Description:
Migrate all the LOBO M365 Tenant components to TDLR’s M365 Tenant and perform necessary changes to the on-premise AD infrastructure.
Summary of Key Activities
· Fully assess, design and plan the migration for all LOBO Microsoft Tenant Components
· Prepare tenants for migration
· Execute migration phases with minimal disruption to business operations and end-users
· Provide post-migration support
· Assessment and Planning
The project team will conduct a discovery and planning phase that includes:
· Introductory and project kick-off meeting with vendor team and TDLR
· Introduction of vendor team Texas Department of Licensing and Regulation
· Confirm security requirements for vendor staff have been completed
· Review project scope, timeline, dependencies, and assumptions
· Confirm team communication and collaboration needs, protocols, and tools
Fully assess all LOBO Microsoft tenant components in scope for migration, including, but not limited to:
· Microsoft 365 Users (approximately 400 users)
· Shared Mailboxes (approximately 51 shared mailboxes)
· Mail-enabled Security Groups
· Resource Mailboxes (e.g. calendars, rooms)
· External Contacts – convert to online contacts
· Teams & Groups (approximately 171 Teams and Microsoft groups)
· OneDrive (approximately 311 OneDrive Accounts)
· SharePoint Sites (approximately 62 standalone sites)
· Intune
· Purview
· EntraID
· Enterprise Applications
· Application Proxy
· Assessment of identity management for cloud resources
· Power BI resources (workspaces, dashboards, reports)
Full assessment of on-premise active directory domains, including:
· Forest and domain structure (single vs. multiple forests/domains)
· Trust relationships between source and target environments
· Domain functional levels and schema versions
· Organizational Unit (OU) design and delegation model
· Group structure (security, distribution, nested memberships)
· Account types and application dependencies
· Assessment of identify management for on-premise resources (legacy files shares, AD or Lightweight Directory Access Protocol (LDAP) integrated applications, etc.)
· Hybrid identity configuration assessment, including:
· Azure AD Connect (Entra Connect) configuration and version
· Synchronization scope and filtering rules
· Authentication method (Password Hash Sync, Pass-Through Authentication, or Federated Services (FS) such as AD FS)
· Device identity state (Hybrid Azure AD Join, Azure AD Join, on-prem only)
Device and endpoint dependency assessment, including:
· Domain-joined workstations and servers
· Group Policy Objects (GPOs) and their business impact
· Login scripts, mapped drives, and legacy dependencies
Domain Name System (DNS) and identity namespace alignment, including:
· Full assessment of DNS records
· Universal Principal Name (UPN) suffixes and email domain alignment
· Internal vs external domain name consistency
Security and compliance posture review of AD, including:
· Privileged accounts and tiering model
· Identity protection and conditional access dependencies
· Audit policies and logging configurations