Exchange requirements

Before you set up your migration from Microsoft Exchange, make sure you meet the following requirements.

Before you begin

Make sure that you:

  1. Meet the Google Workspace Migrate requirements.
  2. Complete the steps to Install & set up Google Workspace Migrate.

Exchange versions & setup

Exchange versions

Exchange 2010, 2010 SP1, 2010 SP2, 2010 SP3, 2013, 2013 SP1, 2016, 2019 or Exchange Online (Microsoft 365).

Exchange 2007 is unsupported.

Exchange Web Services

You must enable Exchange Web Services (EWS) and make sure that the computer that runs the Google Workspace Migrate software can reach it.

Transport Layer Security

On the Exchange connection, configure TLS 1.2 or later.

Exchange admin requirements

The Exchange administrator must be a Global or Application Administrator. They need a mailbox in the Exchange environment and these roles:

  • View-Only Configuration
  • View-Only Recipients
  • Mailbox Search (not required for Exchange 2010)
  • MailboxSearchApplication (not required for Exchange 2010)

It can take several hours for an admin role to take effect. If you're seeing a role-based access control (RBAC) related error after applying the roles, wait a few hours and try again.

Additional requirements for Exchange Online

The additional requirements for Exchange Online depend on the version of Google Workspace Migrate that you're using.

Version 2.4.18.0 or later

URLs

Make sure the Google Workspace Migrate platform and nodes can access the following URLs:

  • https://login.microsoftonline.com/organizations/oauth2/v2.0/token
  • https://outlook.office365.com/EWS/Exchange.asmx

Scopes

You must authorize the full_access_as_app scope, which gives your Microsoft Azure app full access to all mailboxes in your tenant through the EWS API.

Admin requirements

  • Ensure that the application administrator grants their consent to the registered Microsoft Azure app. 
  • The application administrator that is used to grant administrator consent to Google Workspace Migrate must be able to impersonate itself. If you're using a delegated admin or Exchange management role scopes, you might need to explicitly set this up.
Version 2.4.16.0 or earlier

URLs

Make sure the Google Workspace Migrate platform and nodes can access the following URLs:

  • https://login.microsoftonline.com/organizations/oauth2/v2.0/devicecode
  • https://microsoft.com/devicelogin
  • https://login.microsoftonline.com/common/oauth2/deviceauth
  • https://login.microsoftonline.com/common/login
  • https://login.microsoftonline.com/appverify
  • https://login.microsoftonline.com/organizations/oauth2/v2.0/token
  • https://outlook.office365.com/EWS/Exchange.asmx

Scopes

You must authorize the following scopes:

  • EWS.AccessAsUser.All—Allows Google Workspace Migrate to act as the authenticated account through the EWS API.
  • Offline_access—Allows Google Workspace Migrate to obtain a refresh token that remains valid until it’s manually revoked.

Admin requirements

Make sure that the admin meets the following requirements: 

  • The application administrator that is used to grant administrator consent to Google Workspace Migrate can impersonate itself. You might need to explicitly set this up if you're using a delegated admin or Exchange management role scopes.
  • They have the ApplicationImpersonation role
  • You meet one of these requirements: 
    • Your Exchange administrator has the Application Administrator role in Microsoft Azure Active Directory.
    • An Application Administrator has granted administrator consent to the Google Workspace Migrate application for your organization. (To do so, sign in to Microsoft Online here.)

Next

Supported & unsupported features for Exchange


Google, Google Workspace, and related marks and logos are trademarks of Google LLC. All other company and product names are trademarks of the companies with which they are associated.

Search
Clear search
Close search
Main menu
3370370195482173558
true
Search Help Center
true
true
true
false
false