A SharePoint Online pre-migration assessment is the structured audit that converts assumptions about the source environment into evidence the migration plan can rely on. It typically covers eight categories: site and content inventory, permissions audit, customization inventory, integration inventory, external sharing audit, compliance and records audit, storage and quota analysis, and identity readiness.
Each category produces outputs that feed tooling selection, wave design, risk prioritization, and change management. Skipping or shortening the assessment is the single most common reason migrations slip schedule or surprise teams at cutover.
This guide is written for US IT leaders, SharePoint administrators, infrastructure architects, program managers, and security and compliance leads scoping a SharePoint Online migration. It walks each audit category, names the outputs, and identifies the migration decisions each output should drive.
Why a Pre-Migration Assessment?
The assessment is the cheapest insurance against migration failure. Three reasons it pays back disproportionately.
- Tooling selection: assessment evidence about content volume, customization, and integrations drives the choice between SharePoint Migration Tool, Migration Manager, ShareGate, AvePoint, Quest, and Metalogix the wrong tool extends timelines by months.
- Risk prioritization: the seven categories of migration risk only become actionable when the assessment surfaces what is actually in the source.
- Executive sign-off: evidence-based plans survive executive review; assumption-based plans do not.
Site and Content Inventory
The content inventory is the foundation. The audit produces: site count and structure (site collections, subsites, hub sites), library and list count, item counts by site, content volume in storage terms (GB/TB), file size distribution (which matters for tool throughput), file type distribution, version history depth, and last-modified distribution (active vs archival content).
The outputs drive wave design, tooling throughput planning, storage planning, and the question of what to migrate versus retire.
Secure Your Business Files with SharePoint Document Management
Permissions Audit
The permissions audit is the most expensive audit to skip. It produces: SharePoint groups inventory, AD/Entra ID group inventory, unique permissions count by site and library, broken inheritance map, external sharing inventory (often surprising), service-account inventory, and the high-privilege account list.
The outputs drive the target permission model, identity-mapping plan, external sharing policy, and the cleanup work that should happen before migration rather than after.
Customization Inventory
The customization inventory determines whether the program has a customization remediation track and how long it is. The audit produces: full-trust solutions list, sandbox solutions list, SPFx solutions list, classic SharePoint Designer workflows, custom timer jobs, custom service applications, InfoPath forms, and third-party tools embedded in the source.
Each item gets a target modernization decision: rebuild in SPFx, rebuild in Power Apps and Power Automate, replace with native Microsoft 365 capability, or retire. The outputs are the modernization backlog.
Integration Inventory
The integration inventory is often the audit most likely to surface forgotten dependencies. It produces: list of systems connected to SharePoint (Salesforce, Dynamics, Teams, Power BI, ServiceNow, SAP, Workday, DocuSign, Adobe Sign, custom LOB), connection pattern for each (API call, document push, embedded UI, scheduled sync), business owner for each integration, and the migration sequencing requirement. The outputs drive cutover sequencing, integration retest plans, and the conversations with system owners that have to happen before cutover.
External Sharing Audit
External sharing in SharePoint Online is a different governance model than most on-premise SharePoint. The audit produces: current external sharing settings by site, count of items shared externally, identity of external collaborators where visible, and the policy gap between current state and target state. The output is the external sharing policy for the target environment and the cleanup decisions for the source.
Compliance and Records Audit
Compliance and records audit reviews how the source environment handles regulated content. It produces: existing retention policies, sensitivity labels, DLP policies, eDiscovery holds, records declarations, and any industry-specific compliance configurations (HIPAA, SOX, FINRA, CMMC, state privacy regimes).
The outputs drive the Microsoft Purview deployment plan for the target environment and the conversation with security and compliance leadership about what moves, what re-applies, and what gets stricter in the cloud. General guidance, not legal or compliance advice; consult counsel and your security function.
Storage and Quota Analysis
Storage and quota analysis sizes the target environment. It produces: source storage volume, projected growth, current archive volume, Microsoft 365 storage allocation by tenant, multi-geo decisions where applicable, and the storage planning for the target. The outputs drive Microsoft 365 license decisions, multi-geo configuration, and archive strategy.
Identity Readiness
Identity readiness checks the Entra ID foundation that SharePoint Online sits on. It produces: AD to Entra ID synchronization health, group structure readiness, conditional access policy review, MFA coverage, app registration review, and Microsoft 365 group strategy. The outputs drive the identity workstream that runs in parallel with the SharePoint migration.
Reporting and Outputs
A useful pre-migration assessment produces a defined set of artifacts that downstream phases consume.
|
Audit category |
Primary output |
Downstream consumer |
|
Site and content |
Inventory + storage profile |
Wave design, tooling |
|
Permissions |
Permission model + identity map |
Target design, cutover |
|
Customization |
Modernization backlog |
Parallel build track |
|
Integration |
Integration map + sequencing |
Cutover plan |
|
External sharing |
Sharing policy + cleanup list |
Governance |
|
Compliance |
Purview deployment plan |
Security sign-off |
|
Storage |
Target sizing + multi-geo |
Licensing, configuration |
|
Identity |
Identity readiness backlog |
Parallel identity track |
How to Run the Assessment?
A pre-migration assessment for a mid-market SharePoint environment typically runs two to six weeks with a small assessment team and access to source environment, identity systems, and business-unit interviews.
The pattern: discovery interviews in week one, automated inventory and audit tooling running in parallel, business-unit and integration owner conversations through weeks two to four, and reporting and prioritization in the final weeks.
Large or complex environments extend; the discipline does not change. Centric runs pre-migration assessments through its SharePoint migration & integration practice, as part of the broader Centric SharePoint consulting practice.
Frequently Asked Questions
How long does a pre-migration assessment take?
Typically two to six weeks for mid-market environments; longer for complex or large enterprise environments. Most assessments overlap discovery conversations with automated audit tooling.
Can we run the assessment ourselves?
Yes, with the right tooling and SharePoint-specialist experience. Most enterprises bring in a partner for objectivity and to accelerate the process; the assessment is usually a small fraction of the total program cost.
What tools are used in the assessment?
SharePoint admin center reports, Microsoft 365 admin center, third-party assessment tools (ShareGate, AvePoint, Quest), custom PowerShell or Microsoft Graph scripts, and structured interviews.
Does the assessment include security and compliance?
Yes compliance and records audit, external sharing audit, and identity readiness are core categories. Security and compliance leadership should sign off on the audit outputs.
What if we have very few customizations?
The assessment still has value for permissions, integration, external sharing, and compliance audits. The customization inventory is faster but the other categories are largely independent.
Can the assessment be skipped if our SharePoint is small?
Almost never advisable. Even small environments surface surprises forgotten integrations, broken inheritance, external shares that are cheap to find now and expensive at cutover.
What is the deliverable from the assessment?
A structured report with each audit category, the outputs above, a prioritized risk register, and a migration plan recommendation that the executive sponsor can review.
Conclusion
A SharePoint Online pre-migration assessment is the cheapest, highest-leverage step in a migration program. Eight audit categories content, permissions, customization, integration, external sharing, compliance, storage, identity convert assumptions into evidence and drive every subsequent decision from tooling to wave design to executive sign-off.
The teams that run the assessment well consistently land migrations on time and on adoption; the teams that skip it consistently surface the same risks at cutover. This is the discipline Centric brings to every migration engagement.
