We still quote roughly thirty-five percent average infrastructure cost reduction across hybrid and cloud migration programs that were run honestly. After five-plus years of post-project audits, this post is the anatomy: where savings really came from, where costs merely moved, and how to promise responsibly in 2021 without becoming the vendor who sold fairy dust in 2016.
The buckets that actually shrink
Across government and enterprise programs (mailbox migrations at multi-thousand seat scale, private cloud rationalization, hybrid identity):
- Retired on-prem estates — Exchange, SharePoint farms, associated backup and DR shadows
- Avoided hardware refresh — timed migrations before major capital cycles
- Storage growth avoided — mailbox and content DB growth leaving tier-1 arrays
- DR contract reduction — less dual-datacenter scope when workloads leave
- License consolidation — sometimes; sometimes a wash or a raise depending on suite level
The 35% is a composite, not a law of physics. Programs timed wrong or lifted every VM untouched saw mid-single digits or temporary increases.
Where cost moves instead of vanishes
- Subscription opex replaces capex — finance must want that shape
- Network egress and premium SKUs surprise the unprepared
- 24/7 cloud VMs without autoscale recreate the always-on datacenter bill
- Security and logging tools billed per GB
- People — cloud done well needs engineers; it does not remove payroll
If you compare cloud opex to fully depreciated on-prem gear with no refresh in the model, you can “prove” anything.
How we promise now
- Range, not a single tattooed number
- Explicit assumptions (refresh horizon, growth, which workloads)
- Quarterly FinOps review after land
- Refusal to guarantee 35% on pure lift-and-shift IaaS
Case pattern that hits the band
Mailbox and collaboration to Microsoft 365, AD hybrid kept lean, file partially rationalized, DR shrunk, refresh cancelled. Not: every Oracle VM to largest D-series forever.
Extended practice notes (2021)
The remaining gap between a short checklist and a usable field note is usually scenario detail. In practice, the same engagement type described above still requires explicit answers to: what is in scope this quarter, what is deferred with a date, who can halt a wave, and how success is measured in production — not in a lab.
We document those answers before the first production change. When stakeholders disagree, the disagreement is resolved in writing, not on the bridge at cutover. That habit is independent of whether the workload is mail, identity, virtualization, desktop delivery, or security hardening.
Repeatable detail also includes communication: who tells users what changes, when the freeze starts, where status is posted, and how exceptions are requested. Technical excellence without communication still produces an outage from the user's point of view.
If you're facing this
If someone guarantees huge savings without a workload-level model, ask for the buckets. We still build migration business cases with audit trails — bring last refresh invoice and a list of what you refuse to retire.