Smart Migrations: Preparing Legacy File Shares for the Cloud
-
Published on Aug 25, 2026
By: Jason Brandes
Moving legacy file shares into Microsoft 365 can look like a technology project. In practice, it is an opportunity to make better decisions about years, sometimes decades, of accumulated information.
Many organizations accelerated their move to Microsoft 365 during the pandemic. Email moved. OneDrive and SharePoint environments were created. Employees gained new ways to collaborate remotely. But in the rush to keep businesses operating, legacy file shares often remained in the background, holding years of information that still needs attention. A migration creates a natural point to address that backlog and determine what should move forward.
Think about moving to a new house. You can take everything from the garage and attic, load it into boxes, and move it exactly as it is. But if you already know some of those boxes contain things you no longer need, moving them does not make the problem go away. All you did was change where the clutter lives.
Legacy data works the same way.
- Do Not Move the Problem to the Cloud
- Start With People and Process, Then Apply Technology
- Migration Is an Opportunity to Fix Security Creep
- Modernize How Information Is Organized, Found, and Governed
- A Migration Should Improve Litigation Readiness
- The Migration Ends. Governance Does Not.
- A Smart Migration Is a Modernization Opportunity
A smart migration is not simply about moving files from one platform to another. It is an opportunity to decide what should move, improve how information is organized and secured, and create an environment that better supports how people work today.
Do Not Move the Problem to the Cloud
Legacy file shares tend to grow organically. Projects end, but their folders remain. Employees leave while their data persists. Departments reorganize, duplicate documents spread across personal and shared drives, and temporary files, old software, outdated materials, and prior versions accumulate because keeping information has traditionally been easier than deciding what to do with it.
Over time, organizations can lose visibility into what they have, who owns it, and whether it still provides business, legal, or regulatory value. That makes migration an important decision point.
Redundant, obsolete, and trivial information (ROT) can often be identified using characteristics such as file type, age, ownership, duplicate status, last-accessed dates, and other metadata. Organizations can then evaluate those characteristics against organization-specific rules, rather than forcing employees to make individual decisions about millions of files.
The goal is not to delete as much information as possible. It is to avoid spending time and money moving information that provides little or no continuing value. That connects directly to the storage challenge discussed in the first article in this series, Stop the Bleeding: Smart Microsoft 365 Storage Cleanup and Cost Optimization. Cleaning legacy information before migration can help organizations avoid beginning their Microsoft 365 journey with the same storage problem they had in the old environment.
Start With People and Process, Then Apply Technology
Large migration projects can feel overwhelming, particularly when an organization has decades of information spread across different departments and file structures. Rather than beginning at the individual-file level, the more practical starting point is to understand the people, processes, and business requirements that will shape the migration.
Before migration begins, organizations can work with business, IT, legal, records, security, and information governance stakeholders to understand what information exists and establish rules for how different categories should be treated. Some categories may be obvious candidates for remediation, while others require more context.
Consider an HR policy document that is 10 years old. Its age alone does not determine whether it should be deleted. The organization needs to understand whether the policy is still operative, whether a retention requirement applies, whether it has legal significance, or whether a more current version has replaced it.
That same process can be applied at scale. Once the organization defines what matters, technology can help classify, label, migrate, retain, or remediate information according to those decisions. The technology is often the easier part. The more important work is defining what the organization wants the technology to do and ensuring that those decisions reflect operational, legal, and governance requirements.
Migration Is an Opportunity to Fix Security Creep
Legacy information environments often contain another issue that storage reports do not show: years of accumulated permissions.
An employee may have needed access to a folder for one project. An administrator added that employee to a group. A department received broader access during a reorganization. Years later, those permissions may still exist even though the original business need is gone. This type of “security creep” can leave users with access to information they no longer need.
We have encountered this during migrations in very practical ways. An old payroll spreadsheet, for example, may still be sitting on a legacy share years after the system migration that created it. The file can contain salary information, Social Security numbers, or other sensitive employee data, while users who once needed access may still be able to open it.
Deleting that information is not always appropriate, but leaving broad legacy access in place is not the only alternative. Migration creates an opportunity to identify sensitive content, reassess permissions, and move information into environments with more appropriate controls. In some cases, access can shift from broadly inherited permissions to a request-based process in which only authorized users can reach sensitive records.
The objective is not to make information harder to use. It is to make access more deliberate and aligned with current business needs, security requirements, and governance expectations.
Modernize How Information Is Organized, Found, and Governed
Migration is also an opportunity to reconsider how information is organized and how people expect to find it.
Many legacy file shares were designed for a world in which users had to remember exactly where they put a document. Deep folder structures made sense because search was limited or unreliable, and that shaped how generations of employees learned to work. Someone who grew up working in traditional file systems may carefully maintain folders for each client, project, contract, work product, and reference document. Increasingly, newer workers expect something different. They are accustomed to typing a few words into a search box and finding what they need regardless of where it is stored.
Neither approach is inherently wrong. But a modern information environment should support the way people actually work rather than forcing a legacy workflow into a new platform. During migration, organizations can standardize inconsistent metadata, add useful classifications, and create more consistent document information. Instead of relying only on a breadcrumb trail of folders, Microsoft 365 users can search using attributes such as document type, business unit, owner, date, matter, project, or other relevant characteristics.
The garage analogy applies here too. If you move a box and label it “contracts,” you may still have to open it years later to find the contract you need. If you describe the information inside more precisely, finding it later becomes much easier.
The same thinking applies to duplicate content. A legacy environment may contain the same spreadsheet in an employee’s personal folder, multiple departmental drives, and several project locations. Simply deleting duplicates can create a user-adoption problem because people may rely on those familiar locations to find the document. A modern environment can provide a better option by maintaining a single document of record while preserving links from the places where users expect to find it. That gives users familiar access while the organization gains greater control over versioning, retention, and updates.
These improvements create value beyond storage. Every unnecessary document that remains in the environment may eventually need to be searched, classified, secured, reviewed, collected, or analyzed. That becomes especially important in litigation, where preserving, collecting, processing, and reviewing a smaller, better-governed information environment is fundamentally different from addressing decades of unmanaged data.
The goal of modernization is not to create a technically perfect structure that makes work harder. It is to simplify the underlying information environment, improve how people find and use information, and reduce the volume and complexity the organization will need to manage later.
A Migration Should Improve Litigation Readiness
The legal impact of migration is closely connected to these governance decisions.
A legacy environment with inconsistent ownership, broad permissions, unclear retention, duplicate content, and years of unnecessary data can create significant challenges when an organization needs to respond to litigation or an investigation. Moving all of that information into Microsoft 365 without addressing those issues does not make them disappear.
A well-planned migration can instead improve visibility into what information exists, who owns it, what needs to be retained, what may be deleted, and where sensitive or legally significant information resides. Those improvements create a stronger foundation for litigation readiness.
The relationship also works in the other direction. Organizations considering cleanup must understand legal holds, retention requirements, and preservation obligations before removing information. Migration therefore becomes another point where IT, legal, and information governance should follow the same plan.
As discussed in Stop the Bleeding, the goal is not simply to store less information. It is to better control the information the organization keeps so it can respond more efficiently when it needs it.
The Migration Ends. Governance Does Not.
One of the most important lessons from migration work is that even a well-executed cleanup does not permanently solve information growth.
In one public-sector engagement, we completed a significant legacy cleanup several years ago. The environment was organized, unnecessary data was removed, and the organization moved forward with a much cleaner information landscape.
Years later, the organization needed help again.
That does not mean the original project failed. It demonstrates what happens naturally when organizations continue creating information. Employees join and leave, new projects begin, business processes change, new file types appear, and retention requirements evolve. Without ongoing governance, even a clean environment gradually becomes another legacy environment.
The answer is not continuous large-scale cleanup. It is establishing an operating model after migration that includes regular reporting, appropriate retention, ownership, training, classification, security controls, and periodic review.
People are central to that model. Users need to understand where information belongs and how the environment is intended to work. If a process is too complicated or creates too much friction, employees will find ways around it and the information problem will begin again. Technology can augment that work through classification, automation, and increasingly AI-enabled tools, but governance still succeeds or fails based on whether people can realistically follow the process.
A Smart Migration Is a Modernization Opportunity
A migration has a defined technical objective: move information from one environment to another. A smart migration goes further by asking what information should make the move, how it should be secured, how users will find it, what should be retained, what can be defensibly removed, and what processes will keep the new environment from becoming the next legacy problem.
Those decisions can reduce unnecessary storage and migration effort today. They can also strengthen security, improve search, support more consistent retention, improve litigation readiness, and build a foundation for the next generation of information management.
That foundation will become increasingly important as organizations expand their use of AI. AI can search and analyze information at a scale humans cannot, which makes the quality and governance of the underlying data even more important. Preparing data for that environment will be the next step in this Information Governance series.
The opportunity is not simply to move the contents of the garage and attic into a new house. It is to decide what belongs in the new environment, organize it so people can find it, and establish a process that keeps the clutter from building up again.
Generative AI tools were used to assist with research, synthesis, drafting, and editorial refinement of this article. The final article reflects the review, judgment, and approval of Innovative Driven.