Migration from On-Premises Infrastructure to Microsoft 365: Strategy and Compliance

July 08, 20266 min read
"Office 365""Cloud""Exchange""Compliance"

Migrating complex local environments to the cloud involves much more than just moving electronic mailboxes or syncing network directories. It requires a robust corporate compliance approach, stable digital identity control, and minimal disruption planning.

In this article, I discuss the methodological steps I followed to migrate corporate local structures to the Microsoft SaaS ecosystem, maintaining alignment with international ISO standards and ITIL best practices.

Migration Phasing

A successful hybrid or direct ("cutover") migration follows four well-defined stages:
  1. Discovery: Mapping active accounts, shared mailbox permissions, email traffic rules, and local storage sizes.
  2. Identity Synchronization: Configuring Microsoft Entra Connect (formerly Azure AD Connect) to synchronize the local Active Directory (AD) with the cloud directory.
  3. Pilot Migration: Transferring technology and leadership users to validate latency, MFA (Multi-Factor Authentication) policies, and mobile applications.
  4. Final Cutover: Adjusting public DNS records (MX, SPF, DKIM, DMARC) and final pointing of the corporate email flow.

Compliance and Conformity Assurance

During the transition in regulated companies (such as in the IMS - Integrated Management System of VA Engenharia), data protection and privacy are non-negotiable. We ensured compliance by implementing: Data Retention Policies: Configuring eDiscovery and litigation hold to ensure that historical data was not deleted improperly. Data Loss Prevention (DLP): Automated rules in the cloud to block external sharing of files containing proprietary or strategic engineering information.

Cutover DNS

Mail only moves when MX, SPF, and DKIM point at Microsoft 365. I publish the three together and only then lower the TTL.

example.com.  MX   0  example-com.mail.protection.outlook.com.
example.com.  TXT  "v=spf1 include:spf.protection.outlook.com -all"
selector1._domainkey.example.com.  CNAME  selector1-example-com._domainkey.example.z-v1.dkim.mail.o365.com.
dig +short MX example.com
dig +short TXT example.com

dig has to return the Microsoft MX before the on-premises Exchange is switched off. DMARC (v=DMARC1; p=quarantine) comes after SPF already passes, not in the same minute as the cutover.


Conclusion

The migration significantly reduced on-premises server licensing costs and eliminated the need for physical maintenance on internal Exchange servers, bringing scalability and high availability under hybrid cloud governance.

Related Articles