Start by identifying what data is active, what is stale, and what is legally required to retain. Then map ownership, business purpose, and access rights before migration. This avoids carrying unnecessary risk and storage cost into the cloud, and it gives auditors a clearer view of governance. A disciplined pre migration review also reduces surprises in OneDrive, SharePoint, and Exchange.
What should be cleaned up before Exchange data moves to Microsoft 365?
The right preparation is less about the migration tool and more about data discipline. Treat the mailbox set as a governance problem first: separate active content from stale content, identify records that must be retained, and understand where ownership or business purpose is unclear. That upfront triage makes the later move to Exchange Online, OneDrive, and SharePoint cleaner and easier to defend.
Unstructured data in a legacy Exchange environment often includes email threads, attachments, forwarded copies, and shared folders that have accumulated without clear retention logic. Before moving anything, decide what belongs in the new environment, what should be archived, and what can be removed under policy. If you skip that step, you usually migrate ambiguity, not just data.
A practical cleanup also means checking duplicates, orphaned mailboxes, and content that no longer has a valid business owner. That is the point where migration work becomes a records, access, and storage exercise rather than a pure IT transfer. The cleaner the source set, the easier it is to preserve searchability, retention, and user trust after cutover.
Why ownership and access review matter before migration
Exchange content is not just information, it is information with permission history attached. Before moving unstructured data, map who owns the content, who can access it, and whether those rights still match current roles and business need. This is especially important where shared mailboxes, delegated access, or long-lived folders have grown well beyond their original purpose.
That review helps prevent two common failure modes: overexposure and overretention. Overexposure happens when content lands in Microsoft 365 with broader access than intended, while overretention happens when obsolete data is carried forward because no one challenged its purpose. Both create unnecessary governance burden and make later audits harder.
It also helps separate operational mail from content that has archival, legal, or compliance value. Some unstructured data should be preserved, but preservation should be deliberate, documented, and tied to a retention rule. If that decision is made after migration, remediation usually takes longer and costs more.
How to reduce migration surprises in Office 365
Migration surprises usually come from content that was never normalised before the move. Large attachments, deep folder nesting, stale shared content, and user-generated workarounds can all behave differently once they are in Microsoft Exchange Online, SharePoint, or OneDrive. A pre-migration review should therefore test content volume, retention status, and ownership assumptions before the cutover window begins.
It is also wise to identify business exceptions early. Some teams will want to keep informal historical mail because it supports investigations, client disputes, or knowledge continuity. That may be valid, but it should be an explicit decision with a retention or archive path, not an accidental default. The goal is to move useful data, not inherited clutter.
Risk and Threat Considerations
Legacy Exchange content can carry security and compliance risk into Microsoft 365 if organisations migrate it without first removing obsolete, excessive, or poorly owned data. The main exposure is not just storage cost, it is the persistence of content that may still be accessible, searchable, or retained longer than intended.
Failure mechanism: stale mail, attachments, and shared content are lifted into the new environment with old permissions, unclear ownership, or no clear retention decision, which preserves unnecessary access and complicates later control cleanup.
Impact: the organisation inherits avoidable eDiscovery burden, larger attack surface for sensitive information, and more difficult audit or legal defensibility after the migration.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.9 — Inventory of information and other associated assets | Legacy mail content should be inventoried before migration. |
| A.5.12 — Classification of information | Active, stale, and retained content need classification before moving. | |
| A.5.15 — Access control | Ownership and access rights must be reviewed before content moves. | |
| Recommendation — Inventory mail data and associated assets before deciding what to migrate. Classify unstructured data so retention and migration decisions stay consistent. Review and revalidate access rights before migrating legacy mail content. | ||
| CIS Controls v8 | CIS-3 — Data Protection | Data minimisation and retention choices reduce unnecessary sensitive exposure. |
| CIS-5 — Account Management | Mailbox ownership and delegated access depend on current account governance. | |
| Recommendation — Reduce exposed and stale data before migrating to cloud services. Remove inactive or unnecessary access paths before cutover. | ||
| NIST CSF 2.0 | ID.AM-01 — Physical devices and systems within the organization are inventoried | Migration prep depends on knowing what content and systems exist. |
| ID.RA-01 — Asset vulnerabilities are identified and documented | Stale data, orphaned content, and unclear ownership are migration weaknesses. | |
| PR.AA-05 — Access permissions and authorizations are defined, managed, enforced, and reviewed | Legacy access rights must be confirmed before the move. | |
| Recommendation — Inventory mail stores and associated repositories before migration. Document data quality and governance weaknesses before moving content. Review and reapprove permissions before migrating legacy Exchange content. | ||
Practitioner Guidance
What to prioritise: start with mailbox and content triage, then move to ownership and access validation. If you cannot explain why a data set still exists, do not treat it as migration-ready.
What to verify: confirm that retention categories are documented, that orphaned or inactive content has a disposition rule, and that any shared or delegated access still matches the current business need. For mail-heavy environments, this is often where the biggest risk reduction comes from.
Common mistake: treating every mailbox item as if it must be migrated because it exists. That approach inflates cost, preserves confusion, and makes post-migration governance much harder.
Practitioner takeaway: the best pre-migration cleanup is a decision process, not a file deletion exercise, because defensible ownership and retention choices matter more than simply moving data faster.
Related resources from NHI Mgmt Group
- How should organisations prepare identity and access controls before moving users into Office 365?
- How should organisations govern sensitive data moving outside Microsoft 365?
- What should organisations do before moving personal data across borders?
- Should organisations prioritise data security coverage for GenAI and MCP paths before expanding more legacy controls?