Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations prepare unstructured data before moving…
Governance, Ownership & Risk

How should organisations prepare unstructured data before moving a legacy Exchange environment to Office 365?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Start by identifying what data is active, what is stale, and what is legally required to retain. Then map ownership, business purpose, and access rights before migration. This avoids carrying unnecessary risk and storage cost into the cloud, and it gives auditors a clearer view of governance. A disciplined pre migration review also reduces surprises in OneDrive, SharePoint, and Exchange.

What should be cleaned up before Exchange data moves to Microsoft 365?

The right preparation is less about the migration tool and more about data discipline. Treat the mailbox set as a governance problem first: separate active content from stale content, identify records that must be retained, and understand where ownership or business purpose is unclear. That upfront triage makes the later move to Exchange Online, OneDrive, and SharePoint cleaner and easier to defend.

Unstructured data in a legacy Exchange environment often includes email threads, attachments, forwarded copies, and shared folders that have accumulated without clear retention logic. Before moving anything, decide what belongs in the new environment, what should be archived, and what can be removed under policy. If you skip that step, you usually migrate ambiguity, not just data.

A practical cleanup also means checking duplicates, orphaned mailboxes, and content that no longer has a valid business owner. That is the point where migration work becomes a records, access, and storage exercise rather than a pure IT transfer. The cleaner the source set, the easier it is to preserve searchability, retention, and user trust after cutover.

Why ownership and access review matter before migration

Exchange content is not just information, it is information with permission history attached. Before moving unstructured data, map who owns the content, who can access it, and whether those rights still match current roles and business need. This is especially important where shared mailboxes, delegated access, or long-lived folders have grown well beyond their original purpose.

That review helps prevent two common failure modes: overexposure and overretention. Overexposure happens when content lands in Microsoft 365 with broader access than intended, while overretention happens when obsolete data is carried forward because no one challenged its purpose. Both create unnecessary governance burden and make later audits harder.

It also helps separate operational mail from content that has archival, legal, or compliance value. Some unstructured data should be preserved, but preservation should be deliberate, documented, and tied to a retention rule. If that decision is made after migration, remediation usually takes longer and costs more.

How to reduce migration surprises in Office 365

Migration surprises usually come from content that was never normalised before the move. Large attachments, deep folder nesting, stale shared content, and user-generated workarounds can all behave differently once they are in Microsoft Exchange Online, SharePoint, or OneDrive. A pre-migration review should therefore test content volume, retention status, and ownership assumptions before the cutover window begins.

It is also wise to identify business exceptions early. Some teams will want to keep informal historical mail because it supports investigations, client disputes, or knowledge continuity. That may be valid, but it should be an explicit decision with a retention or archive path, not an accidental default. The goal is to move useful data, not inherited clutter.

Risk and Threat Considerations

Legacy Exchange content can carry security and compliance risk into Microsoft 365 if organisations migrate it without first removing obsolete, excessive, or poorly owned data. The main exposure is not just storage cost, it is the persistence of content that may still be accessible, searchable, or retained longer than intended.

Failure mechanism: stale mail, attachments, and shared content are lifted into the new environment with old permissions, unclear ownership, or no clear retention decision, which preserves unnecessary access and complicates later control cleanup.

Impact: the organisation inherits avoidable eDiscovery burden, larger attack surface for sensitive information, and more difficult audit or legal defensibility after the migration.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsLegacy mail content should be inventoried before migration.
A.5.12 — Classification of informationActive, stale, and retained content need classification before moving.
A.5.15 — Access controlOwnership and access rights must be reviewed before content moves.
Recommendation — Inventory mail data and associated assets before deciding what to migrate. Classify unstructured data so retention and migration decisions stay consistent. Review and revalidate access rights before migrating legacy mail content.
CIS Controls v8CIS-3 — Data ProtectionData minimisation and retention choices reduce unnecessary sensitive exposure.
CIS-5 — Account ManagementMailbox ownership and delegated access depend on current account governance.
Recommendation — Reduce exposed and stale data before migrating to cloud services. Remove inactive or unnecessary access paths before cutover.
NIST CSF 2.0ID.AM-01 — Physical devices and systems within the organization are inventoriedMigration prep depends on knowing what content and systems exist.
ID.RA-01 — Asset vulnerabilities are identified and documentedStale data, orphaned content, and unclear ownership are migration weaknesses.
PR.AA-05 — Access permissions and authorizations are defined, managed, enforced, and reviewedLegacy access rights must be confirmed before the move.
Recommendation — Inventory mail stores and associated repositories before migration. Document data quality and governance weaknesses before moving content. Review and reapprove permissions before migrating legacy Exchange content.

Practitioner Guidance

What to prioritise: start with mailbox and content triage, then move to ownership and access validation. If you cannot explain why a data set still exists, do not treat it as migration-ready.

What to verify: confirm that retention categories are documented, that orphaned or inactive content has a disposition rule, and that any shared or delegated access still matches the current business need. For mail-heavy environments, this is often where the biggest risk reduction comes from.

Common mistake: treating every mailbox item as if it must be migrated because it exists. That approach inflates cost, preserves confusion, and makes post-migration governance much harder.

Practitioner takeaway: the best pre-migration cleanup is a decision process, not a file deletion exercise, because defensible ownership and retention choices matter more than simply moving data faster.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org