Ask three IT providers for a migration plan and you will get three project timelines. A timeline is not a runbook. A timeline says the cutover is on Saturday; a runbook says what happens at 19:14 when the delta sync reports a mailbox mismatch.
Here is what ours contain, and why each section exists.
1. The environment map
Not the documentation you were given — what is actually there. Mailbox inventory with sizes and item counts, shared mailboxes, distribution groups, aliases, delegate permissions, calendar resources, and every application that authenticates against the mail system.
That last category is where projects go wrong. There is nearly always a scan-to-email device, a CRM connector or a dispatch system relaying through an unauthenticated internal connector that nobody has thought about in six years. Discovery finds those, because the alternative is finding them at 22:00 on the Saturday.
2. The window, and what happens inside it
A minute-by-minute sequence. Each step has an owner, an expected duration, and a verification action — not “cut over MX” but “cut over MX, then confirm propagation from three external resolvers and send a test message from an outside address”.
If a step cannot be verified, it does not belong in the runbook as a step. It belongs as an assumption, written down and agreed.
3. Rollback triggers
This is the section that most plans omit, and it is the most important one.
Before the window opens, everybody agrees the specific conditions under which we stop and revert. Not “if things go badly” — actual thresholds. Delta sync exceeding a defined duration. Item-count variance above an agreed percentage. Mail flow tests failing after a set number of retries.
The point is to make the decision in advance, calmly, rather than at midnight under pressure with a client on the phone. A rollback that was planned is a scheduling inconvenience. A rollback improvised at 01:00 is an incident.
4. Communications
Who tells the business what, and when. Templates written in advance for the “we are starting”, “we are halfway”, “we are done” and “we have hit a problem” messages.
Silence during a migration is its own failure mode. The worst cutovers we have inherited were not technically worse than the good ones — the client simply had no idea what was happening for six hours, and that is what they remember.
5. Reconciliation and sign-off
Item counts compared per mailbox, an exceptions list, and a written report. “Looks fine” is not a completion criterion, because two weeks later somebody will ask whether a specific folder came across and the answer needs to be evidence rather than recollection.
The uncomfortable part
Writing this properly takes longer than most people expect, and it happens before anyone touches a server. That is a difficult thing to sell — clients want to see progress, and a document does not look like progress.
But the cutover window is short precisely because the runbook is long. Pre-staging moves the bulk of the data days ahead; the window carries only the delta. Eighteen minutes on the Saturday is a consequence of three weeks of preparation, not a substitute for it.
If somebody quotes you a migration without discovery first, they are not quoting the work. They are quoting a guess, and you will find out which by how the invoice changes.
Want to see what discovery would surface in your environment? Start a conversation.