Microsoft 365 setup

Liscaragh Migrate signs in to Microsoft 365 as its own app registration, using a certificate rather than a password. A built-in wizard sets this up for you: one admin sign-in, and the app registration, certificate, permissions and admin consent are all handled automatically.

What you need before you start. A Microsoft 365 Global Administrator (or an account that can create app registrations and grant admin consent) for the one-time sign-in. If you do not have that, this is the part to hand to whoever administers the tenant.

1. Open the wizard

In Liscaragh Migrate, open Settings > Setup checklist. Find Microsoft 365 in the list and click Set up.... This opens the Microsoft 365 setup window, which explains what it is about to do, then click Sign in and set up.

The Microsoft 365 setup wizard, listing the five things it does before you sign in

What the wizard shows before you sign in to anything.

2. Sign in

A sign-in prompt appears. By default this is a device code sign-in: the tool shows a short code, you visit microsoft.com/devicelogin in any browser (on this computer or another device) and enter it there. A full browser sign-in window is also available as an alternative if your setup supports it.

Sign in with your Global Administrator account. The account is asked to approve three permissions for this setup only: Application.ReadWrite.All (create or find the app registration and add this computer's certificate to it), AppRoleAssignment.ReadWrite.All (record admin consent for the migration permissions) and Organization.Read.All (read your tenant name and verified domains). These are used once, for setup, and are separate from the permissions the migration itself runs with afterwards.

3. What the wizard does automatically

From that one sign-in, the wizard:

Safe to re-run. Run the wizard again at any time: to rotate this computer's certificate, after a rebuild, or to set up a second machine against a tenant that is already configured. It reuses the existing app registration and simply adds a fresh certificate for whichever computer runs it; other machines' certificates already on the app registration are left in place.

4. Permissions granted

The wizard grants the app these five Microsoft Graph application permissions, with admin consent recorded automatically as part of the sign-in above:

Tightening this later. These are application permissions across the tenant, which suits a migration that discovers sites and OneDrives as it goes. If your security policy needs narrower access, SharePoint's Sites.Selected model can restrict the app to named sites, but it has to be granted per site, outside the wizard, and is more involved to run. Start with the wizard unless you have a specific reason not to.

5. Email alerts (optional)

The setup window has a checkbox to also set up completion email alerts. Ticking it grants one further permission, Mail.Send, and creates a shared mailbox in your tenant to send from, which needs a separate Exchange Online admin sign-in. Leave it unticked to do only the core Microsoft 365 setup, with a single sign-in and no Exchange step; you can set up email alerts later from the same wizard, or from Settings, without repeating anything already done.

Prefer to do it by hand?

If you would rather set up the app registration yourself, or have been handed a certificate by an IT contact, Settings > API settings still takes the Tenant ID, App (Client) ID and a .pfx certificate directly, with an Auto-detect URLs button to fill in your SharePoint and OneDrive addresses once those are entered. This manual route is unchanged and works alongside the wizard; use whichever suits how your tenant is administered.

That is the Microsoft 365 side done. If you migrate from Datto Workplace, set that up next with the Datto Workplace API setup. To start migrating, see the main how-to guide.

Liscaragh Migrate is an independent product built by Liscaragh Software. It is not affiliated with, connected with, endorsed by, sponsored by or acting on behalf of Datto, Kaseya or Microsoft. Platform names on this page are used only to describe compatibility and remain the trademarks of their respective owners.