Large mailbox migrations fail for boring reasons: domains not ready, identity dirty, networking unknown, nobody owns licensing. Before a full Office 365 migration assessment (the kind we run for multi-thousand-seat estates), we run a tenant readiness checklist. This post is that gate — June 2016 field standard.
Domains
- Public DNS control proven
- Desired primary SMTP domains listed
- Onmicrosoft.com only as temporary — plan vanity domains
- SPF planning started (DKIM comes as features allow in your wave)
Identity
- Azure AD Connect strategy chosen
- UPN plan documented
- DirSync debt retired or scheduled
- Admin roles and break-glass concept started
Licensing and SKUs
- Who pays
- Which SKU for which population
- Trial vs production tenant discipline
- Whether education/government clouds apply
Networking foreshadow
- Internet egress capacity ballpark
- Proxy behavior for Microsoft endpoints
- Whether a VPN hairpin will punish clients
Full egress math lands in assessment; readiness flags obvious blockers.
Governance stubs
- Who is global admin (limit it)
- Naming for groups
- External sharing default intent
- Retention — even a one-line “TBD with legal by date X”
Tenant hygiene
- Name the production tenant correctly the first time
- Region selection conscious of data residency discussions
- Separate prod from endless demo trials
Exit criteria for “ready to assess”
When domains, identity direction, and executive sponsor exist, open the full assessment: mailbox stats, ADFS needs, pilot design, wave plan. If those three are missing, assessment becomes theater.
Naming and tenant lifespan
Tenant names and first domains are sticky. Avoid joke trials becoming production. Document the intended long-term vanity domains and who can approve DNS changes. DNS ownership fights have delayed more migrations than MRS throughput.
Pilot population design
Readiness includes naming the pilot group: IT plus one friendly business unit with real mail volume. Pilots that only use empty test accounts prove nothing about Outlook behavior or mobile devices.
Security baseline stubs
Even before full Conditional Access maturity, decide MFA pilot intent, admin account separation, and whether legacy protocols will be allowed. Security debt created on day one of the tenant lasts for years.
Cross-workstream RACI
Identity, messaging, networking, endpoint, and security each need a named lead. A single “Office 365 project manager” without technical leads produces status slides without decisions.
Entry into formal assessment
When readiness gates pass, the full assessment begins: detailed mailbox stats, ADFS necessity, network egress math, wave design, and pilot success criteria. Readiness is the on-ramp, not a substitute for assessment.
Scenario walkthrough
Consider a mid-size organization with hybrid identity, mixed desktop delivery, and a mandate to reduce risk without stopping the business. Week one is inventory and sponsor alignment. Week two is a written target state with two options and explicit out-of-scope items. Weeks three and four are pilot build and measurement. Only then does broad change begin. Compressing that sequence into a single weekend is how outages are born.
Along the way, three conversations dominate: who owns identity decisions, who pays for platform capacity, and what residual risk leadership accepts in writing. When those conversations are avoided, engineers improvise under pressure and the organization inherits accidental architecture.
We keep a living risk register with severity, mitigation, residual risk, and owner. The register is reviewed in the same meeting as the delivery burn-down. Risks that never move owners are the ones that become incidents.
If you're facing this
If someone scheduled a 15,000-seat migration kickoff without a tenant readiness pass, run this checklist first. We take programs from readiness through assessment and hybrid migration — bring DNS ownership proof and an identity decision-maker.