[Announcement] New Teams Application for On Demand Migration - Teams App Only Permissions

Introducing Teams – App Only Permissions for On Demand Migration

As Microsoft 365 environments continue to mature, customer expectations around security, compliance, and least privilege access have never been higher. Nowhere is this more evident than in Microsoft Teams migrations, where legacy approaches often rely on broad permissions and service accounts that no longer align with modern compliance standards.

To address this, we’re introducing a new application for On Demand Migration for Teams: Teams – App Only Permissions.

This new consent option is designed for organizations with strict compliance and security requirements, enabling Teams migrations without delegated permissions and without adding a migration service account to the source tenant for migration purposes.

# Update: June 2026: This application has now been updated to require READ only permissions. All ReadWrite permissions have been removed #

 

Why This Matters

Many organizations migrating Microsoft Teams often face a difficult challenge:

“How do we move collaboration data without expanding access beyond what security and compliance teams are willing to approve?”

Prior to the introduction of Teams – App Only Permissions, migrating Teams with On Demand Migration required granting consent using a Global Administrator account, which could then be limited to Teams Administrator and Exchange Administrator roles, along with an active M365 Teams license. While this reduced the scope of permissions, migration still relied on elevated permissions.

When using Teams – Minimal applications for the migration, this is still a prerequisite as the Service Account used for the migration is added as a member or owner of source Teams and M365 Groups to access specific Teams, Channels & Groups settings and objects required for a full fidelity migration.

From a functional standpoint, this approach works well. From a security and compliance standpoint, however, it introduced challenges.

For many organizations, particularly those in regulated industries or with strict internal security controls, introducing a licensed service account with administrator roles enabled into production Teams environments on the source tenant (even temporarily) is not permitted. Delegated permissions and user-based access models can also increase audit scope, identity exposure, and risk.

Teams – App Only Permissions directly addresses these concerns by eliminating delegated access entirely and removing the need for a migration service account to participate in Teams on the source tenant, allowing migrations to proceed while staying aligned with modern least‑privilege and compliance requirements.

 

Designed for Compliance Driven Environments

This new application is particularly well suited for organizations that:

  • Must avoid delegated permissions entirely
  • Require reduced identity footprint during migration
  • Need stronger separation between migration tooling and production collaboration workloads

By using application only access, organizations can proceed with migration plans while staying aligned with internal security policies and external regulatory requirements.

 

Feature Impact and Trade Offs

To maintain this restrictive security posture, the Teams – App Only Permissions application intentionally denies access to certain features that require broader or delegated privileges.

When using this application, the following capabilities are not available:

  • Channel settings migration during the Teams Provision task
  • Archiving the source Team with the SharePoint site set to read only
  • Collecting statistics using the Advanced option on the source tenant

These limitations are a direct result of maintaining application only access and avoiding elevation of privileges. For many compliance driven organizations, this is a deliberate and acceptable trade off.

 

Choosing the Right Consent Model

Quest On Demand Migration continues to offer multiple consent models so customers can choose the approach that best aligns with their technical and organizational requirements.

  1. Need maximum fidelity and advanced features?

Teams – Minimal utilizes a broader permission model to meet expectations.

 

  1. Need to align and comply with stricter compliance rules and a smaller footprint?

Teams – App Only Permissions provides a secure, purpose built option.

Our goal is not to dictate a single approach, but to enable an informed choice.

 

Advancing Secure Migrations

This release reflects our ongoing commitment to:

  • Evolving with Microsoft’s security and identity model
  • Supporting real world compliance requirements
  • Giving customers control over how migrations are executed

As security expectations continue to rise, migration tools must evolve alongside them. This new application for On Demand Migration is another step toward making secure, compliant Microsoft 365 migrations not just possible but practical.

 

Learn More

You can find and learn more about configuring and using Teams – App Only Permissions in On Demand Migration in our official User Guide & Permissions Reference guide, here: https://support.quest.com/on-demand-migration/current/technical-documents