Thank you for reading my blog about the technical implementation for a Microsoft 365 workplace. In this article I've written a high-level approach of an implementation and shift from a more traditional organisation towards a cloud-focused organization. If you're not totally a fan of the cloud idea, please read The value of Microsoft 365 E3 and E5 and How to build your Zero Trust modern workplace with Microsoft 365 — which totally covers the why cloud and why modern technology.

This blog describes the high-level tech actions to grow to a Microsoft 365 modern organization. I would love to receive feedback in the comments, on LinkedIn or Twitter.

1
Identity Management — Azure AD Connect
2
Exchange migration to Exchange Online
3
Personal data migration to OneDrive
4
Departments to Teams & SharePoint Online
5
Voice shift to Microsoft Teams
6
Microsoft Endpoint Manager
7
Basic identity security
8
Windows Autopilot enrollment
9
Software deployment migration
10
GPO migration to MDM
11
Windows updates & security improvements
12
Shift infrastructure to Azure
13
Legacy Active Directory integration
14
Teams & SharePoint collaboration platforms
15
Rethink on-premises
16
Build automated security mechanisms

1. Start with Identity Management and extending Active Directory to Azure AD

Install Azure AD Connect and sync your users and groups to Azure AD. You could use Directory and Password Synchronization to bring all identities from your current environment towards Azure AD. I prefer the hybrid scenario and later full cloud scenario — worst case ADDS in Azure — to have the controls shifted and the primary directory in Azure AD.

Why? Microsoft Azure AD is beyond the current 'legacy' integration and is a next-gen identity platform. Make it simple. If you don't need third-party solutions (which always limits new capabilities) don't go for it. Use native Azure AD. It's also a big opportunity to leave things behind and smoothly shift to ADDS or Azure AD.

Azure AD Connect — directory sync from on-premises to Azure AD
Azure AD Connect — syncing identities from on-premises Active Directory to Azure AD

2. Migrate your Exchange workload with Exchange Hybrid Wizard

It's very easy to shift Exchange workloads as the first load to Office 365.

Exchange Hybrid Wizard — migration to Exchange Online
Exchange Hybrid Wizard — mailbox migration to Exchange Online

3. Migrate personal data to OneDrive

Document data is one of the most important things running in any workplace. Personal data is crucial to take into account for migration. It will help support the shift to M365 when you help people achieve a better collaboration space.

OneDrive Known Folder Move — personal data migration
OneDrive Known Folder Move — automatic migration of Desktop, Documents and Favourites

4. Migrate departments to Teams or SharePoint Online

Microsoft Teams — department migration and SharePoint Online
Teams and SharePoint Online — department data migration approach

5. Voice shift from on-premises to Microsoft 365

There are 4 options for Microsoft Teams voice solutions:

Don't go for less. Use Microsoft Teams. If you choose other platforms, think about trust, compliance, adoption, inclusion, security, segmentation and — most importantly — the speed of implementation compared to the easiness of one platform.

Microsoft Teams voice — Direct Routing and Calling Plan options
Microsoft Teams voice — calling options and Direct Routing

6. Microsoft Endpoint Manager

Microsoft Endpoint Manager — device management and compliance
Microsoft Endpoint Manager — unified device management console

7. Increase basic identity security

Azure AD identity security — MFA, Conditional Access, SSPR
Azure AD — MFA, Conditional Access and identity lifecycle management

8. Windows Autopilot for enrollment of Windows devices

Windows Autopilot — zero-touch device enrollment
Windows Autopilot — zero-touch enrollment for new devices

9. Software deployment migration

Endpoint Manager — software deployment and Microsoft 365 Apps
Endpoint Manager — software deployment, Microsoft 365 Apps and update management

10. Group Policy Objects (GPO) migration

Intune Policy Analytics — GPO to MDM migration
Intune Policy Analytics — mapping GPOs to MDM equivalent policies

11. Windows updates and security improvements

Endpoint Manager — Windows 10 update rings and security baselines
Endpoint Manager — update rings and Windows 10 security baselines

12. Shift infrastructure to Azure

Think about: Rehost · Refactor · Rearchitect · Rebuild · Replace

If you want to do an infrastructure shift, follow the steps below. Otherwise do the assessment, write down all infrastructure and start rearchitecting where possible. When hosting well-known vendor applications, ask if they are planning for SaaS or Azure.

Azure Migrate — server assessment and migration dashboard
Azure Migrate — server discovery, assessment and migration planning

13. Migration of legacy Active Directory integration

Legacy AD migration — application authentication to Azure AD
Legacy AD integration — migrating application authentication to Azure AD

14. Build collaboration platforms with Microsoft Teams & SharePoint

We need to leave complex legacy behind. Choose SaaS solutions with future benefits. Don't wait for phasing these out before going cloud. Do cloud and leave legacy behind — or migrate and isolate. And more importantly: long-term strategy.

Always choose long-term. Don't choose non-compliant solutions that are not ready for future compliance requirements. Security complexity and needs are growing — GDPR and ISO27001 are important.

Microsoft Teams and SharePoint Online — collaboration platform
Microsoft Teams and SharePoint — building the collaboration layer

15. Rethink on-premises

Rehost · Refactor · Rearchitect · Rebuild · Replace

Rethink the new needs of on-premises. All collaboration spaces are shifted to Office 365. Devices are managed with M365 Endpoint Manager. Documents are shifted to OneDrive, Teams and SharePoint. Authentication and integration with Azure AD is shifted. Printers handled with Universal Print or solutions like Printix. Core applications moved to IaaS and waiting to become SaaS over time.

What else is there?

16. Build security mechanisms that can be automated

Now — only now, when the shift is completed — is the time to build your SecOps landscape. Why? It's easier. Don't you want to go fast? Don't you want 1 platform? Don't you want to integrate with modern technology in Azure AD and M365?
Microsoft SecOps — MDATP, Cloud App Security and SecureScore
SecOps automation — MDATP, Cloud App Security, Information Protection and SecureScore