The mailbox migration is a weekend. The records migration is a year.

When a large asset manager decides to move off Microsoft 365, the business case usually rests on licensing costs. The assumption is that email is a commodity. But in a regulated institution, you are not migrating mailboxes. You are migrating records. A mailbox that can be opened is not necessarily a record that can be produced.

The first question is not whether you can migrate the mail. It is whether you can produce the mail when a market authority asks for it.

The Archive Gatekeeper

The compliance archive is the gatekeeper. If your institution runs a third-party WORM (Write Once, Read Many) archive for trade surveillance, the archive vendor’s support matrix decides whether the migration is possible. Not the CIO. Not the steering committee. The vendor’s platform support page.

If the matrix says “limited” for the target platform, the professional services quote to build a custom connector will exceed the migration budget. If the matrix says “roadmap,” the project stops.

Compliance requires capturing a message the millisecond it hits the transport layer. Exchange uses envelope journaling to send a blind copy of every message to a surveillance archive. Moving to another platform requires configuring routing rules at the SMTP level. If the new platform processes internal-to-internal mail without passing through the SMTP relay, those messages bypass surveillance.

The surveillance team runs lexicon monitoring tuned to Exchange headers. The new platform’s headers are different. The false positive rate triples, and the team stops trusting the feed. You must test negative scenarios: what happens when a message exceeds the archive’s ingestion limit, or when it contains encrypted content. If the new platform delivers the message anyway when it cannot be journaled, you have a compliance breach.

The Canary and the Add-ins

IT evaluates a mail platform based on protocols and uptime. The business evaluates it based on whether an executive assistant can manage three managing directors’ calendars, color-code their categories, and send-as without triggering a security flag. Microsoft built its enterprise dominance on the back of the EA. Test the EA workflow before you commit. If the shared inbox and calendar delegation do not survive the move, the project is not done, regardless of what the migration dashboard says.

Financial services also rely heavily on local integration. Bloomberg Terminal data drops into emails; secure file transfer tools inject large attachments via Outlook buttons; classification tools force users to tag emails before sending. Moving off Microsoft usually means moving from thick-client COM/VSTO add-ins to web-based extensions. If the vendor does not supply the binary for the new platform, the workflow stops on cutover Monday.

The Hidden Liabilities

An active mailbox is a workspace; a departed user’s mailbox is a liability. In an asset manager, the active headcount might be 5,000, but you are storing 15,000 mailboxes for regulatory retention. Moving means deciding whether to pay to migrate dead mailboxes, keep them in a dormant Microsoft tenant, or extract them to cold storage that your eDiscovery tools can still parse.

If a legal hold lands on a department mid-migration, the migration tool might alter the modified date metadata on the emails as they are injected into the new system. Opposing counsel flags the metadata change as spoliation of evidence. Isolate mailboxes on legal hold. Delay their migration until the hold is lifted, or use tools certified for forensic data transfer that generate and verify a hash for every item extracted. The migration delta report becomes a permanent compliance record.

Platforms conflate retention, backup, and legal hold in marketing. Regulators do not. A retention policy that keeps everything forever is not a backup. A backup that restores everything is not a legal hold. When the backup vendor demonstrates recovery, ensure it shows a point-in-time recovery after bulk corruption, not just restoring a recently deleted mailbox. Native retention in the new platform is not a recovery plan.

Decision Criteria

The options do not carry the same burden. Which option fits your situation depends on the dependencies you cannot break.

Stay on Microsoft if:

  • Your archive vendor does not support the target platform.
  • Your COM add-in dependency is heavy and lacks web equivalents.
  • Your identity architecture is heavily reliant on Entra ID and splitting it is not feasible.
  • Your regulator requires WORM storage the target platform does not natively provide.
  • Your EA workflow depends strictly on Outlook delegation semantics.
  • Your coexistence tolerance is low.

Move to Google Workspace if:

  • Your archive vendor explicitly supports it.
  • Your add-in dependency is light or already web-based.
  • Your identity is multi-cloud or Google-friendly.
  • Your regulatory requirements are met by Vault combined with a third-party archive.
  • Your EA workflow can be adapted to the new delegation model.
  • Your coexistence tolerance is high.

Move to Zoho if:

  • Your regulatory requirements are light.
  • Your add-in dependency is minimal.
  • Cost is the primary driver. For a large regulated institution, this is rarely a fit.

Move to an open-source stack if:

  • You have a product team that can own and build the compliance layer. You are not buying a platform; you are building one. You must operate identity, calendaring, mobile access, retention, and discovery as a supported service.

Run hybrid if:

  • You need to move a specific subsidiary or region while keeping the core on Microsoft. Coexistence requires budget for two systems, two eDiscovery tools, and two patching cadences. The complexity is not linear; it is a second system with its own audit surface.

What to Check Before Committing

Before signing the contract, map the dependencies and test the workflows. The dependency list is longer than the migration plan.

  1. Archive vendor support matrix: Check the actual support matrix for the target platform, not the sales deck.
  2. Regulatory retention requirements: Map the specific records, formats, and durations required by your jurisdiction.
  3. Legal hold semantics: Understand how holds are set, released, and exported in the target platform, and how they map to your current Exchange holds.
  4. eDiscovery export formats: Verify the formats and chain-of-custody documentation. Ensure your outside counsel’s review platform accepts the export.
  5. Journaling connector support: Test format, envelope, deduplication, replay, and internal mail capture.
  6. Shared mailbox and delegation semantics: Test send-as, send-on-behalf, and concurrent reads for shared inboxes.
  7. Calendar delegation and resource booking: Test the EA workflow, including complex recurring meetings and room booking integrations.
  8. Outlook add-in inventory: Identify which add-ins lack web equivalents and require replacement or custom development.
  9. MDM and conditional access: Calculate the policy rewrite effort to enforce containerization on the new provider’s mobile apps.
  10. Backup and DR capabilities: Verify point-in-time restore and granular item restore.
  11. Identity architecture: Calculate the effort and cost to federate or split your identity provider.
  12. Coexistence costs: Budget for the duration, exit criteria, and dual-system operational overhead.
  13. PST inventory: Locate PSTs on file shares and plan their ingestion. The PST problem never goes away; it just moves to a different file share.
  14. Total cost of ownership: Price the replacement archive, surveillance integration, migration validation, discovery workflow, and any Microsoft access that must remain for historical records.

The license line is the smallest part of the cost. The migration delta report becomes a permanent compliance record, and it will be read by your auditors.