Off Google, onto Microsoft, without losing a login
- Client
- Consultancy, New York
- Size
- 3 mailboxes
- Scope
- Mail, calendars, contacts, files
- Status
- In progress, 2026
The brief
A three-person consultancy wanted to leave Google Workspace for Microsoft 365: mailboxes, calendars, contacts and everything in Drive, plus a shared drive for the team and a new laptop set up for one of the staff.
What the first hour turned up
Before touching anything, I checked the domain's public records. Three things came out of that, none of which the client knew about:
- A Microsoft tenant already existed on the domain, created through their domain registrar's resold Microsoft plan and never used. The domain was locked to it, and sign-ins were being redirected to the registrar rather than to Microsoft.
- A mailbox for one staff member had already been provisioned inside it, sitting empty, because mail was still being delivered to Google.
- The registrar's dashboard was prompting the owner to "fix" her SPF record. Doing so would have stopped her existing Google mail from authenticating, and quietly sent her outbound mail to spam folders, weeks before any migration.
None of this was visible from inside the client's inbox. All of it would have surfaced mid-migration, at the least convenient moment.
The part clients don't expect
The email itself is the straightforward half. The harder half is every other account that authenticates through the mailbox being moved.
This client signed into ten services with the "Sign in with Google" button: design software, a supplier marketplace, file sharing, e-signature, video calls, source control, the laptop vendor's own account. That button doesn't store an email address, it asks Google to vouch for the person each time. Once the domain leaves Google, it stops working, even though the email address itself never changes.
So the sequence runs backwards from what people expect. Convert the logins first, while the old account still answers. Then move the mail.
How the work is sequenced
- Convert each third-party login to its own password, verify each one, and note where the second factor points.
- Deal with the dormant tenant: either take it over properly or release the domain from it, so licences can be bought directly and administered in full.
- Provision the three accounts, then migrate mail, calendars, contacts and files.
- Cut the DNS records over in order, out of business hours, with SPF changed at the switch and not before.
- Keep the old subscription alive for a month afterwards as a fallback.
Client details are withheld; this write-up is published with permission to describe the work in general terms.