
Our experience with Microsoft 365 migration projects has revealed a simple relationship: Success depends not so much on the tool itself as on how well it is suited to the nature of the environment. In the projects we’ve carried out, we’ve seen both pure cloud migrations and complex hybrid scenarios involving an on-premises Active Directory. It is precisely this difference that most often determines the choice of technology. Of course, migration from other systems and identity platforms—such as migration from Lotus Notes or other cloud service providers like Google or hosted email services—is a separate topic. Below, I’ll focus only on tenant-to-tenant migration scenarios or hybrid environments with AD. Rather than recommending a single „best” solution, in this article I’ll compare four approaches, showing which situations each one is best suited for.
The discussion will cover Microsoft’s native tool (CTIM) and three third-party solutions: ShareGate Migrate, BitTitan MigrationWiz, and Quest On Demand Migration—in terms of factors that actually impact the project’s timeline and risk, such as scope of work, account and group provisioning, support for hybrid environments, conflict detection, and licensing models.
Why is identity the first step in tenant-to-tenant migration?
The key attributes required by Exchange Online (including ExchangeGuid, ArchiveGuid, and X.500 proxy addresses) must be correctly applied to the target objects. If even one of them is missing, the mailbox migration fails. It is this stage that most often distinguishes the tools described here.
Manual Migration (PowerShell) – When It Makes Sense
Very small migrations usually do not require any tools; you can carry out the process either via PowerShell by synchronizing email from archives or by manually creating accounts in the console and leaving the archived data in local .pst files. This method will work for companies with up to 50 mailboxes. Beyond that, it becomes too cumbersome and should be streamlined using appropriate tools and automation.
Each step of the migration depends on the previous one, and the order is not arbitrary. This approach is flexible, but time-consuming and prone to errors at larger scales. Manual migration works well for small, well-defined migrations or as a supplement to tools in unusual cases. For larger projects, tools with conflict detection and a planning interface typically pay for themselves by reducing risk and corrective work.
Microsoft CTIM (Cross-Tenant Identity Mapping)
CTIM is a native Microsoft tool (currently in preview) that maps user identities across tenants before the mailbox migration begins. It allows you to map source users to destination users on a one-to-one basis, automate property updates, and maintain a mapping file to track and verify the migration.
This is a preparatory step, not a tool for creating accounts. Users and groups must already exist in the destination tenant. CTIM simply applies the attributes required by Exchange Online to them. It works exclusively through PowerShell, run in both tenants (first the source, then the destination), and creates a mapping file that you verify and upload before starting the mailbox migration. If you are using Migration Orchestrator for content, running CTIM is a required step.
Best for: Preparing identity attributes as a preliminary step before migrating mailboxes in the Microsoft ecosystem.
Strengths:
- Microsoft's native tool
- It directly supports the requirements of Migration Orchestrator
- Automation of Attribute Updates
Limitations:
- PowerShell Only
- It does not create users or groups—they must already exist
- Includes only the following features: SharePoint, Teams, OneDrive, and groups are out of scope
ShareGate Migrate
Best for: Preparing identity attributes as a preliminary step before migrating mailboxes in the Microsoft ecosystem.
What is transferred:
- Users: members and guests
- Shared mailboxes, rooms, and resources (Full Access, Send As, and Send on Behalf permissions)
- Security groups – static and dynamic
- Microsoft 365 Groups (Unified Groups) – Static and Dynamic
- Basic user attributes (name, UPN, job title, department, location, employee ID) and license assignments
Strengths:
- Identity and Content in a Single Flow
- Detecting Conflicts Before Performing a Migration
- Safe reruns of runs at no additional charge
Limitations:
- Limited support for on-premises AD and hybrid environments
- No migration of distribution lists
- No mail-enabled security groups
BitTitan MigrationWiz
Best for: identity migration in environments with a local Active Directory and hybrid configurations.
What to look for:Identity migration is not part of the core MigrationWiz workflow. It requires a separate Active Directory Migration license for each user being migrated. For Entra-to-Entra scenarios, automatic synchronization and simulation mode are not supported, and distribution lists are not migrated.
Strengths:
- Cloud coverage, hybrid models, and local AD
- Flexible matching criteria
- An agent-based architecture that supports synchronization between tenants
Limitations:
- Identity as a Separate License Add-on
- Per-User Licensing
- No simulation or auto-synchronization for the Entra ID target
Quest On-Demand Migration
Identity migration is part of a separate AD licensing tier; there is no trial version for these modules, and pricing is determined on a case-by-case basis.
Best for: hybrid environments and the modernization of the local Active Directory.
Strengths:
- In-depth coverage of local and hybrid AD
- Password synchronization, domain migration, and device migration
- Coexistence and the free/busy calendar across tenants
Limitations:
- Separate AD licensing is required
- No trial version of the AD modules
- Pricing is available only after contacting the sales department
Tool Comparison: CTIM vs. ShareGate vs. BitTitan vs. Quest
Below is a summary of the key differences in the area of identity migration. The features of these tools are constantly evolving, so it’s always a good idea to check the manufacturer’s documentation for the current scope.
| Criterion | Microsoft CTIM | ShareGate Migrate | BitTitan MigrationWiz | Quest On Demand |
|---|---|---|---|---|
| User Provisioning |
No They must already exist in the target tenant |
Yes Members, guests, mailboxes |
Yes Users and security groups |
Yes Users, Groups, Contacts |
| Group Provisioning | No |
Yes Security Groups and M365 (static and dynamic) |
Yes Security groups only (cloud-to-cloud) |
Yes Security Groups and M365 |
| Local ADs | No |
No Cloud-to-cloud only | Yes | Yes |
| Content Migration |
No A separate tool is required |
Yes SharePoint, Teams, OneDrive, Exchange | Separate tool / separate license |
Yes AD/Entra, Exchange, OneDrive, SharePoint, Teams |
| Interface | PowerShell Only | UI with a planning view | Simulation Mode | SaaS Dashboard with a Schedule |
| Conflict Detection | Manual verification of the mapping file | Before performing the migration | Pre-production simulation | Before Starting the Migration |
| Repeating Runs | Overwriting resets the mapping |
Yes No additional fees | Additional license for each user | No data available |
| Status | Preview |
Preview (Pro and Enterprise plans) | Generally available | Generally available |
| Pricing Model |
Cross-Tenant User Data Migration License per user (no retail price) | Fixed annual fee, no per-user charges | On behalf of the user | Custom pricing, separate AD licenses |
How to Choose an Entra ID Migration Tool? Scenarios
In practice, the choice comes down to a few questions about the nature of the environment and the scope of the project:
- A purely cloud-to-cloud migration, such as the merger of two Microsoft 365 tenants?
ShareGate Migrate – identity and content in a single workflow, with conflict detection and a fixed annual fee. - A hybrid environment or on-premises AD for modernization?
Quest On Demand – the broadest AD coverage, password synchronization, domain rewriting, and device migration. - A hybrid model with an emphasis on flexible adaptation and an agent-based model?
BitTitan MigrationWiz – customizable matching criteria, tested in on-premises scenarios. - Does it serve as a preliminary step in the native Microsoft process?
CTIM – attribute preparation, typically supplemented by a third-party tool to cover the full scope.
For Lotus Notes migrations, we typically use Quest tools. Depending on the client’s budget, we sometimes choose BitTitan solutions for hybrid migrations, although in one very complex migration process, this solution did not work for us, and we ultimately chose Quest. In both cases, it is important to verify that the configuration is correct and that there are no errors in Active Directory. In one project, we had to repair the domain because it was experiencing replication issues, and in that particular case, the Quest tools were generating errors that prevented the migration from proceeding.
FAQ - The most common questions about Microsoft HealthCheck
Is CTIM sufficient for a full tenant-to-tenant migration?
No. CTIM prepares identity attributes, but it does not create accounts or transfer content (SharePoint, Teams, OneDrive). A third-party tool is required to cover the full scope.
What should be migrated first?
Identity. Users and groups must exist in the target tenant with the correct attributes before mailboxes and content are migrated—otherwise, mailbox mapping and permissions will fail.
Which tool is best for hybrid environments?
Quest On Demand and BitTitan MigrationWiz support on-premises AD and hybrid configurations. ShareGate focuses on cloud-to-cloud scenarios.
How does the pricing model differ?
ShareGate charges a flat annual fee with no per-user fees; BitTitan charges on a per-user basis; Quest prices its solutions individually, with a separate AD licensing tier.
Summary
There is no single, universally „best” tool for Entra ID migration—there is a tool that’s right for each specific environment. CTIM works well as a native initial step, ShareGate speeds up cloud-to-cloud migrations, and BitTitan and Quest cover complex hybrid and on-premises AD scenarios. The real risk of a project lies not in the choice itself, but in accurately matching the tool to the environment model, the scope of identity, and the schedule. A very important element is the design and standardization process.
From the perspective of the projects we’ve carried out at ISCG, the most time and money is saved by thoroughly assessing the environment before migration—taking an inventory of identities, identifying gaps and conflicts, and making an informed decision on whether to handle content and identity in a single workflow. The result is a migration that goes according to plan, without weeks of corrective work for the IT team and without downtime for users.
Are you planning to migrate or consolidate your Microsoft 365 tenants? If you could use a second set of eyes to assess your environment and select the right tool, we’d be happy to share our experience from similar projects.
Learn about our other services

Business applications
Services for applications and turnkey solutions in the area of process digitization and modern work environment.

Full support and optimization of IT infrastructure, ensuring stable development of your business.
IT infrastructure

Security of deployment and maintenance of Microsoft 365 and Azure services that enable flexible management and cost optimization.

