# SharePoint Server → SPO Migration Checklist

> 44 checkpoints across 8 stages: discovery, permissions, customizations, workflows, integrations, compliance, cutover, and post-migration validation. The same list used on real engagements, whether you're moving off an out-of-support 2016 or 2019 farm or off Subscription Edition.

1.  [Home](https://tenantcraft.ca/)
2.   [Insights](https://tenantcraft.ca/insights)
3.   SharePoint Server → SPO Migration Checklist

Plan Migration 44 checkpoints

Last reviewed August 3, 2026 · 7 pages in print

Before you start

## How to use this checklist

Print it, or open it on a second monitor, and tick each item as you complete it. The eight stages run in the order a real migration follows. If you are already mid-flight, jump to the stage that matches where you are. Nothing here is theoretical; every checkpoint maps to a decision or a failure mode seen on actual SharePoint 2016 cutovers.

Dates & limits worth pinning to the wall
| Item | What it means |
| --- | --- |
| July 14, 2026 | SharePoint 2016 reaches end of support. The same day, InfoPath reaches end of life. |
| May 18, 2026 | InfoPath form _publishing_ is blocked. No more form changes can be pushed after this date. |
| 5,000 items | The SharePoint Online list view threshold. Bigger lists need indexed views or restructuring. |
| 100,000 items | Above this, migration tools cannot set unique permissions. Plan to split the list or library. |
| 400 characters | Maximum file path length the migration API accepts. Longer paths are rejected outright. |
| ~250 GB / day | Realistic throughput per migration agent for document-heavy content. Use it to size the timeline. |

The eight stages

1.  1Discovery and inventory6 checkpoints
2.  2Identity and permissions7 checkpoints
3.  3Customizations and solutions5 checkpoints
4.  4Workflows and forms5 checkpoints
5.  5Third-party integrations4 checkpoints
6.  6Data classification, compliance, retention5 checkpoints
7.  7Migration and cutover6 checkpoints
8.  8Post-migration validation and decommission6 checkpoints

Stage one

## Discovery and inventory

6 checkpoints

-   Inventory **every site collection**: URL, owner, storage size, item count (Get-SPSite + Export-Csv, or the SPMT scan).
-   Flag every list or library over **5,000 items**. These hit the SharePoint Online view limit and need indexed views or restructuring.
-   Flag lists or libraries over **100,000 items**. Migration tools cannot set unique permissions above this, so plan to split them.
-   Surface **stale sites** with no edits in 12+ months. Decide archive or migrate before you move anything.
-   Document every **non-default content type** and managed metadata term set.
-   Estimate total size and timeline: plan by content type, document-heavy content typically moves near **250 GB/day per migration agent**.

Stage two

## Identity and permissions

7 checkpoints

-   Confirm **Microsoft Entra ID sync** is healthy and complete.
-   Map every on-prem security group used in SharePoint to its Microsoft 365 destination group.
-   Find every site with **broken permission inheritance**. Record the owner and the reason.
-   Remove **orphaned permissions** tied to disabled or deleted accounts.
-   Audit **external sharing**: who has access, and is it still needed?
-   Redesign permissions to match how access _should_ work. Do not copy the old model unchanged.
-   Set the tenant **default sharing level** before users arrive (anyone / org / specific people).

Stage three

## Customizations and solutions

5 checkpoints

-   List every deployed **solution package (.wsp)** and its scope.
-   Treat **farm solutions** as a rebuild-or-retire decision. They have no equivalent in SharePoint Online.
-   Identify code-based **sandboxed solutions**. Their code no longer runs in SharePoint Online.
-   Decide per customization: rebuild with the **SharePoint Framework (SPFx)**, replace with a built-in feature, or retire.
-   Catalogue custom **master pages, page layouts, and CSS**. Most do not carry over to modern pages.

Stage four

## Workflows and forms

5 checkpoints

-   Inventory every **SharePoint 2010 and 2013 workflow**. Both engines are already retired in SharePoint Online and will not run there.
-   Rebuild any workflow still needed in **Power Automate**; retire the rest.
-   Inventory every **InfoPath form**. InfoPath retires July 14, 2026, and form publishing is blocked after May 18, 2026.
-   Rebuild needed forms in **Power Apps or Microsoft Forms**. There is no automatic conversion.
-   Run rebuilt flows and forms **in parallel** with the originals before cutover to confirm they match.

Stage five

## Third-party integrations

4 checkpoints

-   List every integration touching SharePoint (**Nintex, K2, custom apps, line-of-business systems**).
-   Confirm each vendor **supports SharePoint Online**, or has a documented migration path.
-   Update **API endpoints, app registrations, and secrets** for the new tenant.
-   Re-test every integration **end to end** during the pilot wave.

Stage six

## Data classification, compliance, retention

5 checkpoints

-   Identify sites holding **personal, financial, or otherwise regulated** content.
-   Recreate on-prem **DLP rules** as Microsoft Purview DLP policies. There is no automatic translation.
-   Recreate on-prem **retention and records policies** as Purview retention labels and policies.
-   Apply Microsoft Purview **sensitivity labels** to your highest-risk sites before migration.
-   Document any **legal holds or in-flight eDiscovery** so they survive the move.

Stage seven

## Migration and cutover

6 checkpoints

-   Run a **pilot wave** first: one or two representative sites, fully validated before you scale up.
-   Resolve **checked-out files** with no checked-in version. Migration tools skip them.
-   Confirm **version-history settings**: decide how many versions to carry, and verify they arrive.
-   Fix file paths over **400 characters** and files over **250 GB**. Both are rejected by the migration API.
-   Freeze the source as **read-only at cutover** so no content changes mid-migration.
-   Schedule large transfers for **evenings and weekends**, when throttling is lighter.

Stage eight

## Post-migration validation and decommission

6 checkpoints

-   Confirm every migrated site is **searchable**. Allow up to 24 hours for the index to catch up.
-   Spot-check permissions on a **10% sample** of migrated sites.
-   Confirm **sharing, retention, and DLP policies** behave as expected.
-   Walk a sample of users through the new sites and **gather issues early**.
-   Keep the old farm **read-only until validation is signed off**. Then verify redirects and decommission.
-   Confirm **cyber-insurance and audit posture** once the unsupported farm is retired.

If you get stuck

## Hands-on SharePoint help from Ontario, no enterprise overhead.

This checklist is the planning half of the job. If the inventory turns up more than you want to take on solo (farm solutions to rebuild, InfoPath forms with no owner, permissions nobody can explain), that is the part TenantCraft does for a living. A discovery call is free, 25 minutes, and ends with a written scope, not a sales pitch.

Web

tenantcraft.ca

Email

hello@tenantcraft.ca

Discovery call

Free · 25 minutes

Checklist last reviewed May 15, 2026. SharePoint 2016 reaches end of support on July 14, 2026. Every checkpoint above should be closed (or consciously deferred) before that date.

In this guide

1.  01 [Discovery and inventory](#discovery-and-inventory)
2.  02 [Identity and permissions](#identity-and-permissions)
3.  03 [Customizations and solutions](#customizations-and-solutions)
4.  04 [Workflows and forms](#workflows-and-forms)
5.  05 [Third-party integrations](#third-party-integrations)
6.  06 [Data classification, compliance, retention](#data-classification-compliance-retention)
7.  07 [Migration and cutover](#migration-and-cutover)
8.  08 [Post-migration validation and decommission](#post-migration-validation-and-decommission)

Printable copy

The whole guide is on this page already. If you'd rather work from paper, or hand it to someone who will, the PDF is the same document laid out for printing.

Email me the PDF

One email with the link. No drip sequence, no upsell. Unsubscribe any time.

Thanks, the PDF is on its way to your inbox.

Sneak peek, read it now [Download the PDF](https://tenantcraft.ca/downloads/sp2016-eol-checklist.pdf)

Something went wrong. Email [hello@tenantcraft.ca](mailto:hello@tenantcraft.ca) and I'll send it manually.

The background reading

-   [What one SharePoint cutover weekend actually looks like (hour by hour)](https://tenantcraft.ca/insights/migration-day-runbook)

    The hour-by-hour runbook for a single SharePoint Online cutover weekend. Lock the source, run the final delta, migrate in waves, and make the go/no-go rollback call at the 6-hour mark, before you're too tired to make it well.

-   [The post-migration failures that wait until day 30](https://tenantcraft.ca/insights/post-migration-validation-pass)

    Most silent failures after a SharePoint migration don't show up the morning after cutover. They surface around day 30, exactly when everyone has moved on. Here's the three-pass validation schedule that catches them.

Next in the sequence

-   [InfoPath Forms Decision Tree](https://tenantcraft.ca/resources/guides/infopath-forms-decision-tree)

    Plan · InfoPath

-   [Permissions Cleanup & Governance Prep Checklist](https://tenantcraft.ca/resources/guides/permissions-cleanup-prep)

    Plan · Permissions

-   [SharePoint Workflow Rebuild Playbook](https://tenantcraft.ca/resources/guides/sp2013-workflow-rebuild-playbook)

    Plan · Workflows

TWENTY MINUTES, NO PITCH

## Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

[Book a 20-min call](https://tenantcraft.ca/contact) [See published rates](https://tenantcraft.ca/pricing)

---

_Canonical HTML: https://tenantcraft.ca/resources/guides/sp2016-eol-checklist · Agent guide: https://tenantcraft.ca/llms.txt · Site map: https://tenantcraft.ca/sitemap-index.xml_
