OMDT supports migrating Microsoft Teams using a least-privilege SharePoint permission model based on the SharePoint – Selected Sites consent application (Sites.Selected). Sites.Selected can be applied independently on the source tenant, the target tenant, or both. Tenants that do not use Sites.Selected continue to operate under the standard ODM SharePoint permission model.
On any tenant where Sites.Selected is used, the Selected Sites application is granted explicit per-site permission (role fullcontrol) on the Team's primary SharePoint site and on the dedicated sites associated with each private and shared channel. With this configuration in place, the full migration lifecycle, discovery, provisioning, and content migration, completes successfully.
Note Current Teams ODM enterprise applications do not include the broad Sites.ReadWrite.All or Sites.Read.All SharePoint permissions by default. As a result, no permission removal is required on the ODM enterprise applications themselves — the Sites.Selected configuration is purely additive on whichever side it is applied.
Important Sites.Selected only governs the SharePoint permission scope. The standard Teams Entra application registrations, On Demand Teams Minimal, Teams Full, or Teams Application Only — are still required and must remain consented on both tenants. Sites.Selected does not replace or reduce the Teams-side app registration requirements.
Supported Deployment Scenarios
Both tenants Source: Sites.Selected — Target: Sites.Selected
Both tenants use the scoped model. Per-site fullcontrol grants are required on both source and target sites. Target sites must be pre-provisioned before being granted permission.
Source scoped Source: Sites.Selected — Target: Standard ODM permissions
Only the source tenant uses the scoped model. Per-site fullcontrol grants are required on each source site. The target tenant operates under the default ODM SharePoint permissions; no per-site grants and no pre-provisioning are required on the target.
Target scoped Source: Standard ODM permissions — Target: Sites.Selected
Only the target tenant uses the scoped model. Per-site fullcontrol grants are required on each target site, and target sites must be pre-provisioned before being granted permission. The source tenant operates under the default ODM SharePoint permissions; no per-site grants are required on the source.
Conditions Required (Per Side Where Sites.Selected Is Used)
–
The SharePoint – Selected Sites consent application is granted on each tenant where Sites.Selected is used.
–
On each tenant where Sites.Selected is used, the Selected Sites application is granted explicit per-site permissions using the fullcontrol role on, for each Team to be migrated:
◦
The Team's primary SharePoint site (the site backing the Team and its standard channels).
◦
The dedicated SharePoint site for each private channel in the Team.
◦
The dedicated SharePoint site for each shared channel in the Team.
–
When the target tenant uses Sites.Selected, the target sites must be pre-provisioned before the migration begins and then granted permission (as required by KB 4378526). Pre-provisioning is not required on the source side.
Migration Lifecycle Under the Scoped Model
Discovery
The Team, its channels, members, and backing site content are enumerated correctly using the source-side permissions in effect (scoped or standard).
Provisioning
The Team and its channel structure are created on (or linked to) the target tenant using the target-side permissions in effect (scoped or standard).
Migration
Channel messages, files, tabs, and associated site content are transferred from source to target through whichever permission model is in effect on each side.