Announcing Support for Sites.Selected for OneDrive Migrations
Extending Least‑Privilege Security to Personal Data
As Microsoft 365 environments continue to mature, security expectations across all workloads are rising. SharePoint and Teams migrations have already embraced least‑privilege access through support for Sites.Selected, while mailbox migrations rely on RBAC for Exchange to scope access to only what is required.
OneDrive migrations, since release of such scoping capabilities in On Demand Migration (ODM), had to continue utilising more broader permissions. This was not due to technical limitations, but because focus was placed on other high‑priority improvements within the ODM for OneDrive module. Growing customer and partner demand has now elevated least‑privilege access for OneDrive as a priority in its own right.
That feedback has driven the next step forward.
Quest On Demand Migration has now officially extended support for Sites.Selected to OneDrive migrations, allowing organizations to apply a consistent security and governance model across SharePoint, Teams, Exchange mailboxes, and OneDrive.
Why Security Matters for OneDrive
OneDrive is often viewed as “personal storage,” but in practice it frequently contains some of the most sensitive data in an organization:
- Executive working documents
- Personal and regulated user data
- Files shared broadly across teams or tenants
- Legacy content accumulated through years of organic usage
While Exchange migrations already leverage RBAC to scope mailbox access, and SharePoint and Teams migrations can be constrained using Sites.Selected, OneDrive migrations historically lacked an equivalent least‑privilege model. This created an inconsistent security posture across Microsoft 365 workloads.
With the introduction of supported Sites.Selected configurations, that gap is now closed.
Official Support for Sites.Selected in ODM OneDrive Migrations
Quest has completed Quality Assurance validation of OneDrive migrations using Sites.Selected permissions and now officially supports this configuration in On Demand Migration.
This means customers can adopt this approach with confidence, benefiting from:
- Supported and validated configurations
- Predictable migration behavior
- Clear troubleshooting and escalation paths
The resulting security, compliance, and operational benefits mirror those already available when migrating SharePoint sites, Teams content, and Exchange mailboxes.
What Is Sites.Selected (and How It Applies to OneDrive)?
Sites.Selected is a Microsoft Graph application permission that allows administrators to grant access only to explicitly approved SharePoint sites, rather than permitting tenant‑wide access.
Because each OneDrive is backed by an individual SharePoint site collection, the same permission model can be used to precisely control which OneDrive sites are accessible during a migration.
Benefits of Using Sites.Selected for OneDrive Migrations
Stronger Security for Personal Data
- Access is limited to explicitly approved OneDrive sites
- No tenant‑wide SharePoint permissions are required
- Reduced exposure of personal and business‑critical files
Improved Compliance and Governance
- Consistent least‑privilege model across Exchange, SharePoint, Teams, and OneDrive
- Better alignment with internal security and privacy standards
- Reduced risk of over‑privileged migration tooling
More Granular Control
- Explicit selection of OneDrive sites included in scope
- Clear visibility into what the application can access
- Easier validation prior to migration execution
Easier Auditing and Cleanup
- Clear audit trail for migration access
- Simple removal of permissions once migration completes
- No lingering elevated access post‑project
Current Setup Experience for OneDrive
Today, enabling Sites.Selected for OneDrive migrations requires manual configuration steps. These steps are fully documented in the following knowledge base article: https://support.quest.com/kb/4382683.
This approach is fully supported but involves refining application permissions after initial consent.
What’s Coming Next: A Dedicated OneDrive Application
To further simplify setup and reduce manual steps, Quest is planning a dedicated On Demand Migration OneDrive application, similar to what exists today for SharePoint.
Planned Improvements
- Application provisioned with Sites.Selected only
- No need to remove broader permissions post‑consent
- Cleaner, safer, and faster initial setup
Planned availability: Q3 2026
This will make least‑privilege OneDrive migrations the default path from day one.
Concluding Thoughts
With official support for Sites.Selected in OneDrive migrations, Quest On Demand Migration now enables a consistent, least‑privilege security model across all major Microsoft 365 workloads. Customers no longer need to compromise between migration efficiency and security posture as least privilege is now achievable across SharePoint, Teams, Exchange, and OneDrive using Quest On Demand Migration.