Skip to content

Migrate from Exchange Server to Exchange Online

When you move from a local Exchange Server to Exchange Online in Microsoft 365, you must update the mail account configuration in Sophos Mobile.

The policy you assign to a device includes an Email account configuration to set up a mail account. When you change your mail server to Exchange Online, you must adjust the settings in that configuration.

You have two options:

  • Update the policy with a new Email account configuration.
  • Replace the policy with one that contains the new Email account configuration.

Depending on how you’ve structured your policies, either of these options might be easier to implement. Here, we assume that you replace the policy.

To migrate devices from Exchange Server to Exchange Online, do as follows:

  1. Create a policy, for example by duplicating the policy currently assigned to your devices.

    Repeat this step for the following device policies, if applicable:

    • Android Enterprise device policies
    • Android Enterprise work profile policies
    • Android device policies
    • iOS device policies
    • iOS user policies
    • macOS user policies
    • Windows policies
  2. Edit the Email account configuration.

    Configure the following settings:

    1. In Server name, enter

      Note that applies to the worldwide Microsoft 365 cloud. If you’re using a different Microsoft 365 cloud, such as Office 365 Germany, see the Microsoft document Office 365 URLs and IP address ranges.

    2. In User, enter the %_EMAILADDRESS_% placeholder. Sophos Mobile replaces it with the user’s email address.

    3. If your Microsoft 365 tenant has modern authentication (OAuth) turned on for Exchange Online, select the following:

      • For Android Enterprise policies, select Authentication > Modern authentication.
      • For iOS and macOS policies, select Turn on OAuth 2.0.

      Microsoft 365 tenants created after August 1, 2017, have modern authentication turned on by default.

    4. We recommend that you turn on SSL/TLS to secure the connection to Exchange Online.

    Configure the remaining settings as needed. For details, see the policy-specific pages on Email account configuration in this help.

  3. To replace the policy on the devices, do as follows:

    1. Create a task bundle.
    2. Add an Assign policy task for the new policy.
    3. For Android device policies and iOS device policies, add an Uninstall policy task for the old policy.
    4. For iOS user policies, add an Unassign iOS user policy task for the old policy.
    5. Transfer the task bundle to the relevant devices.
  4. If you’re using Self Service Portal configurations, replace the enrollment task bundle in those configurations with a task bundle that assigns the new policy.

  5. If you’re using the Sophos Mobile EAS proxy for email access control, set it up in PowerShell mode, not proxy mode. The latter doesn’t support Exchange Online.

    See Set up email access control through PowerShell.