Connecting to source Office 365

Once the installation of CodeTwo Office 365 Migration is finished, you need to choose a source environment from which the data will be pulled and migrated to selected mailboxes in target Office 365. This article describes how to connect to source Office 365 tenant.

To create a new source Office 365 connection, click the Settings (Office 365 Migration settings button temp) button on the Defined source server connections card and choose New > Office 365 connection (Fig. 1.). You can also define a new source connection when configuring a migration job. To do so, click Create a new migration job on the How to start card and select Office 365. Type the name of your job and proceed to the Source mailboxes step. Select Add new source connection from the Source server drop-down list to open the source server connection wizard. 

O365 Migration - source Office 365 connection - opening wizard
Fig. 1. Opening the Office 365 source server connection wizard.

Either way, the Office 365 source server connection wizard opens. It consists of the following steps:

Office 365 cloud (legacy setting)

In the Office 365 cloud step (legacy setting), select Office 365 global.

Office 365 Germany

Office 365 Germany (Microsoft Cloud Deutschland) was officially retired on October 29, 2021, so you may not be able to connect to it anymore. If that's the case, choose Office 365 global instead. Read more about Office 365 Germany

Application registration

To connect to your Office 365 tenant, you need to register CodeTwo Office 365 Migration in that tenant's Azure Active Directory. By doing so, the program will be able to authenticate with Office 365 via OAuth 2.0, access source mailboxes and perform the migration tasks on your behalf.

There are two options available:

Automatic registration

Select this option if you want the CodeTwo migration application to register itself in your Azure AD. Click Log in as Office 365 admin (Fig. 2.) to load the Azure sign-in page.

Registering the program automatically in Azure AD.
Fig. 2. Registering the program automatically in Azure AD.

Next, provide the credentials of a global admin of your Office 365 tenant and accept all permissions the application has requested to be able to perform the migration (Fig. 3.).

O365 Migration source O365 azure permissions v3.2
Fig. 3. Granting the necessary permissions to CodeTwo Office 365 Migration.

The application will be registered as CodeTwo Office 365 Migration Source in your Azure AD and will be signed with a unique certificate, valid for 5 years.


Each time you configure a new Office 365 server connection in the program by using the Automatic registration option, a new CodeTwo migration application entry will be registered in your Azure AD (this does not apply to situations where you edit an existing connection). If you don't want to duplicate these entries in your tenant, select the Manual registration option and provide the registration details of the previously registered CodeTwo migration application in the Application details step. You can view the application registration details by signing in to your Azure Active Directory admin center and navigating to Azure Active Directory > App registrations.

Keep in mind even if you delete this connection from the program, or once the migration is finished, the application will not be deleted from your Azure AD. To delete it manually, follow these steps.

Manual registration

Select the Manual registration option (Fig. 4.) if you prefer to register the CodeTwo migration application in Azure AD by yourself. A step by step guide on how to do so is available in this Knowledge Base article. Click Next to proceed to the next step, where you need to provide the application registration details.

Selecting the Manual registration option.
Fig. 4. Selecting the Manual registration option.

Application details

The Application details step is required only if you have selected the Manual registration option. You are asked to provide the following information:

  • Dedicated application mailbox – the email address of any user from your source Office 365 tenant. This account is used to gain access to the tenant's information, such as name, domain, etc.
  • Client ID – this is the ID assigned to CodeTwo Office 365 Migration after the application has been registered in your Azure AD. The ID can be found on the application's Overview page in the Azure Active Directory admin center, under Application (client) ID (Fig. 5.).
  • Tenant ID – this the ID of your Office 365 tenant. It also can be found on the application's Overview page, under Directory (tenant) ID (Fig. 5.).
  • Certificate thumbprint or Client secret – only one of these credentials needs to be provided in the wizard. You can add or view certificates and client secrets (app passwords) on the application's Certificates & secrets page in Azure Active Directory (Fig. 6.).

O365 Migration source Office 365 connection - Azure AD application Overview page
Fig. 5. Client and tenant IDs shown on the application's Overview page in Azure AD.

The location of a certificate thumbprint (A) and client secret (B) in Azure AD.
Fig. 6. The location of a certificate thumbprint (A) and client secret (B) in Azure AD.

To use the Certificate thumbprint credential, your certificate needs to be signed with a 2048 bits key. The certificate also needs to be installed in the CurrentUser\Personal store. Use the Import button to open the Import certificate window (Fig. 7.), where you can select your certificate. If your certificate is already installed in the CurrentUser\Personal store, simply enter the certificate thumbprint in the appropriate field in the server connection wizard.

Importing the certificate associated with the CodeTwo migration application.
Fig. 7. Importing the certificate associated with the CodeTwo migration application.

Client secret can be generated in Azure AD on the Certificates & secrets page (see Fig. 6. above). Once generated, it will be visible for as long as you remain on that page, so make sure to copy its value to the clipboard and paste it in the server connection wizard (Fig. 8.).

Application registration details filled out in the source Office 365 server connection wizard.
Fig. 8. Application registration details filled out in the source Office 365 server connection wizard.


In the last step, the wizard will set up a connection between the program and your source Office 365 tenant (and register the CodeTwo migration application in your Azure AD, if you have selected the Automatic registration option in the previous step). Click Configure and verify the results (Fig. 9.).

O365 Migration source O365 configuration
Fig. 9. The program has successfully connected to the source Office 365 tenant.

Once the setup is complete, click Finish to close the wizard, and then click OK in the Manage source server connections window to save your connection. The new connection will be displayed on the Defined source server connections card (Fig. 10.).

O365 Migration source O365 defined connection v3.2
Fig. 10. The Defined source server connections card.

If you encounter any problems during the server configuration process, see Troubleshooting

See next

Connecting to a target Office 365 environment

Configuring a migration job

Managing server connections

In this article

Was this information useful?