Home

Cross-Tenant OD4B -> OD4B Migration With Modern Auth. MigrationWiz Won't Work - SPO PS?

%3CLINGO-SUB%20id%3D%22lingo-sub-199410%22%20slang%3D%22en-US%22%3ECross-Tenant%20OD4B%20-%26gt%3B%20OD4B%20Migration%20With%20Modern%20Auth.%20MigrationWiz%20Won't%20Work%20-%20SPO%20PS%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-199410%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EWe've%20acquired%20a%20company%20who%20also%20has%20an%20O365%20Tenant.%26nbsp%3B%20I've%20had%20a%20great%20experience%20using%20BitTitan%20MigrationWiz%20to%20migrate%20the%20mailboxes%20over.%26nbsp%3B%20It%20was%20a%20dream%20and%20I%20highly%20recommend%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPhase%20II%20was%20to%20perform%20a%20document%20migration%2C%20and%20the%20process%20was%20that%20all%20source%20users%20would%20move%20everything%20into%20their%20OD4B%2C%20and%20I%20would%20use%20the%20doc%20migration%20component%20of%20MigrationWiz%20to%20forklift%20all%20data%20out%20and%20over%20into%20their%20new%20OD4B%20sites%20in%20our%20tenant.%26nbsp%3B%20MigrationWiz%20supports%20this%20migration.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20our%20(the%20'destination')%20tenant%20we%20have%20implemented%20Modern%20Authentication%20%26amp%3B%20Conditional%20Access%20Policies%2C%20along%20with%20some%20MFA.%26nbsp%3B%20I%20got%20rid%20of%20the%20MFA%20for%20the%20migration%20acct%2C%20and%20excluded%20it%20from%20the%20Conditional%20Access%20Policies.%26nbsp%3B%20When%20I%20tried%20the%20pilot%20migration%20I%20got%20the%20below%20error%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CH5%20id%3D%22toc-hId-1034995167%22%20id%3D%22toc-hId-1116142263%22%3EYour%20migration%20failed%20checking%20destination%20credentials.%20Cannot%20contact%20web%20site%20'%3CA%20href%3D%22https%3A%2F%2FTENANTNAME-admin.sharepoint.com%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2FTENANTNAME-admin.sharepoint.com%2F%3C%2FA%3E'%20or%20the%20web%20site%20does%20not%20support%20SharePoint%20Online%20credentials.%20The%20response%20status%20code%20is%20'Unauthorized'.%20The%20response%20headers%20are%20'Content-Type%3Dtext%2Fplain%3B%20charset%3Dutf-8%2C%20P3P%3DCP%3D%22ALL%20IND%20DSP%20COR%20ADM%20CONo%20CUR%20CUSo%20IVAo%20IVDo%20PSA%20PSD%20TAI%20TELo%20OUR%20SAMo%20CNT%20COM%20INT%20NAV%20ONL%20PHY%20PRE%20PUR%20UNI%22%2C%20X-SharePointHealthScore%3D3%2C%20X-MSDAVEXT_Error%3D917656%3B%20Access%2Bdenied.%2BBefore%2Bopening%2Bfiles%2Bin%2Bthis%2Blocation%252c%2Byou%2Bmust%2Bfirst%2Bbrowse%2Bto%2Bthe%2Bweb%2Bsite%2Band%2Bselect%2Bthe%2Boption%2Bto%2Blogin%2Bautomatically.%2C%20SPRequestDuration%3D27%2C%20SPIisLatency%3D4%2C%20X-Powered-By%3DASP.NET%2C%20MicrosoftSharePointTeamServices%3D16.0.0.7716%2C%20X-Content-Type-Options%3Dnosniff%2C%20X-MS-InvokeApp%3D1%3B%20RequireReadOnly%2C%20X-MSEdge-Ref%3DRef%20A%3A%20A023B5802BE4460D83753583C1F81C92%20Ref%20B%3A%20BL2EDGE0918%20Ref%20C%3A%202018-05-30T18%3A36%3A12Z%2C%20Date%3DWed%2C%2030%20May%202018%2018%3A36%3A11%20GMT%2C%20Content-Length%3D0'.%3C%2FH5%3E%3CP%3EBitTitan%20told%20me%20that%20this%20is%20because%20their%20tool%20only%20supports%20%3CSTRONG%3ESet-SPOTenant%20-%3C%2FSTRONG%3E%3CSTRONG%3ELegacyAuthProtocolsEnabled%20%24True%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EPart%20of%20our%20ModernAuth%20config%20sets%20that%20to%26nbsp%3B%3CSTRONG%3E%24false%3C%2FSTRONG%3E.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20the%20only%20way%20to%20use%20this%20tool%20and%20complete%20the%20OD4B%20migration%20to%20reset%20the%20tenantwide%20'legacyauthprotocols'%20setting%20to%20'%24true'%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOtherwise%2C%20can%20SPO%20PS%20be%20used%20to%20connect%20to%20other%20tenants%20with%20appropriate%20creds%2C%20iterate%20through%20a%20source%20user's%20OneDrive%20files%2Ffolders%2C%20connect%20to%20the%20target%20tenant%20with%20separate%20creds%20and%20populate%20a%20corresponding%20OneDrive%20with%20that%20data%3F%26nbsp%3B%20We%20only%20have%20about%2040%20users%20and%20I%20can%20use%20a%20CSV%20for%20source%2Ftarget.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20a%20tough%20one.%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3EJohn%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fanswers.microsoft.com%2Fen-us%2Fmsoffice%2Fforum%2Fmsoffice_o365admin-mso_manage%2Fconnect-sposervice-fails-unable-to-access%2F0aa6665b-c3d8-4138-92e4-6dfab2cbf038%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fanswers.microsoft.com%2Fen-us%2Fmsoffice%2Fforum%2Fmsoffice_o365admin-mso_manage%2Fconnect-sposervice-fails-unable-to-access%2F0aa6665b-c3d8-4138-92e4-6dfab2cbf038%26nbsp%3B%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-199410%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EFiles%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMigration%20issue%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOneDrive%20for%20Business%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-200173%22%20slang%3D%22en-US%22%3ERe%3A%20Cross-Tenant%20OD4B%20-%26gt%3B%20OD4B%20Migration%20With%20Modern%20Auth.%20MigrationWiz%20Won't%20Work%20-%20SPO%20PS%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-200173%22%20slang%3D%22en-US%22%3EIf%20changing%20that%20setting%20in%20your%20tenant%20is%20not%20possible%20(for%20whatever%20reason%20you%20have)%2C%20then%20you%20can%20(as%20you%20say)%20create%20your%20custom%20PowerShell%20scripts%20to%20move%20files%20from%20one%20tenant%20to%20another%20one...another%20alternative%20you%20have%20is%20just%20change%20your%20migration%20tool%20(Sharegate%2C%20Metalogix)%20and%20see%20if%20they%20deal%20better%20with%20your%20scenario.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-199630%22%20slang%3D%22en-US%22%3ERe%3A%20Cross-Tenant%20OD4B%20-%26gt%3B%20OD4B%20Migration%20With%20Modern%20Auth.%20MigrationWiz%20Won't%20Work%20-%20SPO%20PS%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-199630%22%20slang%3D%22en-US%22%3ENot%20the%20most%20helpful%20reply%2C%20esp%20since%20if%20you%20had%20read%20my%20OP%20you'd%20have%20seen%3A%3CBR%20%2F%3E%22BitTitan%20told%20me%20that%20this%20is%20because%20their%20tool%20only%20supports%20%22-LegacyAuthProtocolsEnabled%20%24True%22.%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-199462%22%20slang%3D%22en-US%22%3ERe%3A%20Cross-Tenant%20OD4B%20-%26gt%3B%20OD4B%20Migration%20With%20Modern%20Auth.%20MigrationWiz%20Won't%20Work%20-%20SPO%20PS%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-199462%22%20slang%3D%22en-US%22%3EWell%2C%20you%20might%20need%20to%20ask%20this%20to%20BitTitan%20support%20and%20if%20there%20are%20not%20other%20alternatives%20you%20might%20need%20to%20use%20another%20tool%20for%20the%20migration%3C%2FLINGO-BODY%3E
Highlighted
Deleted
Not applicable

Hi,

We've acquired a company who also has an O365 Tenant.  I've had a great experience using BitTitan MigrationWiz to migrate the mailboxes over.  It was a dream and I highly recommend it.

 

Phase II was to perform a document migration, and the process was that all source users would move everything into their OD4B, and I would use the doc migration component of MigrationWiz to forklift all data out and over into their new OD4B sites in our tenant.  MigrationWiz supports this migration.

 

However.

 

In our (the 'destination') tenant we have implemented Modern Authentication & Conditional Access Policies, along with some MFA.  I got rid of the MFA for the migration acct, and excluded it from the Conditional Access Policies.  When I tried the pilot migration I got the below error:

 

 

Your migration failed checking destination credentials. Cannot contact web site 'https://TENANTNAME-admin.sharepoint.com/' or the web site does not support SharePoint Online credentials. The response status code is 'Unauthorized'. The response headers are 'Content-Type=text/plain; charset=utf-8, P3P=CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI", X-SharePointHealthScore=3, X-MSDAVEXT_Error=917656; Access+denied.+Before+opening+files+in+this+location%2c+you+must+first+browse+to+the+web+site+and+select+the+option+to+login+automatically., SPRequestDuration=27, SPIisLatency=4, X-Powered-By=ASP.NET, MicrosoftSharePointTeamServices=16.0.0.7716, X-Content-Type-Options=nosniff, X-MS-InvokeApp=1; RequireReadOnly, X-MSEdge-Ref=Ref A: A023B5802BE4460D83753583C1F81C92 Ref B: BL2EDGE0918 Ref C: 2018-05-30T18:36:12Z, Date=Wed, 30 May 2018 18:36:11 GMT, Content-Length=0'.

BitTitan told me that this is because their tool only supports Set-SPOTenant -LegacyAuthProtocolsEnabled $True

Part of our ModernAuth config sets that to $false.

 

Is the only way to use this tool and complete the OD4B migration to reset the tenantwide 'legacyauthprotocols' setting to '$true'?

 

Otherwise, can SPO PS be used to connect to other tenants with appropriate creds, iterate through a source user's OneDrive files/folders, connect to the target tenant with separate creds and populate a corresponding OneDrive with that data?  We only have about 40 users and I can use a CSV for source/target.

 

This is a tough one.

Thanks,

John

 

 

https://answers.microsoft.com/en-us/msoffice/forum/msoffice_o365admin-mso_manage/connect-sposervice-...

 

3 Replies
Well, you might need to ask this to BitTitan support and if there are not other alternatives you might need to use another tool for the migration
Not the most helpful reply, esp since if you had read my OP you'd have seen:
"BitTitan told me that this is because their tool only supports "-LegacyAuthProtocolsEnabled $True".
If changing that setting in your tenant is not possible (for whatever reason you have), then you can (as you say) create your custom PowerShell scripts to move files from one tenant to another one...another alternative you have is just change your migration tool (Sharegate, Metalogix) and see if they deal better with your scenario.
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
50 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
32 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
15 Replies
Discussion - Updating our interface with Fluent touches
Elliot Kirk in Discussions on
102 Replies