# Cloud migration checklist for Canadian businesses (2026 edition)

> Amen Security Team · 2026-08-19T12:25:05.273Z · cloud · cloud · azure · microsoft-365 · migration

Cloud migration is not a single weekend cutover. It is a sequence of decisions about identity, data residency, dependencies, and rollback. This checklist reflects what Amen Security uses with Canadian clients moving to Microsoft 365 and Azure in 2026.

Phase 1 — Discover and prioritize

- Inventory servers, SaaS apps, file shares, printers, and line-of-business software

- Map dependencies (which app needs which database, LDAP bind, or static IP?)

- Classify data: public, internal, personal information under PIPEDA, regulated health/financial data

- Choose migration waves — start with collaboration (email/files), not the riskiest database on day one

Phase 2 — Identity first

Most failed migrations trace back to identity — not storage. Before moving mailboxes:

- Standardize on Microsoft Entra ID (or hybrid if legacy AD remains)

- Enforce MFA and conditional access for admins and remote users

- Document break-glass accounts and store credentials offline

- Align UPNs and primary SMTP addresses to avoid Teams/SharePoint confusion later

Phase 3 — Network and security

- Validate bandwidth and latency to Microsoft peering points

- Replace VPN-only access with Zero Trust patterns where possible

- Segment guest Wi‑Fi and PCI/PHI zones before lifting workloads

- Update firewall rules for new SaaS endpoints — don’t “allow all HTTPS” as a shortcut

Phase 4 — Data move and residency

Canadian clients often require clarity on where data lives. Confirm Microsoft 365 tenant region, Azure resource groups, and backup copy locations. Document subprocessors for privacy questionnaires.

- Use staged mailbox and SharePoint migrations with pilot users

- Keep legacy read-only access during parallel run

- Verify search, retention labels, and eDiscovery if you are in a regulated sector

Phase 5 — Test rollback before you need it

Define rollback triggers: authentication failure rate, critical app incompatibility, data loss beyond RPO. Run a tabletop with executives and IT — who decides to roll back, and within what window?

Phase 6 — Go-live and hypercare

- Freeze non-essential changes for 72 hours post-cutover

- Staff amplified helpdesk coverage

- Monitor sign-in logs, transport queues, and backup success — not just “green dashboards”

- Schedule a 30-day retrospective to capture lessons for wave two

Downloadable next step

Need a migration partner? Amen Security runs assessments that output a prioritized wave plan with effort, risk, and Canadian compliance notes.

[Request a migration assessment](/en/contact?tab=consult)

---
Source page: https://amensecurity.ca/en/blog/cloud-migration-checklist
Markdown version for AI agents · Amen Security
Email: info@amensecurity.ca
Phone: +1 (204) 514-3536
