Microsoft 365 Migration for a Pretoria Business: What Actually Happens

Published: September 20, 2026 | By Code Masters | 8 min read

Moving a Pretoria business onto Microsoft 365 is not a big-bang IT project. It is a fortnight of preparation, one evening of cutover, and a few days of tidying up. Most of the pain people remember from bad migrations comes from skipped preparation, not from Microsoft. This is what actually happens, week by week, whether you are coming off POP3 or IMAP hosting, an old on-premises Exchange server, or Google Workspace.

Before Anything Starts: What We Need From You

The migration goes as fast as the slowest piece of paperwork. Before the first mailbox moves, the business has to produce three things:

  • Who owns the domain — the registrar or hosting login (often a konsoleH-style panel from a local host) is where the MX and other DNS records live. If a previous IT provider registered it, find out now, not on cutover night.
  • A list of every shared mailbox, distribution list and alias — sales@, accounts@, info@ and the old address that still receives supplier invoices all count. If it is not on the list, it does not get migrated.
  • Current passwords for every mailbox, or the willingness to reset them — a mailbox that cannot be opened cannot be copied. On Google Workspace this means a super-admin account; on Exchange, domain admin.

You also decide who gets what. Some staff only need emails on a phone, not the full Office apps. Microsoft 365 licences are billed per user by Microsoft at current Microsoft pricing and are separate from support fees.

Week One: Discovery and Mailbox Sizes

Everything starts with measuring. Mailbox sizes decide the migration method and the timeline: a 40 GB accounts mailbox that has sat on IMAP since 2011 takes many hours to copy, a 2 GB mailbox takes minutes. Discovery also finds the archive PSTs on desktops and documents how each device gets its mail: Outlook, phones, webmail, the odd Thunderbird.

It also covers everything that sends emails but is not a person: the printer that scans to email, the accounting package that emails invoices, the website contact form. Each has old SMTP settings buried in it, and every one will break at cutover if it is not on the list.

Week One to Two: Domain Verification and DNS

Microsoft has to know you own your domain, and the internet has to know where to deliver your mail. Both happen in DNS at your registrar or host, usually through a panel like konsoleH. In order:

  1. A TXT verification record proves ownership of the domain to Microsoft. Harmless, added on day one.
  2. SPF is updated to include Microsoft's mail servers so receiving systems accept mail from 365 as legitimate. Anything else sending as your domain goes in the same record.
  3. DKIM signing keys are published as two CNAME records so Microsoft can cryptographically sign your outgoing mail.
  4. DMARC tells the world what to do with mail that fails those checks. It starts in monitoring mode and is tightened once reports come in.
  5. The MX record is the switch. It changes last, on cutover evening, and it is what actually moves inbound mail to Microsoft.

Lowering the TTL on these records a few days early means the final change spreads faster when it is flipped.

Tenant Setup

In parallel, the tenant is built: users with the right names and licences, shared mailboxes and distribution lists recreated, aliases attached, spam filtering set to sensible defaults, and a separate admin account that nobody uses for daily work. If files are moving to OneDrive and SharePoint as well, that is a separate project with its own cutover.

Staged or Cutover?

For a business of 5 to 50 people the answer is almost always a cutover migration: everything moves in one go. Mail is pre-copied during the week while the old system stays live, then on cutover evening the final delta is synced and MX is switched. A staged migration, moving departments in batches over weeks, makes sense for firms with hundreds of mailboxes, not for yours. Google Workspace follows the same outline, with a different tool pulling mail, calendar and contacts straight from Google.

Cutover Evening

It happens after hours, usually on a weekday evening:

  1. Final sync of every mailbox, so anything that arrived since the last pre-copy comes across.
  2. MX record changed at the registrar. From that moment new mail heads to Microsoft.
  3. Autodiscover CNAME pointed at Microsoft so Outlook and phones can find the new server on their own.
  4. Old server kept alive but not deleted. Mail may still trickle in there for a day while DNS spreads; it is swept into 365 the next morning.
  5. Test messages in both directions, including a shared mailbox and an external address.

Nobody notices, because nobody is working. The next morning is where the effort goes.

The Morning After: Outlook, Phones and Everything Else

Every Outlook profile needs rebuilding. On POP3 or IMAP it was pointed at the old host; on old Exchange it holds a profile that will not simply reattach. A rebuild takes 10 to 20 minutes per PC, which is why a 10-user office is done by lunch and a 40-user office is a two-day exercise.

Phones are quicker: remove the old account, add the Microsoft 365 account in Outlook mobile or the built-in mail app. Staff who were on POP3 sometimes discover their sent items lived only on the phone.

Shared mailboxes are re-attached to the people who need them and distribution lists are tested. Calendar and contacts on IMAP hosting were usually local to Outlook, so they are exported beforehand and imported afterwards; on Exchange and Google they migrate with the mailbox. Archive PSTs go into the online archive rather than back into the inbox.

What Breaks and Why

  • Autodiscover — if the old CNAME or an internal DNS record still points at the previous server, Outlook keeps trying to set itself up against it. Fix the record, flush DNS, retry.
  • Scanners and printers — the multifunction device in the corner is still sending scans through the old host's SMTP port with an old password. It needs the new relay address, TLS and usually a dedicated account.
  • Accounting software — packages such as Pastel, Sage or Xero connectors store SMTP settings inside the application. Same fix: new server, new port, new credentials.
  • Website forms — if the site emails you through the old host, it still will until the developer updates it.
  • The one mailbox nobody listed — an alias or a former director's address that still receives supplier statements. It surfaces within a week.

How Long Does It Take? 10 Users vs 40

Ten users with modest mailboxes: a week of preparation, one cutover evening, and profile rebuilds finished the next morning. Call it seven working days end to end.

Forty users with a few large mailboxes and an on-premises Exchange server: two to three weeks. The pre-copy alone can run for days, the list of shared mailboxes and rules is longer, and the day-after work is spread over two or three days so no department is offline all at once.

The Security Baseline to Switch On the Next Day

A freshly migrated tenant on default settings is not secure enough. Before the end of the first week, switch on:

  • MFA for every user, using the Authenticator app rather than SMS wherever possible.
  • Conditional access basics — block legacy authentication (POP3 and IMAP), require MFA outside trusted locations, and block sign-ins from countries you never do business with.
  • Anti-phishing policies, safe links and safe attachments at the level your licence allows, plus impersonation protection for your own domain.
  • Admin accounts separated from daily accounts — nobody reads emails on an account that can delete the tenant.
  • Auditing turned on so a suspicious inbox rule or forwarder can be traced later.

Our security services page covers the wider baseline, and the cybersecurity checklist for South African SMEs is a practical walk-through for the owner.

Why You Still Need a Backup

Microsoft keeps your mail available; it does not keep a recoverable copy for you indefinitely. Deleted items, deleted mailboxes and OneDrive files are held for Microsoft's fixed retention windows, and once those pass the data is gone. Ransomware that encrypts a synced OneDrive folder syncs the encrypted versions faithfully.

That is why Code Masters runs a nightly Microsoft 365 backup for its clients: an independent copy of mail, calendars, contacts, OneDrive and SharePoint that can be restored months later. It belongs in the same conversation as your wider disaster recovery plan.

A POPIA Note

Your mailboxes hold personal information about customers, staff and suppliers, which makes the migration a POPIA event. Three practical points: Microsoft offers South African data residency for Microsoft 365, so choose that region when the tenant is created; the old server or hosting account must be closed and its data removed once the migration is verified, not left running because nobody cancelled it; and access to shared mailboxes should be reviewed rather than copied across as it was, because "everyone can see accounts@" is rarely what your Information Officer would sign off.

Pretoria Realities

  • Load-shedding on cutover night — the schedule is checked before the date is set. The router and the PC running the migration tooling go on a UPS, and if the area is due to go dark mid-evening the cutover is run remotely.
  • Fibre outages — if the office fibre drops during the final sync, the sync resumes. A mobile-data fallback covers the Outlook rebuilds the next morning.
  • Local registrar DNS — changes made in a South African host's panel can take longer to propagate than the panel promises. Lower the TTL early and verify from outside networks rather than trusting the panel's green tick.
  • Old hosting that will not let go — some legacy accounts keep accepting inbound mail on the old MX for a day or two. That is what the morning-after sweep is for.

What It Costs and How to Start

Migrations are quoted after discovery, because mailbox sizes and the number of devices drive the hours. Code Masters' pay-as-you-go rate is R750 per hour, and managed plans start from R750 per user per month for ongoing Microsoft 365 administration after the move. Microsoft's licences are billed separately by Microsoft at current Microsoft pricing.

The helpdesk runs 07:00 to 18:00 on weekdays, with emergency support 24/7 for the cutover night and the week after. The office is at 257 Jean Avenue in Centurion, which puts most Pretoria clients 15 to 30 minutes away. See the Microsoft 365 support and IT support in Pretoria pages for the ongoing arrangement, or the general IT support page if you are further afield.

Planning a Microsoft 365 Migration?

Call 060 131 5099 or send us the size of your team and what you are moving from. We will tell you what the migration involves before you commit to anything.

Call 060 131 5099Contact Us