to migrate user accounts using the migration account so that you do not have to provide user passwords.

Setting up Impersonation in New Exchange Admin Center

We recommend creating a cloud-only service account with a mailbox and license from Microsoft 365 Admin Portal > Users. Disable Multi-factor authentication for this account.

  1. Click on More Features in the side navigator.
    Alt text
  2. Under Permissions, click Open.
    Alt text
  3. The permissions will open in the Classic Exchange admin center.
    Alt text
  4. Click on + plus sign to create a new admin role for the migration account.
  5. Under Roles click + plus sign to add Application Impersonation.
  6. Under Members click + plus sign to add the migration service account.
  7. Click OK
  8. Click Save
    Alt text

Setting up Impersonation in Classic Exchange Admin Center

  1. Click Show All.
    Alt text
  2. Scroll down in the side navigator.
  3. Click on Exchange to open the Classic Exchange admin center.
    Alt text
  4. Click on More Features in the side navigator.
    Alt text
  5. Under Permissions, click Open.
    Alt text
  6. Enter your preferred language and timezone and click Save.
  7. The permissions will open in the Classic Exchange admin center.
    Alt text
  8. Click on + plus sign to create a new admin role for the migration service account.
  9. Under Roles click + plus sign to add Application Impersonation.
  10. Under Members click + plus sign to add the migration service account.
  11. Click OK.
  12. Click Save.
    Alt text

Setting up Impersonation with Powershell

  1. Open the Exchange Management Shell
  2. Run the New-ManagementRoleAssignment cmdlet to add the permission to impersonate to the specified user
  3. Change “ServiceAccount” to the account you are assigning impersonation to

The following example shows how to configure Application Impersonation to enable an administrator account to impersonate all other users in an organization:

Example:

New-ManagementRoleAssignment –Name:impersonationAssignmentName –  Role:ApplicationImpersonation –User:serviceAccount  

Debug Application Impersonation Rights

Click on Service Account Access and perform the login test for the migration account:

https://testconnectivity.microsoft.com/

Migrate to/from an Online Archive

Microsoft 365 mailboxes have an affiliated Online Archive (In-Place Archive) that you can migrate data directly into our out of. To migrate data into or out of the Online Archive, rather than the live mailbox, follow these steps in Transend Migration Console:

  1. Go to the Optional Confiuration Settings page.
  2. In the Basic Options tab, select the Migrate from Online Archive checkbox or Migrate to Online Archive checkbox, depending on your migration scenario.
  3. After the appropriate checkbox is selected, click Continue to complete configuration of your migration.

Alt text