Migration Playbook

Box SharePoint

Box to SharePoint: The Complete Migration Playbook

A 35-step runbook across six phases — track your progress, and open the right tool at every step.

0 / 35 steps complete 0%
TL;DR

Box-to-SharePoint migration success hinges on storage audits, Box Notes .docx conversion, permission redesign before migrating, and knowing which features silently break.

Box and SharePoint are built on fundamentally different architectures. Box is a folder-centric cloud storage platform with unlimited storage and flat permission hierarchies. SharePoint is a site-based document management system governed by Microsoft 365 Groups, managed metadata, and strict storage quotas. The migration is driven by Microsoft 365 consolidation — eliminating a separate Box invoice when E3/E5 licenses already bundle SharePoint and OneDrive. Success hinges on storage audits, Box Notes conversion to .docx, permission redesign before migration, and knowing which features — shared links, version history, external collaborators — silently don't transfer.

Read this first

Pair-specific gotchas that catch teams out. Each one has cost somebody a weekend.

OneDrive pre-provisioning

If you choose OneDrive as the destination, pre-provision OneDrive for users in your organization before migration. Otherwise, the OneDrive destinations aren't going to pass validation, causing migrations to fail.

Plan for Power Automate rebuilds

Any workflow logic in Box Relay needs to be rebuilt in Power Automate. Power Automate is capable but architecturally different — its SharePoint connector Get items action defaults to returning 100 results, and you must configure pagination for larger datasets. See our SharePoint Import Guide for workarounds.

Do not copy a messy Box permission model 1:1 into SharePoint

Redesign the target first, then map into that design. Otherwise you trade one access model for a broken-inheritance cleanup project.

Do not rename or restructure during migration

The risks that come with rearranging content during the migration are primarily in the form of data duplication; the incremental process sees all changes as new data. If you change a folder name at the root, it detects that as a new folder, and all of the contents is retransferred, including all subfolders.

The runbook

Work top to bottom. Tick steps as you go — your progress is saved in this browser.

01 Discovery Decide what content deserves to move before you plan how to move it. 0/5

Objective A content inventory with a keep/rewrite/retire decision on every article and an agreed URL strategy.

  1. Inventory all content in Box

    Content lead 2-3 days

    Count articles, categories, attachments, images and embedded media, and pull page views and last-updated dates for each article. Usage data is what makes the next decision defensible rather than political.

    Data Profiler Get real record counts instead of estimating from memory
  2. Make a keep, rewrite or retire call on every article

    Content lead 1-2 weeks

    Most knowledge bases are half stale. Migrating everything imports the staleness and doubles the work; use views and last-updated to triage, and get the owning team to confirm. This usually removes 30-50% of scope.

    Migrating stale content is the most common knowledge-base migration mistake — it costs effort and actively degrades the new site.

  3. Agree the URL and redirect strategy

    SEO / web 2-3 days

    Decide the SharePoint URL structure and whether you can serve 301 redirects from the old paths. Public help centres carry real search traffic and inbound links; losing it is a measurable commercial impact.

    Without 301 redirects from old article URLs you lose accumulated search ranking and every external link and bookmark breaks.

  4. Map the information architecture

    Content lead 3-5 days

    Document the current category tree and design the target one, checking whether SharePoint supports your nesting depth. Deeply nested hierarchies frequently have to be flattened, which changes navigation for everyone.

  5. Confirm permissions, audiences and localisation scope

    Content lead 2-3 days

    Establish which content is public, internal or restricted, and how SharePoint models that. Then confirm how many locales you have and whether translation relationships between articles survive the move.

Don't move on until

  • Full content inventory with page views and last-updated dates
  • Keep / rewrite / retire decision recorded per article
  • URL and redirect strategy agreed with whoever owns SEO
02 Data Audit Audit the markup, the links and the assets — that is where KB migrations break. 0/6

Objective A content export with markup, internal links and every embedded asset accounted for.

  1. Export content and assess markup fidelity

    Content engineer 2-3 days

    Export articles in the richest format available and inspect what survived: tables, code blocks, callouts, nested lists, anchors and embedded video. Rich formatting is where fidelity is lost, and it is lost quietly.

    HTML-to-Markdown conversion routinely mangles nested lists, tables and code blocks. Inspect the output rather than trusting the converter.

    Data Profiler Profile the Box export for nulls, outliers and type drift
  2. Inventory every internal link and cross-reference

    Content engineer 2-3 days

    Extract all internal links, anchor links and article cross-references. These break by default: the target URL structure differs, so every internal link needs rewriting as part of the load, not afterwards.

    Internal links left pointing at old URLs turn the new knowledge base into a maze of 404s on day one.

  3. Inventory images, attachments and embedded media

    Content engineer 2 days

    List every asset with its URL, size and type, and confirm each still resolves. Assets hosted on the old platform's CDN will 404 the moment you decommission it, so they must be rehosted, not referenced.

    Images referenced from the source platform's CDN break when the old account closes. Download and rehost every asset.

  4. Find and fix broken links and orphans

    Content lead 2-3 days

    Crawl for existing broken internal and external links, and find articles no category links to. Fix them before migrating — a migration is a bad time to discover pre-existing rot.

  5. Check for PII and internal information in public content

    Compliance 1-2 days

    Scan for customer names, internal hostnames, credentials in code samples and screenshots containing real data. Republishing these on a public help centre is a disclosure, and screenshots are the usual culprit.

    PII & Compliance Scanner Find regulated fields before they land in a new system
  6. Normalise metadata

    Content engineer 1-2 days

    Standardise authors, tags, timestamps to UTC, and locale codes. Author mapping needs a decision for people who have left — attribution to a deleted user usually fails the import.

Box → SharePoint specifics

Box Groups
which will need to become SharePoint Groups or Entra ID security groups
Permission audit
Spot-check 10–20 folders across different permission levels. Verify the right users have the right access. Ensure no unintended "Everyone except external users" permissions were applied to sensitive HR or Finance libraries.
External collaborator audit
Verify that all required vendors and partners have redeemed their Entra ID guest invitations and can access their designated content.

Don't move on until

  • Content exported with markup fidelity assessed
  • Every internal link and asset reference inventoried
  • Broken links and missing assets fixed or logged
03 Field Mapping Map structure, metadata, permissions and — above all — URLs. 0/6

Objective A mapping covering article fields, taxonomy, permissions and a complete old-to-new URL map.

  1. Map the article schema

    Content engineer 2 days

    Map title, body, excerpt, author, dates, status, tags, SEO metadata and any custom properties. Confirm which fields SharePoint lets you set on import versus which it computes — computed dates are a common surprise.

    Schema Mapper Opens pre-loaded with the Box → SharePoint field pair
  2. Map the taxonomy and hierarchy

    Content lead 2-3 days

    Map categories, sections and tags to the target structure, resolving any nesting-depth limit explicitly. If you must flatten, decide how the lost level is preserved — usually as a tag or a title prefix.

    JSON to CSV Converter Flatten nested API responses into a reviewable sheet
  3. Map permissions and audience segmentation

    Content lead 2 days

    Map public, logged-in, and role-restricted visibility to SharePoint's model. Verify the mapping deliberately: internal content accidentally published publicly is the highest-severity failure in this whole category.

    Permission mapping errors publish internal documentation to the open web. Verify visibility on every restricted article after load.

  4. Build the complete old-to-new URL map

    SEO / web 2-3 days

    Produce a row per article mapping the old URL to the new one, then confirm exactly where the 301s will be served — SharePoint, a CDN, or your own web layer. Without this artifact the redirect step cannot be executed at all.

  5. Define the markup conversion and link-rewrite rules

    Content engineer 3-5 days

    Specify how each markup construct converts and how internal links are rewritten using the URL map. Write it as a repeatable transform, not manual edits — you will run it more than once.

    Data Format Converter Reshape the export into the format SharePoint's importer expects
  6. Plan localisation and freeze the spec

    Content lead 1-2 days

    Confirm how translated articles link to their source language in SharePoint, then version and sign off the mapping spec.

Don't move on until

  • Article schema and taxonomy mapped
  • Permission and audience model mapped to target equivalents
  • Complete URL map produced and redirect method confirmed
04 Test Migration Pilot the hardest articles, then read them. 0/6

Objective A pilot load whose formatting, links, assets and search all hold up under human review.

  1. Configure SharePoint with the agreed structure

    Content engineer 3-5 days

    Create the category tree, permission groups, locales and branding before loading. Articles loaded before their categories exist land uncategorised and have to be moved by hand.

  2. Pick the most difficult articles as the pilot

    Content lead 0.5 day

    Choose 20-50 articles for difficulty: the longest, the most heavily formatted, ones with tables and code blocks, deep internal linking, many images, embedded video, restricted visibility, and non-Latin scripts. Easy articles prove nothing.

  3. Run the conversion and load with link rewriting

    Content engineer 2-3 days

    Apply the markup conversion, rewrite internal links from the URL map, upload and re-reference assets, then load. Log every conversion warning rather than suppressing it.

  4. Read every pilot article side by side

    Content lead 2-3 days

    Open source and target together and compare rendering. This step is manual on purpose: no automated check catches a table that collapsed into a paragraph or a code block that lost its indentation.

  5. Click every link and load every asset

    Content engineer 1-2 days

    Verify each internal link resolves, each image loads from the new host, each attachment downloads and each embed plays. Assets still served from the old CDN are the defect that surfaces only after decommissioning.

    Migration Validation Tool Diff the pilot batch against source before scaling up
  6. Test search and permissions

    Content lead 1-2 days

    Search for known terms and confirm the right articles rank, then verify every restricted pilot article is invisible to an anonymous browser. Test permissions from a logged-out session, not an admin one.

Don't move on until

  • Complex articles render correctly with formatting intact
  • Every internal link and asset in the pilot resolves
  • Search returns sensible results for the pilot content
05 Cutover Publish, redirect, and keep the search traffic. 0/6

Objective All in-scope content live in SharePoint with redirects serving and search engines informed.

  1. Load the full content set ahead of the switch

    Content engineer 1-2 weeks

    Run the full conversion and load into SharePoint, unpublished or on a staging domain. Content migration differs from data migration here: you can stage the whole thing before anyone sees it.

  2. Publish the runbook with the redirect step first-class

    Project manager 1 day

    Sequence the freeze, final delta, publish, redirect activation, sitemap submission and link updates, with owners for each. Redirect activation is the step with lasting commercial consequences, so it gets explicit ownership.

  3. Freeze editing and migrate the delta

    Content lead 2-4 hours

    Stop editing in Box, then convert and load anything changed since the full load. Announce the freeze to every team that publishes — content teams are used to editing whenever they like.

  4. Publish and verify permissions live

    Content lead 2-4 hours

    Publish the content set, then immediately verify restricted articles are not publicly reachable using an anonymous session. Do this before announcing the new site, not after.

    Verify restricted content from a logged-out browser. An admin session will show you everything and tell you nothing.

    Migration Validation Tool Confirm the final delta landed before you reopen
  5. Activate 301 redirects and submit the sitemap

    SEO / web 2-4 hours

    Turn on the redirects from the URL map, then spot-check a sample of high-traffic old URLs and confirm each returns 301 to the right article. Submit the new sitemap and keep the old one reachable until search engines have recrawled.

    Redirect chains and redirect loops both leak ranking. Verify each redirect resolves in a single hop.

  6. Repoint in-product and support links

    Content lead 1-2 days

    Update help links embedded in your product, in support macros, in email templates and in onboarding material. These are the links your existing customers actually use, and they are easy to forget.

Don't move on until

  • All content loaded, categorised and correctly permissioned
  • 301 redirects live and verified from a sample of old URLs
  • Sitemap submitted and support links repointed
06 Validation Watch traffic, links and search rankings for weeks, not hours. 0/6

Objective Verified content completeness, healthy redirects, and search traffic recovered to baseline.

  1. Reconcile content counts and assets

    Content engineer 1-2 days

    Compare article counts by category and status, plus asset counts, against source. Confirm every article in the keep list is present and every retired one genuinely is not.

    Migration Validation Tool Reconcile Box and SharePoint record-for-record
  2. Crawl the new site for broken links and assets

    Content engineer 1-2 days

    Run a full crawl for 404s, broken images and missing attachments, and fix everything it finds. Repeat the crawl after the fixes rather than assuming they worked.

  3. Verify the redirects at scale

    SEO / web 1-2 days

    Test every mapped old URL for a single-hop 301 to the right destination. Chains and loops both leak ranking and are invisible unless you check the whole map, not a sample.

  4. Monitor organic traffic and rankings for four to eight weeks

    SEO / web 4-8 weeks

    Track organic sessions, impressions and rankings for your top articles against baseline. A dip in the first two weeks is normal; one that has not recovered by week six is a redirect or indexing problem to investigate.

    Do not decommission the old platform until search traffic has recovered — you may still need the old URLs to diagnose a ranking loss.

  5. Verify search, permissions and feedback loops

    Content lead 1-2 days

    Confirm on-site search returns good results for real queries, re-verify restricted content from a logged-out session, and check article feedback and analytics are collecting.

  6. Sign off and decommission on a delay

    Project sponsor 1 day

    Get acceptance against the Discovery criteria, keep Box available read-only until traffic has recovered, take a final export, and only then close the account.

Box → SharePoint specifics

File count reconciliation
Compare total file counts between Box source and SharePoint destination. Account for files skipped due to path length, zero-byte files, or unsupported types.
Box Notes conversion verification
Open a representative sample of converted .docx files. Check formatting, tables, embedded images. Watch for silently dropped annotations and tables of contents.
Link rewriting
Internal documents referencing Box URLs now have broken links. Identify and update the highest-traffic ones. Broken Box URLs circulate in emails, wikis, and Slack for years.
List view threshold
If any document library exceeds 5,000 items, verify that list views are indexed properly.

Don't move on until

  • Article counts reconciled and no broken links remain
  • Redirects returning 301 with no chains or loops
  • Organic traffic recovered to within tolerance of baseline

Field mapping reference

The field-by-field mapping for each object. Use this as the starting point for your mapping spec.

Source Target 4 fields
Box fieldSharePoint fieldNotes
Personal folders (per user) OneDrive for Business Pre-provision OneDrive accounts before migration
Team/department folders SharePoint document libraries (one per team site) Design site architecture first
Archived or cold data Azure Blob Storage or archive site Don't burn SharePoint quota on files no one opens
Project-specific folders SharePoint sites or Teams channels Consider hub site architecture
Role Equivalent 4 fields
Box fieldSharePoint fieldNotes
Owner Site Owner / Full Control Map carefully — Site Owner grants broad admin rights
Editor Edit or Contribute "Edit" includes delete; "Contribute" doesn't
Viewer Read Direct mapping
Uploader Contribute (custom) No direct SharePoint equivalent
Approach Best For 3 fields
Box fieldSharePoint fieldNotes
ClonePartner (Engineer-Led Service) Enterprises (50TB+), complex permissions, compliance, zero downtime Custom conversion pipeline — programmatically validates every file
ShareGate / AvePoint Mid-market DIY with dedicated IT staff Converts to .docx (unverified output)
Basic DIY Tools (Movebot, Cloudiway, CloudM) Simple, flat folder structures Varies (often raw JSON or basic Word docs)

Risk matrix

Per-object risk for this pair. Plan extra validation around anything marked high.

ObjectRiskNotes
Box Shared Links high Not migrated — every internal and external URL breaks
External Collaborator Access high Must be manually re-invited post-migration
File Version History high Migration Manager transfers only the most recent version
Box Tasks high No transfer — must be recreated in Planner or To Do
Box Relay Workflows high Must be rebuilt from scratch in Power Automate
Box Notes medium Converted to .docx but annotations and TOC may be dropped
Box Comments medium Tool-dependent — validate with your exact migration tool
File Permissions medium Internal permissions can be mapped but require redesign
Metadata & Tags medium Requires pre-defined SharePoint site columns to preserve
File Content low Standard files and folder structures migrate cleanly

The hard parts

What makes this specific migration difficult, beyond the mechanics.

Permission Redesign

Box uses folder-level collaboration roles. SharePoint uses site-and-library inheritance with unique permission scopes that are difficult to audit or clean up after the fact.

Box Notes Conversion

Box Notes are a proprietary format incompatible with Microsoft Office. Conversion to .docx drops elements like annotations, file previews, and tables of contents.

Storage Reconciliation

Box offers unlimited storage. SharePoint allocates 1 TB per tenant plus 10 GB per user, requiring aggressive data auditing.

External Collaborators

Migration Manager does not share content with external users by design. Every external collaborator must be manually re-invited.

Path Length Limits

SharePoint enforces a 400-character path limit. Deep Box folder hierarchies with long filenames fail silently during migration.

Tools used in this playbook

All free, all run entirely in your browser — nothing is uploaded.

FAQ

Does the SharePoint Migration Tool (SPMT) support Box as a source?

No. SPMT only supports on-premises SharePoint Server and local file shares. For Box, use Microsoft's Migration Manager (free, in the SharePoint Admin Center) or a third-party tool like ShareGate, AvePoint, Movebot, Cloudiway, or CloudM. For enterprises needing zero-downtime migration with full permission redesign and Box Notes conversion handled end-to-end, ClonePartner offers a managed engineering service that eliminates the tool-selection guesswork entirely.

What happens to Box Notes when migrating to SharePoint?

Box Notes are a proprietary format incompatible with Microsoft Office. Migration Manager and most third-party tools convert them to .docx, but elements like File Preview, Table of Contents, and Annotations may be omitted. Movebot converts to JSON instead of .docx. Always run a pilot batch and verify the output before a full migration.

Do Box sharing permissions transfer to SharePoint automatically?

Internal permissions can be mapped using identity mapping in Migration Manager or third-party tools. External collaborators must be re-invited manually — Migration Manager does not share content with external users by design. Shared links are not migrated and must be recreated.

What Box features do NOT migrate to SharePoint?

Box Shared Links, Tasks, Relay workflows, third-party app integrations, external collaborator access, and file version history (in Migration Manager) do not transfer. Box Comments are tool-dependent — Cloudiway says they don't migrate, while Microsoft FastTrack says they do. Validate with your exact tool.

How long should I keep Box active after migrating to SharePoint?

Keep Box running in read-only mode for a minimum of 30 days after migration — 60 days for large enterprises or regulated industries. Run a final delta sync before canceling to catch any missed files.

Or skip all of this and let us handle it

Book a 30-minute call and we'll scope your migration in a single session.