<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00009QZeQHSA1Okta Classic EngineOkta Integration NetworkAnswered2025-02-22T09:00:13.000Z2020-09-16T13:03:33.000Z2020-09-22T11:55:56.000Z
  • czos7 (czos7)

    Hi Jeff,

     

    We have done several O365 to O365 migrations now and have found the below to work effectively.

     

    1. Create the new / "to be migrated" users in O365 directly with @.onmicrosoft.com addresses - this includes any Shared Mailboxes
    2. Migrate the data from the source to your tenant
    3. At the point of "Go-Live", remove the domain from the old tenant and add it to your tenant
    4. Change the username of the new users (previously set to the @.onmicrosoft.com) to the new domain
    5. Now that the domain(s) is in your tenant, your can configure a O365 application in OKTA with WS-Federation on that domain
    6. Make sure the user's profiles match to the usernames in O365 so it syncs
    7. Assign the O365 application to the user - this will sync the two accounts together and OKTA will master these accounts.

     

    Hope you find this helpful! 😀

     

    Kind Regards,

    Tom

    Expand Post
  • feok4 (feok4)

    Thanks Tom. We have the steps for the migration down pat, which you outlined above. My question was more on the best way to root the domain out with Okta in place for SSO and provisioning. We've done several migrations previously and successfully but were only dealing with 20-50 users. However, we now need to migrate ~450 user mailboxes to a new tenant. Here is what we're thinking:

    (1) Block sign in to O365 for all users

    (2) Convert the O365 Okta app from WS-Fed to SWA

    (3) Convert all users names to the onmicrosoft.com address and remove the domain.com from the SMTP/Proxy addresses

    (4) Complete migration of mail

    (5) Create new O365 app in Okta with WS-Fed and Provisioning

    (6) Assign users to app

    (7) Test SSO

     

    These are not inclusive but gives a high level on what we're trying to do. My concern is the WS-Fed to SWA... I need to be able to manipulate the O365 objects in the cloud. Any thoughts?

     

    Jeff

    Expand Post
This question is closed.
Loading
O365 Tenant to Tenant migration