Box to SharePoint migration services

Box to SharePoint migration services that carry the metadata, permissions, and workflows across with the files

Fixed-fee Box to SharePoint migration services from senior US-based Microsoft engineers. Copying files is the easy part. We map Box collaborator roles onto SharePoint groups, rebuild your custom metadata templates as SharePoint columns, recreate Box Relay workflows in Power Automate, and translate Box Shield classifications into Microsoft Purview labels — so what lands in Microsoft 365 works the way Box did. One written price, typical delivery in 2–4 weeks, 30 days of hypercare included.

  • Fixed-fee scoped projects
  • Senior US-based engineers
  • Typical 2–4 week delivery
  • 30 days of hypercare
Revenue Overview Revenue$4.2M Margin38% Orders12.4k Churn2.1% Monthly performance By segment 64%

Representative dashboard — sample data

What you get

The parts of Box that a file copy leaves behind

Content moves with a supported Microsoft tool. Everything your teams built on top of Box — roles, metadata, workflow, classification, signatures — has to be designed into Microsoft 365 deliberately.

An inventory of every Box account

Each user account and folder is scanned and listed with size, owner, and last activity, so the keep, archive, and leave-behind decisions rest on evidence rather than on whoever shouts loudest in the kickoff call.

Collaborator roles mapped to groups

Box grades access more finely than SharePoint's default read, edit, and full-control levels. Every role is mapped to a destination group before the first pass, then confirmed by the person who owns the folder.

Metadata templates rebuilt as columns

Custom templates become site columns and managed metadata term sets, so contract type, client, and review date stay searchable and filterable instead of surviving only as a folder name somebody has to remember.

Relay workflows rebuilt in Power Automate

Approval and review routes running in Box Relay are inventoried, owners are confirmed, and the ones still earning their keep are rebuilt as Power Automate flows on the new libraries before anyone relies on them.

Shield classifications translated, not dropped

Each Box Shield label is matched to a Microsoft Purview sensitivity label, and you decide what that label enforces — encryption, sharing limits, or visible marking — while there is still time to test it on real documents.

Training and 30-day hypercare

Each team gets a walkthrough of its libraries, sync, and search before handover, then 30 days of included hypercare for the access requests and “where did this go?” questions that follow any move of this size.

How it works

Three steps from Box accounts to governed libraries

  1. 1

    Inventory and design

    A free consultation plus a scan of your Box tenant tells us how much content is live, how much is history, which metadata templates and Relay workflows are still in use, and how far external sharing reaches. You get a written scope, a wave plan, one fixed price, and a cutover date.

  2. 2

    Build the destination and pilot

    Sites, libraries, columns, groups, and sensitivity labels are built to the agreed design, identities are mapped, rebuilt flows are tested, and one volunteer team moves end to end so permissions and habits are proven on real work before anyone else is affected.

  3. 3

    Migrate in waves, then hand over

    Remaining accounts move wave by wave with validation at each step and a final pass that copies only what changed. After cutover we reissue external access, train your teams, hand over documentation, and stay on for 30 days of included hypercare.

What the copy step actually covers

Microsoft supports Box as a source in Migration Manager, and the process it documents is a sensible one: connect to your Box account, scan and assess, assign destinations, map identities, then migrate and monitor. Microsoft's Box migration overview (opens in new tab) is explicit that the identity mapping step — aligning your source domains, users, and groups with their Microsoft 365 equivalents — is what allows file metadata and permissions to arrive intact. The tooling is included with your tenant and it works. What it moves is files, folders, and the access around them.

Everything else that makes Box feel like Box is a platform feature, and platform features do not copy. Relay workflows, custom metadata templates, Shield classifications, and Sign requests have no file to carry them across, so each one is a rebuild on the Microsoft side rather than a line item in a migration report. Microsoft also documents the limits of the copy itself in its Box migration FAQ (opens in new tab): only the most recent version of each file is transferred, external sharing links are not recreated, and content is deliberately not shared with external collaborators. Nothing is deleted from Box — a migration copies rather than moves — which is why the old tenant can stay live through the waves and read-only afterwards.

Where each piece of Box lands

Some of this is mechanical and some of it is judgement. The table below is the working checklist we take into the inventory session, and it is deliberately honest about which rows are a copy and which are a rebuild.

In Box Where it lands in Microsoft 365 Decided before the first pass
Files and folders Document libraries on SharePoint sites for team content; OneDrive for what is genuinely personal Which folders are a live team, which are an archive, and which should not move at all
Box Notes Converted to .docx during migration, with file preview, table of contents, and annotations omitted per Microsoft's conversion note (opens in new tab) Which Notes are living documents worth rebuilding as a proper page or Word file, and which are just history
Collaborator roles SharePoint groups, applied once your domains, users, and groups are mapped to Microsoft 365 identities (opens in new tab) How each Box role translates, since Box grades access more finely than SharePoint's default levels
Custom metadata templates Rebuilt as SharePoint site columns and managed metadata term sets (opens in new tab) Which template fields drive real work, and which were filled in once and never looked at again
Box Relay workflows Rebuilt as Power Automate approval flows (opens in new tab) running on the new libraries Which workflows are still running, who owns them, and which quietly stopped mattering years ago
Box Shield classifications Mapped to Microsoft Purview sensitivity labels (opens in new tab) Which classifications must survive, and whether each label marks, restricts sharing, or encrypts
Box Sign Signed documents copy as ordinary files; new signature requests run on Microsoft's eSignature service (opens in new tab), which is billed pay-as-you-go and also integrates Adobe Acrobat Sign and Docusign Where signature requests will run after cutover, and whether an existing provider stays in the picture
Shared links and external collaborators Not recreated by the migration; access is reissued deliberately in SharePoint after cutover Which links are still in use, who is on the other end, and who no longer needs access at all
File version history Only the most recent version of each file is copied Which files need their history, and how long Box stays read-only as a reference archive
Very large files Supported up to Microsoft's 250 GB per-file migration limit (opens in new tab) Whether raw video, disk images, and backup archives belong in SharePoint at all

External sharing is the row people underestimate

Box earns its keep on outside collaboration, which is exactly what makes the move awkward. Years of shared links and invited collaborators accumulate: a client contact who left in 2023, an agency given editor access for one project, a link posted in an email thread nobody can find. Microsoft's decision not to recreate any of it is the right one, but it means external access has to be rebuilt on purpose. We inventory active links and collaborators before cutover, hand each list to the person who owns the folder, and then reissue only what survives that review — using the controls described in Microsoft's SharePoint external sharing documentation (opens in new tab), set at the tenant and site level rather than left to individual habit.

This is also the moment to fix the sprawl instead of importing it. Group-based access you can audit and reverse is worth more than a faithful reproduction of whatever Box had accumulated, and it is a prerequisite for anything that reads across your content later.

The three phases of the project

Most moves sort into the same three phases. The table shows scope and typical timeline rather than prices, because an honest number requires seeing your account inventory, metadata, and sharing first — the same principle behind how our fixed-fee process works. You get one written price for the whole project instead of an hourly meter that rewards a slow migration.

Phase Scope Typical timeline Fee
Phase 1 — Inventory and design Scan of every Box account and folder; keep, archive, and retire decisions; the target site, library, and column design; the metadata, workflow, and classification map; the identity map; a wave plan and cutover date About 1 week Fixed fee — scoped after your free consultation
Phase 2 — Build and pilot Destination sites, libraries, columns, groups, and sensitivity labels built; rebuilt Power Automate flows tested; one volunteer team migrated end to end; the plan and the user guidance corrected before anyone else moves About 1 week Fixed fee — scoped after your free consultation
Phase 3 — Waves, cutover, hypercare Remaining accounts migrated in waves with validation at each step, a final pass at cutover, external access reissued, per-team training, admin handover, then 30 days of included hypercare 1–2 weeks, plus 30 days of hypercare Fixed fee — scoped after your free consultation

Everything lands in the tenant you own. The sites, libraries, columns, flows, labels, documentation, and admin access are yours throughout, so your team can carry on in-house the moment hypercare ends.

Who this is for

The usual fit is a company of roughly 20 to 500 people already paying for Microsoft 365 while still paying for Box alongside it — often noticed at renewal, or during a security review that asked who outside the company still has access to the shared folders. It is scoped as one fixed-fee project with a stated end date, delivered by senior US-based engineers from our Orange County, CA base and remote across all US states.

Which source you are leaving changes the work more than people expect. If your files sit in Dropbox rather than Box, the destination design is similar but the gaps differ, and our Dropbox to SharePoint migration services cover that path instead. If some content is still on a server, the file server to SharePoint migration playbook covers the inventory and wave planning that applies there. Once the content lands, our SharePoint intranet and document management consulting turns those libraries into a workspace with navigation, metadata, and governance behind it, and the Relay rebuilds usually grow into wider approval workflow automation in Power Automate. Because Microsoft 365 Copilot can only be as safe as the permissions underneath it, teams planning a Copilot rollout generally want this clean-up finished first.

FAQ

Questions about moving off Box

Microsoft's Migration Manager converts Box Notes to .docx, and its documentation states that elements such as file preview, table of contents, and annotations are omitted in that conversion. We list your Notes during inventory so the few that are living documents get rebuilt properly instead of arriving as flattened Word files.

No. Relay is a Box platform feature rather than a file, so nothing in the copy step recreates it. We inventory which Relay workflows are still running, confirm who owns each one, and rebuild the ones that still matter as Power Automate flows against the new SharePoint libraries before cutover.

Custom metadata templates are rebuilt rather than copied. Each one becomes SharePoint site columns, and where the values are a controlled list, a managed metadata term set. We review which fields drive real work and which were filled in once years ago, then rebuild only what you still use.

Not automatically. Shield labels live in Box's own classification system, so each one is mapped to a Microsoft Purview sensitivity label and you decide what that label should enforce: encryption, sharing restrictions, or visible marking alone. Labelling is a design decision agreed before content moves, not a clean-up job afterwards.

Microsoft's documentation is explicit that shared links are not recreated and content is not automatically shared with external collaborators. That is deliberate, so we treat external access as its own task: before cutover we list who is still active outside your company, then reissue access in SharePoint case by case.

Typical delivery is two to four weeks from kickoff, with a pilot group first and everyone else following in waves. The fee reflects how many Box accounts move, how much metadata and workflow needs rebuilding, and how tangled external sharing has become. You approve one written fixed price before anything starts.

Book a free consultation

Get more from the Microsoft tools you already pay for

Tell us what you’re trying to fix — a report, an approval process, an intranet, a Copilot rollout. We scope it as a fixed-fee project, you approve, and a senior engineer delivers in 2–4 weeks.

  • Fixed-fee scope agreed before any work starts
  • Senior, US-based Microsoft engineers — no handoffs
  • Typical 2–4 week delivery
  • 30 days of post-delivery hypercare included

The fastest way to reach us is the form — tell us the task and we’ll reply within one business day.

All fields are required.

We reply within one business day. No newsletters, no drip campaigns.

Book a Free Consultation