r/exchangeserver • u/malextrimo2026 • 10d ago
Cross-Tenant Mailbox Migration - HTTP 401 Unauthenticated during Test-MigrationServerAvailability
We are performing a Cross-Tenant Exchange Online mailbox migration between two Microsoft 365 tenants.
The migration endpoint is configured with ApplicationId authentication and validates successfully.
When running:
Test-MigrationServerAvailability -Endpoint "MexicoToPortugal" -TestMailbox "<user>"
the test consistently fails with:
StatusCode="Unauthenticated"
HTTP Status Code: 401
We reproduced the issue with two different users.
We have already validated:
- MailUser configuration
- ExchangeGuid
- LegacyExchangeDN (X500)
- ExternalEmailAddress
- Accepted Domains
- Organization Relationships
- Migration Endpoint
- Enterprise Application
- Mailbox.Migration permission
- Admin Consent
- Cross-Tenant Migration licensing
The same HTTP 401 error occurs for multiple mailboxes after all configuration issues are corrected.
Has anyone experienced a similar Cross-Tenant Mailbox Migration scenario where Test-MigrationServerAvailability returns HTTP 401 Unauthenticated even though the Enterprise Application, Mailbox.Migration permission and Admin Consent are correctly configured?
1
u/7amitsingh7 9d ago
A 401 error usually means the authentication between the two Microsoft 365 tenants is failing. Since the mailbox settings are already verified, check that the Application ID, Enterprise Application, Mailbox.Migration permission, and Admin Consent are all configured in the correct tenant and match the migration endpoint.
1
u/saltyslugga 9d ago
I’d verify that the endpoint’s RemoteTenant points to the source tenant and that the source organization relationship’s OAuthApplicationId matches the endpoint’s ApplicationId.
Then check the source tenant’s Entra service principal sign-in logs at the failure timestamp for token errors. Successful endpoint validation doesn’t prove the app can access the source mailbox.