Box-to-SharePoint migration success hinges on storage audits, Box Notes .docx conversion, permission redesign before migrating, and knowing which features silently break.
Box and SharePoint are built on fundamentally different architectures. Box is a folder-centric cloud storage platform with unlimited storage and flat permission hierarchies. SharePoint is a site-based document management system governed by Microsoft 365 Groups, managed metadata, and strict storage quotas. The migration is driven by Microsoft 365 consolidation — eliminating a separate Box invoice when E3/E5 licenses already bundle SharePoint and OneDrive. Success hinges on storage audits, Box Notes conversion to .docx, permission redesign before migration, and knowing which features — shared links, version history, external collaborators — silently don't transfer.
Read this first
Pair-specific gotchas that catch teams out. Each one has cost somebody a weekend.
OneDrive pre-provisioning
If you choose OneDrive as the destination, pre-provision OneDrive for users in your organization before migration. Otherwise, the OneDrive destinations aren't going to pass validation, causing migrations to fail.
Plan for Power Automate rebuilds
Any workflow logic in Box Relay needs to be rebuilt in Power Automate. Power Automate is capable but architecturally different — its SharePoint connector Get items action defaults to returning 100 results, and you must configure pagination for larger datasets. See our SharePoint Import Guide for workarounds.
Do not copy a messy Box permission model 1:1 into SharePoint
Redesign the target first, then map into that design. Otherwise you trade one access model for a broken-inheritance cleanup project.
Do not rename or restructure during migration
The risks that come with rearranging content during the migration are primarily in the form of data duplication; the incremental process sees all changes as new data. If you change a folder name at the root, it detects that as a new folder, and all of the contents is retransferred, including all subfolders.
The runbook
Work top to bottom. Tick steps as you go — your progress is saved in this browser.
01 Discovery Decide what content deserves to move before you plan how to move it.
Objective A content inventory with a keep/rewrite/retire decision on every article and an agreed URL strategy.
Keep these open
-
Inventory all content in Box
Count articles, categories, attachments, images and embedded media, and pull page views and last-updated dates for each article. Usage data is what makes the next decision defensible rather than political.
Data Profiler Get real record counts instead of estimating from memory -
Make a keep, rewrite or retire call on every article
Most knowledge bases are half stale. Migrating everything imports the staleness and doubles the work; use views and last-updated to triage, and get the owning team to confirm. This usually removes 30-50% of scope.
Migrating stale content is the most common knowledge-base migration mistake — it costs effort and actively degrades the new site.
-
Agree the URL and redirect strategy
Decide the SharePoint URL structure and whether you can serve 301 redirects from the old paths. Public help centres carry real search traffic and inbound links; losing it is a measurable commercial impact.
Without 301 redirects from old article URLs you lose accumulated search ranking and every external link and bookmark breaks.
-
Map the information architecture
Document the current category tree and design the target one, checking whether SharePoint supports your nesting depth. Deeply nested hierarchies frequently have to be flattened, which changes navigation for everyone.
-
Confirm permissions, audiences and localisation scope
Establish which content is public, internal or restricted, and how SharePoint models that. Then confirm how many locales you have and whether translation relationships between articles survive the move.
Don't move on until
- Full content inventory with page views and last-updated dates
- Keep / rewrite / retire decision recorded per article
- URL and redirect strategy agreed with whoever owns SEO
02 Data Audit Audit the markup, the links and the assets — that is where KB migrations break.
Objective A content export with markup, internal links and every embedded asset accounted for.
Keep these open
-
Export content and assess markup fidelity
Export articles in the richest format available and inspect what survived: tables, code blocks, callouts, nested lists, anchors and embedded video. Rich formatting is where fidelity is lost, and it is lost quietly.
HTML-to-Markdown conversion routinely mangles nested lists, tables and code blocks. Inspect the output rather than trusting the converter.
Data Profiler Profile the Box export for nulls, outliers and type drift -
Inventory every internal link and cross-reference
Extract all internal links, anchor links and article cross-references. These break by default: the target URL structure differs, so every internal link needs rewriting as part of the load, not afterwards.
Internal links left pointing at old URLs turn the new knowledge base into a maze of 404s on day one.
-
Inventory images, attachments and embedded media
List every asset with its URL, size and type, and confirm each still resolves. Assets hosted on the old platform's CDN will 404 the moment you decommission it, so they must be rehosted, not referenced.
Images referenced from the source platform's CDN break when the old account closes. Download and rehost every asset.
-
Find and fix broken links and orphans
Crawl for existing broken internal and external links, and find articles no category links to. Fix them before migrating — a migration is a bad time to discover pre-existing rot.
-
Check for PII and internal information in public content
Scan for customer names, internal hostnames, credentials in code samples and screenshots containing real data. Republishing these on a public help centre is a disclosure, and screenshots are the usual culprit.
PII & Compliance Scanner Find regulated fields before they land in a new system -
Normalise metadata
Standardise authors, tags, timestamps to UTC, and locale codes. Author mapping needs a decision for people who have left — attribution to a deleted user usually fails the import.
Box → SharePoint specifics
- Box Groups
- which will need to become SharePoint Groups or Entra ID security groups
- Permission audit
- Spot-check 10–20 folders across different permission levels. Verify the right users have the right access. Ensure no unintended "Everyone except external users" permissions were applied to sensitive HR or Finance libraries.
- External collaborator audit
- Verify that all required vendors and partners have redeemed their Entra ID guest invitations and can access their designated content.
Don't move on until
- Content exported with markup fidelity assessed
- Every internal link and asset reference inventoried
- Broken links and missing assets fixed or logged
03 Field Mapping Map structure, metadata, permissions and — above all — URLs.
Objective A mapping covering article fields, taxonomy, permissions and a complete old-to-new URL map.
Keep these open
-
Map the article schema
Map title, body, excerpt, author, dates, status, tags, SEO metadata and any custom properties. Confirm which fields SharePoint lets you set on import versus which it computes — computed dates are a common surprise.
Schema Mapper Opens pre-loaded with the Box → SharePoint field pair -
Map the taxonomy and hierarchy
Map categories, sections and tags to the target structure, resolving any nesting-depth limit explicitly. If you must flatten, decide how the lost level is preserved — usually as a tag or a title prefix.
JSON to CSV Converter Flatten nested API responses into a reviewable sheet -
Map permissions and audience segmentation
Map public, logged-in, and role-restricted visibility to SharePoint's model. Verify the mapping deliberately: internal content accidentally published publicly is the highest-severity failure in this whole category.
Permission mapping errors publish internal documentation to the open web. Verify visibility on every restricted article after load.
-
Build the complete old-to-new URL map
Produce a row per article mapping the old URL to the new one, then confirm exactly where the 301s will be served — SharePoint, a CDN, or your own web layer. Without this artifact the redirect step cannot be executed at all.
-
Define the markup conversion and link-rewrite rules
Specify how each markup construct converts and how internal links are rewritten using the URL map. Write it as a repeatable transform, not manual edits — you will run it more than once.
Data Format Converter Reshape the export into the format SharePoint's importer expects -
Plan localisation and freeze the spec
Confirm how translated articles link to their source language in SharePoint, then version and sign off the mapping spec.
Don't move on until
- Article schema and taxonomy mapped
- Permission and audience model mapped to target equivalents
- Complete URL map produced and redirect method confirmed
04 Test Migration Pilot the hardest articles, then read them.
Objective A pilot load whose formatting, links, assets and search all hold up under human review.
Keep these open
-
Configure SharePoint with the agreed structure
Create the category tree, permission groups, locales and branding before loading. Articles loaded before their categories exist land uncategorised and have to be moved by hand.
-
Pick the most difficult articles as the pilot
Choose 20-50 articles for difficulty: the longest, the most heavily formatted, ones with tables and code blocks, deep internal linking, many images, embedded video, restricted visibility, and non-Latin scripts. Easy articles prove nothing.
-
Run the conversion and load with link rewriting
Apply the markup conversion, rewrite internal links from the URL map, upload and re-reference assets, then load. Log every conversion warning rather than suppressing it.
-
Read every pilot article side by side
Open source and target together and compare rendering. This step is manual on purpose: no automated check catches a table that collapsed into a paragraph or a code block that lost its indentation.
-
Click every link and load every asset
Verify each internal link resolves, each image loads from the new host, each attachment downloads and each embed plays. Assets still served from the old CDN are the defect that surfaces only after decommissioning.
Migration Validation Tool Diff the pilot batch against source before scaling up -
Test search and permissions
Search for known terms and confirm the right articles rank, then verify every restricted pilot article is invisible to an anonymous browser. Test permissions from a logged-out session, not an admin one.
Don't move on until
- Complex articles render correctly with formatting intact
- Every internal link and asset in the pilot resolves
- Search returns sensible results for the pilot content
05 Cutover Publish, redirect, and keep the search traffic.
Objective All in-scope content live in SharePoint with redirects serving and search engines informed.
Keep these open
-
Load the full content set ahead of the switch
Run the full conversion and load into SharePoint, unpublished or on a staging domain. Content migration differs from data migration here: you can stage the whole thing before anyone sees it.
-
Publish the runbook with the redirect step first-class
Sequence the freeze, final delta, publish, redirect activation, sitemap submission and link updates, with owners for each. Redirect activation is the step with lasting commercial consequences, so it gets explicit ownership.
-
Freeze editing and migrate the delta
Stop editing in Box, then convert and load anything changed since the full load. Announce the freeze to every team that publishes — content teams are used to editing whenever they like.
-
Publish and verify permissions live
Publish the content set, then immediately verify restricted articles are not publicly reachable using an anonymous session. Do this before announcing the new site, not after.
Verify restricted content from a logged-out browser. An admin session will show you everything and tell you nothing.
Migration Validation Tool Confirm the final delta landed before you reopen -
Activate 301 redirects and submit the sitemap
Turn on the redirects from the URL map, then spot-check a sample of high-traffic old URLs and confirm each returns 301 to the right article. Submit the new sitemap and keep the old one reachable until search engines have recrawled.
Redirect chains and redirect loops both leak ranking. Verify each redirect resolves in a single hop.
-
Repoint in-product and support links
Update help links embedded in your product, in support macros, in email templates and in onboarding material. These are the links your existing customers actually use, and they are easy to forget.
Don't move on until
- All content loaded, categorised and correctly permissioned
- 301 redirects live and verified from a sample of old URLs
- Sitemap submitted and support links repointed
06 Validation Watch traffic, links and search rankings for weeks, not hours.
Objective Verified content completeness, healthy redirects, and search traffic recovered to baseline.
Keep these open
-
Reconcile content counts and assets
Compare article counts by category and status, plus asset counts, against source. Confirm every article in the keep list is present and every retired one genuinely is not.
Migration Validation Tool Reconcile Box and SharePoint record-for-record -
Crawl the new site for broken links and assets
Run a full crawl for 404s, broken images and missing attachments, and fix everything it finds. Repeat the crawl after the fixes rather than assuming they worked.
-
Verify the redirects at scale
Test every mapped old URL for a single-hop 301 to the right destination. Chains and loops both leak ranking and are invisible unless you check the whole map, not a sample.
-
Monitor organic traffic and rankings for four to eight weeks
Track organic sessions, impressions and rankings for your top articles against baseline. A dip in the first two weeks is normal; one that has not recovered by week six is a redirect or indexing problem to investigate.
Do not decommission the old platform until search traffic has recovered — you may still need the old URLs to diagnose a ranking loss.
-
Verify search, permissions and feedback loops
Confirm on-site search returns good results for real queries, re-verify restricted content from a logged-out session, and check article feedback and analytics are collecting.
-
Sign off and decommission on a delay
Get acceptance against the Discovery criteria, keep Box available read-only until traffic has recovered, take a final export, and only then close the account.
Box → SharePoint specifics
- File count reconciliation
- Compare total file counts between Box source and SharePoint destination. Account for files skipped due to path length, zero-byte files, or unsupported types.
- Box Notes conversion verification
- Open a representative sample of converted .docx files. Check formatting, tables, embedded images. Watch for silently dropped annotations and tables of contents.
- Link rewriting
- Internal documents referencing Box URLs now have broken links. Identify and update the highest-traffic ones. Broken Box URLs circulate in emails, wikis, and Slack for years.
- List view threshold
- If any document library exceeds 5,000 items, verify that list views are indexed properly.
Don't move on until
- Article counts reconciled and no broken links remain
- Redirects returning 301 with no chains or loops
- Organic traffic recovered to within tolerance of baseline
Field mapping reference
The field-by-field mapping for each object. Use this as the starting point for your mapping spec.
Source Target
| Box field | SharePoint field | Notes |
|---|---|---|
| Personal folders (per user) | OneDrive for Business | Pre-provision OneDrive accounts before migration |
| Team/department folders | SharePoint document libraries (one per team site) | Design site architecture first |
| Archived or cold data | Azure Blob Storage or archive site | Don't burn SharePoint quota on files no one opens |
| Project-specific folders | SharePoint sites or Teams channels | Consider hub site architecture |
Role Equivalent
| Box field | SharePoint field | Notes |
|---|---|---|
| Owner | Site Owner / Full Control | Map carefully — Site Owner grants broad admin rights |
| Editor | Edit or Contribute | "Edit" includes delete; "Contribute" doesn't |
| Viewer | Read | Direct mapping |
| Uploader | Contribute (custom) | No direct SharePoint equivalent |
Approach Best For
| Box field | SharePoint field | Notes |
|---|---|---|
| ClonePartner (Engineer-Led Service) | Enterprises (50TB+), complex permissions, compliance, zero downtime | Custom conversion pipeline — programmatically validates every file |
| ShareGate / AvePoint | Mid-market DIY with dedicated IT staff | Converts to .docx (unverified output) |
| Basic DIY Tools (Movebot, Cloudiway, CloudM) | Simple, flat folder structures | Varies (often raw JSON or basic Word docs) |
Risk matrix
Per-object risk for this pair. Plan extra validation around anything marked high.
| Object | Risk | Notes |
|---|---|---|
| Box Shared Links | high | Not migrated — every internal and external URL breaks |
| External Collaborator Access | high | Must be manually re-invited post-migration |
| File Version History | high | Migration Manager transfers only the most recent version |
| Box Tasks | high | No transfer — must be recreated in Planner or To Do |
| Box Relay Workflows | high | Must be rebuilt from scratch in Power Automate |
| Box Notes | medium | Converted to .docx but annotations and TOC may be dropped |
| Box Comments | medium | Tool-dependent — validate with your exact migration tool |
| File Permissions | medium | Internal permissions can be mapped but require redesign |
| Metadata & Tags | medium | Requires pre-defined SharePoint site columns to preserve |
| File Content | low | Standard files and folder structures migrate cleanly |
The hard parts
What makes this specific migration difficult, beyond the mechanics.
Permission Redesign
Box uses folder-level collaboration roles. SharePoint uses site-and-library inheritance with unique permission scopes that are difficult to audit or clean up after the fact.
Box Notes Conversion
Box Notes are a proprietary format incompatible with Microsoft Office. Conversion to .docx drops elements like annotations, file previews, and tables of contents.
Storage Reconciliation
Box offers unlimited storage. SharePoint allocates 1 TB per tenant plus 10 GB per user, requiring aggressive data auditing.
External Collaborators
Migration Manager does not share content with external users by design. Every external collaborator must be manually re-invited.
Path Length Limits
SharePoint enforces a 400-character path limit. Deep Box folder hierarchies with long filenames fail silently during migration.
Tools used in this playbook
All free, all run entirely in your browser — nothing is uploaded.
FAQ
Does the SharePoint Migration Tool (SPMT) support Box as a source?
No. SPMT only supports on-premises SharePoint Server and local file shares. For Box, use Microsoft's Migration Manager (free, in the SharePoint Admin Center) or a third-party tool like ShareGate, AvePoint, Movebot, Cloudiway, or CloudM. For enterprises needing zero-downtime migration with full permission redesign and Box Notes conversion handled end-to-end, ClonePartner offers a managed engineering service that eliminates the tool-selection guesswork entirely.
What happens to Box Notes when migrating to SharePoint?
Box Notes are a proprietary format incompatible with Microsoft Office. Migration Manager and most third-party tools convert them to .docx, but elements like File Preview, Table of Contents, and Annotations may be omitted. Movebot converts to JSON instead of .docx. Always run a pilot batch and verify the output before a full migration.
Do Box sharing permissions transfer to SharePoint automatically?
Internal permissions can be mapped using identity mapping in Migration Manager or third-party tools. External collaborators must be re-invited manually — Migration Manager does not share content with external users by design. Shared links are not migrated and must be recreated.
What Box features do NOT migrate to SharePoint?
Box Shared Links, Tasks, Relay workflows, third-party app integrations, external collaborator access, and file version history (in Migration Manager) do not transfer. Box Comments are tool-dependent — Cloudiway says they don't migrate, while Microsoft FastTrack says they do. Validate with your exact tool.
How long should I keep Box active after migrating to SharePoint?
Keep Box running in read-only mode for a minimum of 30 days after migration — 60 days for large enterprises or regulated industries. Run a final delta sync before canceling to catch any missed files.