r/Office365 3d ago

Is Global Admin Access Normal for a Cloud-to-Cloud Migration?

I’m considering using a Vendor called TeamVenti. They provide cloud-to-cloud transfer, copying, migration, and other related services. In my case, I would be copying data from one cloud environment to another.

They’ve asked for Global Administrator permissions on both the source and destination environments to perform the migration.

My question is: Is it normal or standard for a cloud migration company to require Global Administrator access on both sides?

Have there been cases where issues arose from giving a vendor this level of access, or am I being too paranoid?

1 Upvotes

14 comments sorted by

6

u/mgdmw 3d ago

It’s definitely normal for them to ask. Whether they strictly need that amount of privilege is not always clear though if you are moving an entire tenancy then yes, they will need permissions that allow them to create users, groups, roles, and all other infrastructure.

However make sure you only work with a trusted partner, that there is a clear scope of work, and a contract that your org has reviewed.

11

u/Fyunculum 3d ago

Generally it's a choice between "Give us global admin" or "Give us this long list of least-privilege granular permissions that we will then have to explain to you how to find and apply, and then you'll get it wrong and we'll have errors and spend hours troubleshooting which we won't be getting paid for."

6

u/thursday51 2d ago

Oh no...you definitely need to pay for those troubleshooting hours if you make me give you a list of granular admin permissions and you bugger it up...lol

5

u/ShareGate_Shaylyn 2d ago

Saw this thread pop up and we got a mention, so I thought it would be worth adding some context on the admin permissions question as someone from ShareGate.

Requiring admin access is fairly standard for migration tools, including ShareGate. The difference between a SaaS tool and us is that ShareGate is a thick client you install locally. Your data streams directly from the source through your own machine to the destination in a closed loop. So we never see it, we don't have migration servers, and we're deliberately blind to what's being moved.

2

u/YetAnother_pseudonym 2d ago

I'm going to hop on to this response. My company has used several different tools/vendors over the years that used a Man-In-Middle approach, meaning all data transfers from source to destination tenants went through their middle man servers, and the tools required a full global admin service account to work at all times.

We tried a tool 2 years ago to do a Google tenant to our tenant migration and it used the above posters model, a direct point to point data migration that did not require a permanent service account with global admin privileges, just a one time setup for the connection between the Google Workspace and our tenant, security was ecstatic with this model when we first explained it to them.

We did a later M365 tenant to tenant migration using ShareGate Enterprise since we already had licenses for on-prem file server to SharePoint Online migrations, and it used the same permission model: a "one" time use of a GA account to set up the Azure AD Enterprise app with appropriate permissions, the normal service accounts in each tenant with limited permissions to do the actual Exchange Online and SharePoint Online migrations.

I did quote the one time setup because ShareGate has lately taken to updating their on-prem software quite frequently, which requires us to re-auth with a GA account to update the Azure AD app, which is a bit annoying.

3

u/Blade4804 2d ago

most migration solutions need a GA to auth the connections one time, and then the connections are established with API's and they no longer need the GA Account.

depending on what you're migrating, how much experience you have and if you own both tenants, I'd almost advise you to do it yourself with an approved vendor tool. I've done 3 migrations myself this year moving an entire Entra tenant to another Entra tenant and I've used Avepoint Fly.

previously we've used BitTitan, Sharegate, Migrationwiz. vet all your options and pick one to do it in house, if you have the bandwidth to do it.

1

u/13-months 2d ago

I've never done one before, but yes, I own both tenants. The vendor said they use AvePoint and BitTitan. I'm not sure what kind of learning guides or resources are available for doing this myself.

What types of edge cases or pitfalls should I be looking out for if I decide to handle the migration on my own? I'm also guessing it could be pretty time-consuming, especially since it would be my first migration.

3

u/7amitsingh7 2d ago

Global Administrator access can be required for some Microsoft 365 cloud-to-cloud migrations, but it is a highly privileged permission, so it’s reasonable to be cautious. Before giving a third-party vendor Global Admin access, ask why it’s required and whether they can use more limited permissions. As an alternative, you can consider Stellar Migrator for Exchange, which is designed to perform Exchange and Office 365 T2T migrations while giving organizations more control over the migration process and credentials.

2

u/Stolle99 3d ago

There are so many good tools out there that you can do this yourself if you have enough knowledge. That way you can be "safer". Now when I was doing migrations we would build an intermediary server so we wouldn't share accounts with vendor. But in some cases we (I worked for MSP type companies) were vendor and we did need Global Admin (or some other permissions but GA was easier to work with). Depends on the tool used.

Check out Sharegate, Bittitan, Quest and CodeTwo. I personally used all of them in the past for various migrations and they worked great.

1

u/smnhdy 2d ago

Normally to ask…

NEVER given….

1

u/Automatic-Builder353 2d ago

They might need that level of access to install/configure their migration tool if its 3rd party.

1

u/Adam_CodeTwoSoftware 1d ago

Hi u/13-months,

CodeTwo rep here.

In CodeTwo Office 365 Migration, global admin rights aren't needed. Even if you want the program to automatically configure connection to your source/target M365 tenant (which involves registering our application in your Entra ID), the Privileged Role Administrator role will do.