Old messages cannot be replied to
- What people see
- The user's new email address works, but replying to an older message or using an old Outlook autocomplete entry produces an NDR.
- What caused it
- Exchange does not rely only on the visible SMTP address. Historical messages can contain the mailbox's older Exchange identity, commonly represented by
LegacyExchangeDN. If that identity is not preserved in the target as an X500 address, Exchange may no longer know where to deliver the reply. - How it is planned for
- Legacy Exchange addresses are preserved and mapped to the target recipient so old messages and cached recipient entries continue resolving after the move.
Directory synchronization changes the object back
- What people see
- An administrator fixes an address, attribute, or identity in Microsoft 365 and later finds that the change disappeared or a duplicate object appeared.
- What caused it
- The object is synchronized from on-premises Active Directory. The cloud tenant is not the source of authority, so Entra Connect or Cloud Sync applies the authoritative value from the directory again.
- How it is planned for
- The identity source of authority is established before changes begin. In hybrid environments, Exchange and directory attributes are changed at the layer that actually owns them rather than fighting directory synchronization from the cloud.
The CEO moves but the assistant does not
- What people see
- The mailbox migration succeeds, but delegation stops working. An assistant cannot open the executive mailbox, a manager loses Send As, or a shared calendar stops behaving the way it did before.
- What caused it
- The users were migrated as independent accounts even though their mailboxes had relationships between them. Delegation, Full Access, Send As, Send on Behalf, folder permissions, and automapping are not the same thing as mailbox content.
- How it is planned for
- Migration waves are built around business dependencies rather than an alphabetical list of users. Executives and assistants, departments and their shared mailboxes, and other heavily delegated relationships are tested and moved together where practical.
Everyone migrated successfully and nobody can sign in
- What people see
- The data is in the target tenant, but users are blocked when they try to open Outlook, Teams, OneDrive, or Microsoft 365.
- What caused it
- The target tenant may require MFA, a compliant device, an approved authentication method, a trusted location, or another Conditional Access requirement the user's current device does not satisfy.
- How it is planned for
- Authentication and Conditional Access are tested with real pilot users and devices before the production wave. MFA registration, device state, emergency access accounts, and the Day-1 sign-in path are part of cutover testing.