Share via

Migrating 2 companies to Exchange Online

JRV 561 Reputation points
2020-08-31T20:15:03.6+00:00

Company A and Company B have the same owners, AD Domain, on-prem Exchange server, and Exchange Online Protection tenancy. They each have their own email domain.

Company B is being spun off. The goal for this email project is to have two, separate MS365 tenancies.

Company A will keep its existing tenancy and migrate mailboxes to it from the shared on-prem Exchange server via Cutover Migration.

Company B will have a new tenancy and migrate mailboxes to it from the shared on-prem Exchange server via Cutover Migration.

When I use the term "Cutover Migration" I am referring to the process documented here: https://learn.microsoft.com/en-us/exchange/mailbox-migration/cutover-migration-to-office-365

There are really 2 parts to this: The Company B EOP migration while both companies' mailboxes remain on-prem, then the mailbox migration.

I can't set up Company B's domain in their tenancy while EOP is still filtering their mail from Company A's tenancy. MS365 won't allow the same domain to be associated with 2 tenancies. So I have to work around that.

This is the EOP migration plan I've come up with:

  1. Purchase EOP month-to-month for Company B mailboxes (month-to-month because it won’t be needed after mailbox migration; it’s included with MS365 mailboxes).
  2. Configure EOP for Company B tenancy to match relevant portions of EOP in Company A tenancy.
  3. Modify Company B SPF in advance to add new EOP in addition to existing.
  4. Following steps need to be done in one sitting to avoid outages:
    a. Point Company B MX to EOP host for Company B's tenancy.
    b. Change on-prem Exchange smarthost for Company B to EOP host for Company B.

So now, Company A's tenancy EOP should be performing inbound and outbound filtering for Company A, and Company B's EOP tenancy for Company B. Anyone see any problems with that plan?

----------

Now, we migrate both companies' on-prem mailboxes to their respective MS365 tenancies. I am hopeful that MS365 will allow me to do 2 Cutover Migrations simultaneously from the same on-prem server. Seems like that SHOULD be possible...but does anyone know for sure?

Assuming 2 tenancies can do Cutover Migrations from 1 on-prem Exchange, then this becomes the plan:

  1. Perform steps in https://learn.microsoft.com/en-us/exchange/mailbox-migration/cutover-migration-to-office-365, except that SPF and MX are already changed for Company B and they don't need to be for Company A because they're already set up for EOP.
  2. At "step 5: Route your email directly to Microsoft 365 or Office 365"
    a. Remove EOP connector in MS365 for Exchange
    b. Remove canyongl.com Send Connector (and smarthost) on Exchange.
    c. Remove EOP licenses as they’re no longer needed.
  3. Complete remaining steps in Cutover Migration.

Again...does this seem like it should work? I think the major question is if I can do a Cutover with 2 tenancies and 1 on-prem server, or if I have to do each tenancy separately.

Exchange Online
Exchange Online

A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.

0 comments No comments

3 answers

Sort by: Most helpful
  1. JRV 561 Reputation points
    2020-09-15T20:33:30.113+00:00

    Wow...I submitted this whole answer yesterday and it never showed up. Trying again.

    1. OK. I'd have figured the OA connection would look for SMTP addresses on the mailboxes and import only those. But sounds like this should work.
    2. OK.
    3. OK.
    4. While it is true that I can't verify @companyb.com in Tenant B while it's still associated with Tenant A, I can set up EOP in advance on Tenant B using the companyb.onmicrosoft.com domain. Then remove @companyb.com from Tenant A verify it on Tenant B, and immediately add it to EOP for inbound filtering. As I do so, while the Exchange server is still processing outbound messages, I will have to disable outbound filtering. That's because Exchange 2010 can't send messages from each domain through a different SmartHost. And Tenant A's SmartHost points specifically to their tenancy. Once @companyb.com is removed from Tenant A, the SmartHost will reject outbound emails from @companyb.com because they're from a domain that's no longer associated with Tenant A. Inbound doesn't have that problem: @companya.com and @companyb.com have their own MX's, and both MX's will end up pointing to the same host anyway. I can live without outbound filtering for duration of the migration. Will this not work?

    As for your other suggestions, any antispam installed on the Exchange server or an edge server will require an expensive product purchase and configuration. Any month-to-month hosted antispam will have the same Smarthost issue as EOP and require expensive configuration. So to me, the best option is to use EOP month-to-month for Tenant B until migration is completed.

    Was this answer helpful?


  2. JRV 561 Reputation points
    2020-09-02T14:54:09.94+00:00

    Thanks, KyleXu.

    We have about 60 mailboxes between both companies, so we're well within the Cutover limit. And we don't have any practical choice. I'd prefer to use Hybrid Exchange, but the Exchange server is damaged and we can't install Update Rollups. We have to be within the most recent 2 URs to use Hybrid, but we're many URs behind.

    "So, if you migrate two tenants at the same time, email address A and email address B mailboxes will be migrated twice." If the Company A tenancy has all users in Company A and none from Company B, it will still migrate email for Company B?

    "Cutover migrate to Exchange online one by one." I'm not sure what you mean by, "one by one".

    "Use EOP again." Don't MS 365 mailboxes include EOP?

    "Stop using the EOP briefly, using Edge server or other third-party tools to filter emails for Exchange on-premises." Why? I think I can see that I'd need to stop filtering outbound because I can't scope Send Connectors for messages sent from specific domains to specific EOP smarthosts. Not filtering outbound is not ideal, but I can live with it for a few weeks. I'd have the same issue regardless of the mail filtering service unless filtering was hosted on the Exchange server itself. Inbound filtering is the big need; inbound seems like it would work just fine. Am I missing something?

    Was this answer helpful?


  3. KyleXu-MSFT 26,406 Reputation points
    2020-09-01T06:35:21.33+00:00

    Now, we migrate both companies' on-prem mailboxes to their respective MS365 tenancies. I am hopeful that MS365 will allow me to do 2 Cutover Migrations simultaneously from the same on-prem server. Seems like that SHOULD be possible...but does anyone know for sure?

    Here are some limitation for Cutover Migration:

    1. It suggested migrated mailbox fewer than 150, otherwise, it will consume a lot of time.
    2. It will migrate all mailboxes. So, if you migrate two tenants at the same time, email address A and email address B mailboxes will be migrated twice.

    So, I would suggest you:

    1. Stop using the EOP briefly, using Edge server or other third-party tools to filter emails for Exchange on-premises.
    2. You will could remove EOP and verify domain in new tenant.
    3. Cutover migrate to Exchange online one by one.
    4. Using EOP again.

    If the response is helpful, please click "Accept Answer" and upvote it.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.