Short answer
A cloud migration is planned in steps: take inventory of your systems and data, classify their sensitivity, choose the service model and where the data will reside, secure access, migrate in batches starting with the least critical items, test, prepare a rollback plan, cut over, then train users and shut down the old environment.
This guide is for information only and is not legal advice.
Moving to the cloud is more than copying data: a migration affects access, security, where personal information is stored and day-to-day work. This guide explains the basics, the benefits and risks to weigh, the steps of a migration for an SMB, the Microsoft 365 case and the mistakes to avoid.
Cloud computing: what are we talking about?
The Canadian Centre for Cyber Security describes three service models offered by cloud service providers:
- Software as a Service (SaaS): you use applications hosted by the provider and available over the Internet. The Centre gives Google Workspace and Microsoft 365 as well-known examples. The provider maintains the software.
- Platform as a Service (PaaS): the provider offers a platform to build, deploy and manage applications, without you having to maintain the underlying infrastructure.
- Infrastructure as a Service (IaaS): the provider offers computing resources such as servers, storage and networking, on which you run and manage your own applications.
The Centre also describes four deployment models. A public cloud makes the provider's infrastructure available to anyone over the Internet. A private cloud provides a dedicated environment for a single entity, hosted onsite or by the provider. A community cloud is shared by organizations with similar needs. A hybrid cloud combines several of these types, connected to each other.
Before you migrate: benefits and risks to weigh
According to the Canadian Centre for Cyber Security, cloud services offer, among other things:
- capacity that adapts to your organization's demand;
- subscription services, with fees based on usage;
- the possibility of cutting some costs, such as maintenance, power and cooling, and reclaiming space by using offsite servers;
- access to offsite backup services and disaster recovery plans.
The same agency lists risks to consider before committing:
- possible breaches of the laws and regulations that apply to your data;
- loss of direct control over, and visibility into, cloud components;
- staff who are unfamiliar with cloud deployments;
- unclear roles and responsibilities when responding to an incident;
- the risk of being locked into a particular service because of financial commitments or the difficulty of switching providers.
Above all, remember the shared responsibility principle: the provider is responsible for the security of the cloud, but your organization remains responsible for the security and maintenance of what it puts in the cloud. Its senior decision makers remain accountable for managing the risks.
The steps of a migration
1. Inventory: systems, data, dependencies
List what you have: workstations, servers, software, mailboxes, shared folders, accounts and services already online. For each item, note who uses it and what it connects to. Microsoft's Cloud Adoption Framework recommends discovering all dependencies first, internal and external, because dependent systems that are not migrated together cause service disruptions.
2. Classify data sensitivity
The Canadian Centre for Cyber Security advises determining the value and sensitivity of your information. This exercise helps you identify the information you can store in the cloud and adequately protect sensitive business and personal information.
3. Choose the model and where data will reside
Choose the service model that suits each item, then specify where the data will be stored. The Canadian Centre for Cyber Security points out that privacy requirements differ from one country to another, and that your organization is responsible for ensuring the provider complies with data residency requirements.
In Quebec, section 17 of the Act respecting the protection of personal information in the private sector requires a privacy impact assessment before personal information is communicated outside Quebec, or before someone outside Quebec is entrusted with keeping it on your behalf. The communication must also be covered by a written agreement. If the migration is a project to acquire or overhaul an information system involving personal information, section 3.3 also requires an assessment, with your person in charge of the protection of personal information consulted from the outset. Our guide Law 25: what Quebec SMBs must do on the IT side covers these obligations in detail.
4. Secure identities
Accounts become the front door to your data. The Canadian Centre for Cyber Security recommends requiring two-factor authentication for important accounts, including cloud administration, and using cloud administrator accounts that are separate from internal administrator accounts. It also recommends using administrator accounts only for administrative tasks, not for reading email or browsing the web.
5. Migration order
Microsoft's Cloud Adoption Framework suggests grouping items that depend on each other, for example those sharing a database or an authentication service, so they migrate together. It recommends starting with less complex, lower-risk items, migrating non-production environments before production, and scheduling critical systems for later waves. It also advises avoiding critical business periods, such as a financial year-end or a peak season.
6. Rollback plan and failure criteria
Before you start, decide what counts as a failure and how to return to the previous state. Microsoft recommends establishing rollback criteria and procedures before any migration, deciding with the people involved what counts as a failure, and testing the procedure to make sure it restores the system to a stable, known-good state. For an SMB, this means at least keeping the old system intact and accessible until the new one is accepted.
7. Testing, cutover and employee communication
Test with a few users before the cutover. Microsoft distinguishes two approaches: a migration with planned downtime, simpler, for what can tolerate an interruption, and a near-zero-downtime migration, more complex and requiring prior testing, for critical workloads. Announce the cutover date to employees, explain what changes for them, such as sign-in, two-factor authentication or where files are, and tell them who to contact if something goes wrong.
8. After the migration: backups, monitoring, retiring the old environment
The Canadian Centre for Cyber Security recommends backing up systems that hold essential information and making sure they can be restored, reviewing the security controls that protect your assets in the cloud, and removing accounts that employees no longer need. When the old environment is no longer needed, sanitize its storage: the Centre points out that data that is simply deleted remains recoverable, while sanitization removes it permanently. For managing your environment after the migration, see our page on managed IT and IT support.
Common case: moving email and files to Microsoft 365
Moving email, calendars, contacts and files to Microsoft 365 calls for particular attention to email.
Email migration methods
Microsoft Learn describes several ways to migrate email to Microsoft 365. The choice depends on your current system and the number of mailboxes:
- Cutover migration: all mailboxes on an Exchange server are migrated at once.
- Staged migration: mailboxes on an older Exchange server are migrated in batches.
- Hybrid migration: the on-premises Exchange environment and Microsoft 365 work together, so users can be migrated gradually, in small batches.
- Google Workspace migration: for leaving Google Workspace, with email, calendar and contacts.
- IMAP migration: for other IMAP-compatible systems. Only mail folders are migrated: contacts, calendar items and tasks are not, and mailboxes must be created in Microsoft 365 before the migration.
DNS and email: MX, SPF, DKIM, DMARC
Much of the email switch happens in your domain's DNS:
- MX: this record says where to deliver your domain's email. Microsoft recommends adding users and setting up mailboxes before updating the MX record, so email keeps working without interruption. Once the MX record points to Microsoft 365, all new email is delivered there; existing messages stay with the previous provider unless you migrate them.
- SPF: this record helps prevent spoofing of your domain. If one already exists, Microsoft says to add the Microsoft 365 value to it rather than create a second one: there should be a single SPF record.
- DKIM and DMARC: because some spoofing techniques bypass SPF, Microsoft recommends also setting up DKIM and DMARC. The Canadian Centre for Cyber Security also recommends that your email service implement DMARC.
Mistakes to avoid
- Migrating without an inventory. A forgotten shared folder or piece of software turns up on Monday morning, when someone can no longer find it.
- Putting off account security. Two-factor authentication and separate administrator accounts should be in place before data moves.
- Forgetting where data will reside. The hosting region and section 17 of the Act are dealt with when choosing the service, not afterwards.
- Changing the MX record too early. Mailboxes must exist in Microsoft 365 before email is directed there.
- Retiring the old environment too soon, or never. Keep it until the migration is accepted, then sanitize its storage rather than leaving it running unattended.
To describe the scope of your migration, read How to prepare an IT quote request, and to choose who will manage your environment, How to choose an IT service provider in Quebec. See also our pages on cybersecurity and IT projects, then request a cloud migration quote.
Frequently asked questions
What are the steps of a cloud migration?
Take inventory of systems, data and their dependencies; classify data sensitivity; choose the service model and where data will reside; secure identities; migrate in batches starting with the least critical items; prepare a rollback plan; test, cut over and inform employees; then set up backups, monitoring and the retirement of the old environment.
Is my data secure in the cloud?
Security is shared. According to the Canadian Centre for Cyber Security, the provider is responsible for the security of the cloud, but your organization remains responsible for the security and maintenance of what it puts in it. Two-factor authentication, separate administrator accounts and restorable backups are part of your side of the responsibility.
Should my data stay in Canada?
The Canadian Centre for Cyber Security writes: "For non-GC organizations, we recommend that you ensure all sensitive data, including account and security information, is stored within Canada." The hosting region is therefore a criterion to specify in your quote request. Before communicating personal information outside Quebec, or entrusting its keeping to someone outside Quebec, section 17 of Quebec's private sector privacy Act requires a privacy impact assessment and a written agreement.
Can we migrate without interrupting employees' work?
There are methods designed to limit interruptions. Microsoft describes a near-zero-downtime migration for critical workloads, which requires prior testing, and for email recommends creating mailboxes before changing the MX record. The length of any interruption depends on your environment and should be planned for.
What is the difference between SaaS, PaaS and IaaS?
With SaaS, you use an application hosted by the provider, such as Microsoft 365. With PaaS, you build and run your own applications on a platform managed by the provider. With IaaS, you rent basic resources such as servers and storage, and you manage what you install on them.
What should we do with the old server after the migration?
Keep it available in read-only mode until you have confirmed that all data has been migrated and the new environment is accepted. Then sanitize its storage securely before reusing or disposing of it: according to the Canadian Centre for Cyber Security, data that is deleted or moved to the trash is still recoverable.
Sources
- Canadian Centre for Cyber Security, Models of cloud computing (ITSAP.50.111)
- Canadian Centre for Cyber Security, Benefits and risks of adopting cloud-based services in your organization (ITSE.50.060)
- Canadian Centre for Cyber Security, Secure cloud and outsourced IT services
- Canadian Centre for Cyber Security, Baseline cyber security controls for small and medium organizations, sections 3.5, 3.7, 3.9 and 3.12
- Canadian Centre for Cyber Security, Sanitization and disposal of electronic devices (ITSAP.40.006)
- Microsoft Learn, Plan your migration, Cloud Adoption Framework
- Microsoft Learn, Ways to migrate multiple email accounts to Microsoft 365 or Office 365
- Microsoft Learn, Connect your domain by adding DNS records
- LégisQuébec, Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), sections 3.3 and 17