This article covers the authentication requirements using the BT App registered with BitTitan, the supported migration scenarios, and the setup steps for using Graph API with Microsoft 365 endpoints in MigrationWiz.
Find the authentication steps required to enable Graph API for your migration scenario below. For more information, see Microsoft Graph permissions and consent.
Retirement of Exchange Web Services in Exchange Online
Microsoft has announced a phased retirement of Exchange Web Services (EWS) in Exchange Online, beginning October 1, 2026, with final retirement on April 1, 2027. To ensure migrations continue without disruption, BitTitan is transitioning Microsoft 365 endpoint connectivity to Microsoft Graph API ahead of that deadline.
What This Means to You:
- EWS remains fully supported by MigrationWiz today and will continue to work for most scenarios until closer to Microsoft's final retirement date in April 2027. The official retirement date for MigrationWiz will be announced.
- Plan your transition to Graph API before the 2027 deadline rather than waiting until EWS is fully disabled.
Supported Scenarios
At this time, Graph API authentication is supported only for Mailbox migrations, including the following scenarios:
Exchange/Microsoft 365 as Source
- Exchange Online using Graph API (Microsoft 365) to Exchange Online using Graph API (Microsoft 365) Mailbox Migration Guide
- Microsoft 365 using Graph API to G Suite Migration Guide
- Microsoft 365 using Graph API to (Hosted and On-Premises) Exchange (2013+) Migration Guide
- Exchange Online (Microsoft 365) using Graph API to PST
- Exchange 2010+ (Hosted and On-Premises) to Microsoft 365 using Graph API Migration Guide
- Recoverable Items (Microsoft 365 or Exchange using Graph API) Migration Guide
Google Workspace as Source
- G Suite (Gmail API) to Exchange Online using Graph API (Microsoft 365) Migration Guide
- G Suite (IMAP) to Microsoft 365 using Graph API Migration Guide
- Google Groups to Microsoft 365 Shared Mailbox using Graph API Migration Guide
Other Mailbox Migrations as Source
- Zimbra 6+ to Microsoft 365 using Graph API Migration Guide
- IMAP to Microsoft 365 using Graph API Mailbox Migration Guide
- PST to Microsoft 365 using Graph API Migration Guide
Important
Scenarios not listed above (e.g. Public Folder, Microsoft 365 Groups conversations, and Archive Mailbox Migrations) continue to use EWS authentication. Refer to Authentication Methods for Microsoft 365 (All Products) Migrations for those endpoint types.
Prerequisites
Before you begin your migration process using Graph API endpoints, review the following requirement:
- End-user credentials are not supported. Due to the permission types required for the Entra ID Application, a Global Administrator must be used to consent to the BitTitan app and/or create and consent to the BYO (Bring Your Own Application) in your tenant.
Register and Configure your Application
The following steps outline the necessary steps to set up the tenant, register the application, and assign the required permissions.
If you decide to use this alternative, below, you can find the available authentication options for implementing it in your projects.
Using the BitTitan App
This section explains how to install and grant consent to the BitTitan registered Graph Application for Entra ID in your tenant, so you can migrate Mailboxes using Graph API in MigrationWiz with Application Permissions (App-only authentication). It also covers how to grant consent through the Microsoft Identity platform.
Step 1: Finding your Tenant ID in Entra ID
Follow the steps below to find the Tenant ID for your Project:
- Navigate to Entra ID and sign in with a Global Administrator account.
- In the left Navigation menu, click Overview.
- Copy your Tenant ID and save it somewhere accessible. You will need this value later, in Step 3, to configure your Endpoint with Graph.
Step 2: Create your Project and Select Endpoint Type
Follow the steps below to configure your project:
Source Endpoint
The following steps outline the source endpoint creation:
- Go to Projects.
- Click Create Project.
- Select Mailbox Project.
- Enter the project information: add a Project Name, select a Customer from the drop-down list or create a new one, then click Next Step.
- Click New.
- Name the endpoint. It is recommended to use a unique endpoint name for the project.
- Go to Endpoint Selection.
- From the list, select Microsoft 365 Graph API.
- Click Add.
Destination Endpoint
The following steps outline the destination endpoint creation:
- Click New.
- Name the endpoint. It is recommended to use a unique endpoint name for the project.
- Go to Endpoint Selection.
- From the list, select Microsoft 365 Graph API.
- Click Add.
- Click Save Project.
Step 3: Configure the Graph API Endpoint
After you add your Endpoint, configure it in the Source/Destination settings screen following these steps:
Source Endpoint
-
Use Application Permission is already selected for the Permissions setting. Although present, Delegated Permissions are currently disabled and cannot be selected. Do not check the Use BYO Application checkbox.
- Enter the following details:
Migration Service Account: an email address used for domain discovery purposes. It can be any user account in the tenant and does not require an O365 license or admin role to be assigned to the user.
Tenant ID: copy the value you saved in Step 1.
- Click Next Step.
Destination Endpoint
-
Use Application Permission is already selected for the Permissions setting. Although present, Delegated Permissions are currently disabled and cannot be selected. Do not check the Use BYO Application checkbox.
- Enter the following details:
Migration Service Account: an email address used for domain discovery purposes. It can be any user account in the tenant and does not require an O365 license or admin role to be assigned to the user.
Tenant ID: copy the value you saved in Step 1.
- Click Next Step.
- On the Project Setting page, click Save and Go to Summary. Do not check either of the boxes shown below, unless you are using the Exchange Online using Graph API (Microsoft 365) to Exchange Online using Graph API (Microsoft 365) Mailbox Migration Guide using Coexistence guide.
Step 4: Review the Project Summary and Grant Consent
After configuring both Source and/or Destination endpoints you need to grant consent to the Entra ID Application in your tenant with MigrationWiz. This step grants consent to and installs the BT Application named MigrationWiz-Mailbox-FullControl in the tenant.
Note
An account with a Global Administrator role is required to grant consent.
- Click on the Application Consent button as shown above. You are redirected to the Microsoft Identity Platform (Login Page). The account used to login need to have the Global Administrator role in the tenant.
- If the Consent is successful, the following message appears in your browser. Close the page and continue with the next step.
- Once Consent is successful for the Source/Destination tenant, the status changes from Pending Authorization to Authorized.
Step 5: Grant the Application Exchange Administrator Role
After you complete consent for the BT App, you need to grant your application the Exchange Administrator Role. The following steps allow you to grant this role:
- From the Entra Admin Center menu, select Roles & admins.
- In the search bar, type Exchange, then click Exchange Administrator.
- On the Exchange Administrator role assignments page, click Add assignments.
- Search for the BT Application name (MigrationWiz-Mailbox-FullControl) to grant this role and mark the checkbox.
- Click Add.
- A confirmation message, "Successfully Added Assignment", appears in the top right corner.
Consent Flow:
- Click on Application Consent.
- Sign in using Global Administrator credentials.
-
Review permissions requested by the application.
The following API Permissions are included in the BitTitan App when installed in your tenant:
IMPORTANT
All the permissions you see below, apply to all the Supported Migration Scenarios using Microsoft 365 Graph API using a single application. If you require more scoped API Permissions for your source and/or destination tenant, use one of the BYO Application Options:-Authentication Requirements for Graph API using the BYO App with Client Secret
-Authentication Requirements for Graph API using the BYO App with Client CertificatePermission Name Type Data Type Purpose Calendars.ReadWrite Application Calendar Read and write calendars in all mailboxes Contacts.ReadWrite Application Chat Read and write contacts in all mailboxes Directory.ReadWrite.All Application Directory Read and write directory data Domain.Read.All Application Domain Read domains Group.ReadWrite.All Application Group Read and write all groups GroupMember.ReadWrite.All Application Group Read and write membership of groups across the tenant Group-Conversation.ReadWrite.All Application Group Read and write group conversations Mail.ReadWrite Application Mail Read and write mail in all mailboxes Mail.Send Application Mail Required for MIME Content extracts for IMAP, Pop and Zimbra as source for import in the destination using Graph MailboxFolder.ReadWrite.All Application Mailbox Folder Read and write all the users' mailbox folders MailboxSettings.ReadWrite Application Mailbox Setting Read and write all user mailbox settings Organization.Read.All Application Organization Read organization information Tasks.ReadWrite.All Application Tasks Read and write all users' tasks and task lists User.ReadWrite.All Application User Read and write all users' full profiles Exchange.ManageAsApp Application Office 365 Exchange Online Manage Exchange as Application (Required for migrating calendar folder permissions and mailbox folder permissions) - Click Accept.
- Grant the Application Exchange Administrator Role.