Authentication Requirements for Graph API using the BT App

This article covers the authentication requirements using the BT App registered with BitTitan, the supported migration scenarios, and the setup steps for using Graph API with Microsoft 365 endpoints in MigrationWiz.

Find the authentication steps required to enable Graph API for your migration scenario below. For more information, see Microsoft Graph permissions and consent.

Retirement of Exchange Web Services in Exchange Online

Microsoft has announced a phased retirement of Exchange Web Services (EWS) in Exchange Online, beginning October 1, 2026, with final retirement on April 1, 2027. To ensure migrations continue without disruption, BitTitan is transitioning Microsoft 365 endpoint connectivity to Microsoft Graph API ahead of that deadline.

What This Means to You:

  • EWS remains fully supported by MigrationWiz today and will continue to work for most scenarios until closer to Microsoft's final retirement date in April 2027. The official retirement date for MigrationWiz will be announced.
  • Plan your transition to Graph API before the 2027 deadline rather than waiting until EWS is fully disabled.

Supported Scenarios

At this time, Graph API authentication is supported only for Mailbox migrations, including the following scenarios:

Exchange/Microsoft 365 as Source

Google Workspace as Source

Other Mailbox Migrations as Source

Important

Scenarios not listed above (e.g. Public Folder, Microsoft 365 Groups conversations, and Archive Mailbox Migrations) continue to use EWS authentication. Refer to Authentication Methods for Microsoft 365 (All Products) Migrations for those endpoint types.

Prerequisites

Before you begin your migration process using Graph API endpoints, review the following requirement:

  • End-user credentials are not supported. Due to the permission types required for the Entra ID Application, a Global Administrator must be used to consent to the BitTitan app and/or create and consent to the BYO (Bring Your Own Application) in your tenant.

Register and Configure your Application

The following steps outline the necessary steps to set up the tenant, register the application, and assign the required permissions.

If you decide to use this alternative, below, you can find the available authentication options for implementing it in your projects. 

Using the BitTitan App

This section explains how to install and grant consent to the BitTitan registered Graph Application for Entra ID in your tenant, so you can migrate Mailboxes using Graph API in MigrationWiz with Application Permissions (App-only authentication). It also covers how to grant consent through the Microsoft Identity platform.

Step 1: Finding your Tenant ID in Entra ID

Follow the steps below to find the Tenant ID for your Project:

  1. Navigate to Entra ID and sign in with a Global Administrator account.
  2. In the left Navigation menu, click Overview.
  3. Copy your Tenant ID and save it somewhere accessible. You will need this value later, in Step 3, to configure your Endpoint with Graph.
     Finding details Entra ID.png

Step 2: Create your Project and Select Endpoint Type

Follow the steps below to configure your project:

Source Endpoint

The following steps outline the source endpoint creation:

  1. Go to Projects.
  2. Click Create Project.
  3. Select Mailbox Project.
  4. Enter the project information: add a Project Name, select a Customer from the drop-down list or create a new one, then click Next Step.
  5. Click New.
  6. Name the endpoint. It is recommended to use a unique endpoint name for the project.
  7. Go to Endpoint Selection.
  8. From the list, select Microsoft 365 Graph API.
    Microsoft 365 Graph API Endpoint.png
  9. Click Add.

Destination Endpoint

The following steps outline the destination endpoint creation:

  1. Click New.
  2. Name the endpoint. It is recommended to use a unique endpoint name for the project.
  3. Go to Endpoint Selection.
  4. From the list, select Microsoft 365 Graph API.
    Microsoft 365 Graph API Endpoint.png
  5. Click Add.
  6. Click Save Project.

Step 3: Configure the Graph API Endpoint

After you add your Endpoint, configure it in the Source/Destination settings screen following these steps:

Source Endpoint

  1. Use Application Permission is already selected for the Permissions setting. Although present, Delegated Permissions are currently disabled and cannot be selected. Do not check the Use BYO Application checkbox.
    Graph Source BT Endpoint.png
  2. Enter the following details:
    • Migration Service Account: an email address used for domain discovery purposes. It can be any user account in the tenant and does not require an O365 license or admin role to be assigned to the user.

    • Tenant ID: copy the value you saved in Step 1.
      Graph Source BT Details.png

  3. Click Next Step.

Destination Endpoint

  1. Use Application Permission is already selected for the Permissions setting. Although present, Delegated Permissions are currently disabled and cannot be selected. Do not check the Use BYO Application checkbox.
    Graph Destination BT Endpoint.png
  2. Enter the following details:
    • Migration Service Account: an email address used for domain discovery purposes. It can be any user account in the tenant and does not require an O365 license or admin role to be assigned to the user.

    • Tenant ID: copy the value you saved in Step 1.
      Graph Destination BT Details.png

  3. Click Next Step.
  4. On the Project Setting page, click Save and Go to Summary. Do not check either of the boxes shown below, unless you are using the Exchange Online using Graph API (Microsoft 365) to Exchange Online using Graph API (Microsoft 365) Mailbox Migration Guide using Coexistence guide.
    Project Setting Page.png

Step 4: Review the Project Summary and Grant Consent

After configuring both Source and/or Destination endpoints you need to grant consent to the Entra ID Application in your tenant with MigrationWiz. This step grants consent to and installs the BT Application named MigrationWiz-Mailbox-FullControl in the tenant.

Note

An account with a Global Administrator role is required to grant consent.  

Graph Consent.png
  1. Click on the Application Consent button as shown above. You are redirected to the Microsoft Identity Platform (Login Page). The account used to login need to have the Global Administrator role in the tenant.
  2. If the Consent is successful, the following message appears in your browser. Close the page and continue with the next step.
    Successful Authorization.png
  3. Once Consent is successful for the Source/Destination tenant, the status changes from Pending Authorization to Authorized.
    Graph Project Summary.png

Step 5: Grant the Application Exchange Administrator Role

After you complete consent for the BT App, you need to grant your application the Exchange Administrator Role. The following steps allow you to grant this role:

  1. From the Entra Admin Center menu, select Roles & admins.
  2. In the search bar, type Exchange, then click Exchange Administrator.
    Exchange Admin.png
  3. On the Exchange Administrator role assignments page, click Add assignments.
  4. Search for the BT Application name (MigrationWiz-Mailbox-FullControl) to grant this role and mark the checkbox.
  5. Click Add.
    Graph Add Assignments.png
  6. A confirmation message, "Successfully Added Assignment", appears in the top right corner.

Consent Flow:

  • Click on Application Consent.
  • Sign in using Global Administrator credentials.
  • Review permissions requested by the application.
    The following API Permissions are included in the BitTitan App when installed in your tenant:
    IMPORTANT
    All the permissions you see below, apply to all the Supported Migration Scenarios using Microsoft 365 Graph API using a single application. If you require more scoped API Permissions for your source and/or destination tenant, use one of the BYO Application Options:

    -Authentication Requirements for Graph API using the BYO App with Client Secret
    -Authentication Requirements for Graph API using the BYO App with Client Certificate

    Permission Name Type Data Type Purpose
    Calendars.ReadWrite Application Calendar Read and write calendars in all mailboxes
    Contacts.ReadWrite Application Chat Read and write contacts in all mailboxes
    Directory.ReadWrite.All Application Directory Read and write directory data
    Domain.Read.All Application Domain Read domains
    Group.ReadWrite.All Application Group Read and write all groups
    GroupMember.ReadWrite.All Application Group Read and write membership of groups across the tenant
    Group-Conversation.ReadWrite.All Application Group Read and write group conversations
    Mail.ReadWrite Application Mail Read and write mail in all mailboxes
    Mail.Send Application Mail Required for MIME Content extracts for IMAP, Pop and Zimbra as source for import in the destination using Graph
    MailboxFolder.ReadWrite.All Application Mailbox Folder Read and write all the users' mailbox folders
    MailboxSettings.ReadWrite Application Mailbox Setting Read and write all user mailbox settings
    Organization.Read.All Application Organization Read organization information
    Tasks.ReadWrite.All Application Tasks Read and write all users' tasks and task lists
    User.ReadWrite.All Application User Read and write all users' full profiles
    Exchange.ManageAsApp Application Office 365 Exchange Online Manage Exchange as Application (Required for migrating calendar folder permissions and mailbox folder permissions)
  • Click Accept.
  • Grant the Application Exchange Administrator Role.
Was this article helpful?
0 out of 0 found this helpful