[Announcement] On Demand Migration – Sites.Selected Support for OneDrive

Announcing Support for Sites.Selected for OneDrive Migrations

Extending LeastPrivilege Security to Personal Data

As Microsoft 365 environments continue to mature, security expectations across all workloads are rising. SharePoint and Teams migrations have already embraced leastprivilege access through support for Sites.Selected, while mailbox migrations rely on RBAC for Exchange to scope access to only what is required.

OneDrive migrations, since release of such scoping capabilities in On Demand Migration (ODM), had to continue utilising more broader permissions. This was not due to technical limitations, but because focus was placed on other highpriority improvements within the ODM for OneDrive module. Growing customer and partner demand has now elevated leastprivilege access for OneDrive as a priority in its own right.

That feedback has driven the next step forward.

Quest On Demand Migration has now officially extended support for Sites.Selected to OneDrive migrations, allowing organizations to apply a consistent security and governance model across SharePoint, Teams, Exchange mailboxes, and OneDrive.

 

Why Security Matters for OneDrive

OneDrive is often viewed as “personal storage,” but in practice it frequently contains some of the most sensitive data in an organization:

  • Executive working documents
  • Personal and regulated user data
  • Files shared broadly across teams or tenants
  • Legacy content accumulated through years of organic usage

While Exchange migrations already leverage RBAC to scope mailbox access, and SharePoint and Teams migrations can be constrained using Sites.Selected, OneDrive migrations historically lacked an equivalent leastprivilege model. This created an inconsistent security posture across Microsoft 365 workloads.

With the introduction of supported Sites.Selected configurations, that gap is now closed.

 

Official Support for Sites.Selected in ODM OneDrive Migrations

Quest has completed Quality Assurance validation of OneDrive migrations using Sites.Selected permissions and now officially supports this configuration in On Demand Migration.

This means customers can adopt this approach with confidence, benefiting from:

  • Supported and validated configurations
  • Predictable migration behavior
  • Clear troubleshooting and escalation paths

The resulting security, compliance, and operational benefits mirror those already available when migrating SharePoint sites, Teams content, and Exchange mailboxes.

 

What Is Sites.Selected (and How It Applies to OneDrive)?

Sites.Selected is a Microsoft Graph application permission that allows administrators to grant access only to explicitly approved SharePoint sites, rather than permitting tenantwide access.

Because each OneDrive is backed by an individual SharePoint site collection, the same permission model can be used to precisely control which OneDrive sites are accessible during a migration.

 

Benefits of Using Sites.Selected for OneDrive Migrations

Stronger Security for Personal Data

  • Access is limited to explicitly approved OneDrive sites
  • No tenantwide SharePoint permissions are required
  • Reduced exposure of personal and businesscritical files

Improved Compliance and Governance

  • Consistent leastprivilege model across Exchange, SharePoint, Teams, and OneDrive
  • Better alignment with internal security and privacy standards
  • Reduced risk of overprivileged migration tooling

More Granular Control

  • Explicit selection of OneDrive sites included in scope
  • Clear visibility into what the application can access
  • Easier validation prior to migration execution

Easier Auditing and Cleanup

  • Clear audit trail for migration access
  • Simple removal of permissions once migration completes
  • No lingering elevated access postproject

Current Setup Experience for OneDrive

Today, enabling Sites.Selected for OneDrive migrations requires manual configuration steps. These steps are fully documented in the following knowledge base article: https://support.quest.com/kb/4382683.

This approach is fully supported but involves refining application permissions after initial consent.

 

What’s Coming Next: A Dedicated OneDrive Application

To further simplify setup and reduce manual steps, Quest is planning a dedicated On Demand Migration OneDrive application, similar to what exists today for SharePoint.

Planned Improvements

  • Application provisioned with Sites.Selected only
  • No need to remove broader permissions postconsent
  • Cleaner, safer, and faster initial setup

Planned availability: Q3 2026

This will make leastprivilege OneDrive migrations the default path from day one.

 

Concluding Thoughts

With official support for Sites.Selected in OneDrive migrations, Quest On Demand Migration now enables a consistent, leastprivilege security model across all major Microsoft 365 workloads. Customers no longer need to compromise between migration efficiency and security posture as least privilege is now achievable across SharePoint, Teams, Exchange, and OneDrive using Quest On Demand Migration.