Home › Topics › Shadow Sharing › Migration

Migrating Users Off Consumer Tools Gently (Blocking Comes Last)

The sanctioned path exists, the pilot teams have switched without being told to, and the register still has thirty-odd rows of teams who have not. Moving them is the part of the project that most organizations get backwards: they block the consumer domains on a Friday and call it migration. It is not. Migration means moving the data and moving the partners who hold the old links. Then you teach each team the new path in twenty minutes. Only then do you close the old one. Do this in that order, department by department.

This article is the method. It covers the order of operations and the migration window, a fixed period in which one team moves with support. It includes the checklist for moving the data out of a consumer account without losing any of it. It covers the notice that moves the partners and the communications plan. It also covers the staged block that comes last and the departments that need their own handling. It is the fifth article in our Shadow File Sharing series, and it assumes the sanctioned path has passed the parity pilot from the fourth.

The Order of Operations

Five phases, always in this order, because each one makes the next one safe. First, the sanctioned path is proven: pilot teams have switched and the proxy log shows it. Second, the amnesty from the discovery article is extended for the whole migration, so nobody hides a share to avoid being the last one moved. Third, each team gets a migration window, in the tier order from the triage article, highest score first. Fourth, the consumer domains get a warning page for two weeks. Fifth, and only fifth, they get blocked. The diagram shows the sequence.

A horizontal timeline of five phases in order: sanctioned path proven, amnesty extended, migration windows team by team, warning page for two weeks, then block. The block phase is drawn last and marked as the final step.

The order matters because the block is the only irreversible step. A team migrated before the block loses nothing and gains a supported path. A team blocked before migration loses its working process on a Friday afternoon. By Monday it has found another consumer service. That is the Northgate Retail story from the first article and the reason this article exists.

The Migration Window

A migration window is four to six weeks for one team. You run three or four at a time so that forty rows take a quarter rather than a year. Inside the window the shape is always the same. First comes a twenty-minute kickoff where the team sees the new path and gets their accounts confirmed. Next comes a data move done by the team with your help. Then comes a partner notice sent by the team in its own name. At a checkpoint halfway through, you look at the proxy volume together. At the close, the old location is emptied and the team says, in writing, that it is done. The team leads the window. You support it. That distinction is what makes it gentle.

The email that opens a window is the template most readers of this article will steal, so here it is in full. It goes from IT to the team's manager and the register contact. It is written for someone who will read the first four lines and skim the rest.

Subject: Marketing file sharing migration window, YYYY-MM-DD to YYYY-MM-DD

Hello Priya, hello Tom,

Marketing's turn to move from share-example.net to the company sharing page
starts on YYYY-MM-DD and runs for five weeks. Here is the whole plan.

WHAT CHANGES
  - New sends go through the sharing page: [link]. Browser only, nothing
    to install, recipients just open a link. Your accounts already exist.
  - The print supplier and the agency get an upload page of their own so
    they can send proofs back without an account.

WHAT WE DO TOGETHER
  Week 1   Kickoff, 20 minutes, your team meeting. We show the page and
           answer questions. We agree who owns the data move.
  Week 1-2 Move the files out of share-example.net into your team folder.
           Checklist attached; we sit with whoever does it.
  Week 2   You send the partner notice (draft attached) to the printer
           and the agency. Both links work in parallel until week 5.
  Week 3   Checkpoint, 15 minutes. We look at what is still going to the
           old service and fix whatever is causing it.
  Week 5   Close: old folders emptied, old links revoked, you confirm.

WHAT HAPPENS AFTER
  Two weeks after the last team's window, share-example.net shows a
  warning page, and two weeks after that it is blocked. Nobody in
  Marketing will be affected by then, because you will already be done.

WHAT DOES NOT HAPPEN
  Nobody is in trouble for anything found during the move. The amnesty
  from the discovery survey runs until the end of the migration.

Questions any time: [IT contact, phone, chat]

Two details in that email carry most of the weight. "Both links work in parallel until week five" is the sentence that stops the team panicking, because it means no send fails during the move. And "you confirm" at the close puts the finish line in the team's hands. That is where it belongs, since they are the ones who know whether the printer has actually switched.

Moving the Data

Every consumer sharing account that has been used for work holds files the company needs and nobody has listed. Moving them is a checklist job. The checklist has one rule above all others. Nothing is deleted from the old location until the copy in the new one has been counted, sized, and opened. The steps:

  1. Inventory the old account. Most consumer services show a total file count and size somewhere in their settings; write both down. If the account mixes personal and company files, agree with the owner which folders are company data. Only those move.
  2. Export to a staging folder on company storage. Use the service's bulk download or export, which usually produces one or more archive files. Unpack them into a staging folder, for example \\fileserver\migration\marketing-staging, that only you and the owner can see.
  3. Verify the export. Count and size the staging folder and compare with step one. In PowerShell:
    Get-ChildItem -Path .\marketing-staging -Recurse -File | Measure-Object -Property Length -Sum | Select-Object Count, Sum
    Small differences in size are normal, because services store some files in their own format and convert on export. A difference in count is not normal, and means the export was incomplete.
  4. Upload into the sanctioned path. Into the team's folder, keeping the folder structure the team already uses, so nothing has to be relearned. For a large export, use the server's SFTP door and a bulk client rather than the browser, which is what that door is for.
  5. Open a sample. The owner opens ten files, chosen from different folders and different years, and confirms they are the right files and they open. This catches the export that renamed everything or dropped the file extensions.
  6. Keep the staging copy until the window closes. Then delete it, because a forgotten staging folder is a new shadow share with a company address.
  7. Empty the old location and revoke its links. Delete the company folders from the consumer account. Revoke every share link the owner created for work. If the account is a company-registered one, close it; if it is personal, it stays the owner's, with the company data gone.

Two cautions from experience. Consumer exports are careless with file names. They add suffixes for duplicates, replace characters the service did not like, and occasionally lose the extension entirely. So budget time for step five and read our article on safe characters across platforms before you are surprised. And where the data is regulated, generate a manifest with hashes before and after the move. For that manifest, use the method in checksum files and manifests. That is because "we counted the files" satisfies you and "here is the manifest" satisfies the auditor.

Never revoke a link before the partner on the other end has used the new one at least once. Not the printer, not the agency, not the supplier who "only sends twice a year". A revoked link that a partner is still using fails silently on their side and loudly on yours, a fortnight later, when the proofs do not arrive.

Moving the Partner Relationships

The data is the easy half. The hard half is the two hundred suppliers, the printer, and the agency. They have the old link in a bookmark, an email signature, or a procedure document of their own. They will keep using it until it fails. Each partner needs a notice, sent by the team that works with them rather than by IT. A message from a stranger's department is deleted and a message from Priya is read. The notice is four lines and does one thing:

Subject: New way to send us files (please update your bookmark)

From YYYY-MM-DD we are sending and receiving files through our company
sharing page instead of share-example.net.

  To send us files:   [upload page link] - no account needed, just open it.
  To receive from us: you will get a download link by email as before.

The old link keeps working until YYYY-MM-DD, then it will be switched off.
If anything does not work, reply to this email and I will sort it out.

Priya Mehta, Marketing, Meridian Parts

Send it in week two. In week three look at the old location together to see who has not switched yet. They get a phone call, not a second email. For partners who send you files under a contract or a schedule, the notice becomes a short connection guide. Our partner onboarding documentation series shows how to write one that a partner's junior admin can follow without ringing you. Where the partner is a customer rather than a supplier, our article on the customer account lifecycle covers the case where the relationship outlives any one link.

Meridian Parts, for the record, did the data move perfectly and forgot the printer. The marketing coordinator's old anyone-with-the-link folder was emptied and its share revoked at the close of the window, exactly as the checklist said. But the printer had never received a notice. It kept uploading proofs to the address in its bookmark for three weeks. Nobody at Meridian was looking there any more. The folder, loyal to the end, accepted every one of them. The autumn catalog nearly missed the same press slot that had started the whole shadow sharing story a year earlier.

The Communications Plan

Migration fails on communication more often than on technology, and the failure is nearly always the same. The people who needed to hear something heard it from the wrong person, at the wrong time, or not at all. The plan below is the minimum. Every row is an audience, a message, the channel that audience actually reads, and when.

Audience Message Channel When
Helpdesk What is changing, the one-page user guide, the five likely questions and answers Team meeting and a saved ticket macro Before anyone else hears anything
Managers Why, the window schedule, what their team must do and by when, the amnesty Management meeting, ten minutes, plus the schedule by email Two weeks before the first window
All staff The new page exists, it is easier, here is the one-page guide, your team's window is coming One email from the head of IT and an intranet page Day the first window opens
Migrating team The window email above, then the kickoff Email to manager and contact; twenty minutes in their own meeting One week before their window
Partners The partner notice above Email from the team's own contact, never from IT Week two of the window
Everyone The old services show a warning page from date X and stop from date Y; how to request an exception Email plus the warning page itself Two weeks before the warning page

The helpdesk row comes first for a reason I learned the hard way. I once announced a migration to eight hundred people before telling the four people who answer the phone. I spent the following morning apologizing to each of them in turn. The one-page user guide that most rows refer to, and the twenty-minute kickoff format, belong to the teaching side of this problem. Our training and adoption series covers that in full.

Blocking Comes Last, and in Two Stages

When the last window has closed, the consumer domains can finally be closed off, and even then not all at once. Stage one is a warning page. The proxy still allows the service, but the first visit each day shows a page that says the service is being retired. That page links to the sanctioned path and links to an exception request. Two weeks of warning page catches everyone the windows missed. In my experience, that is a small number of people who were on leave, plus one contractor nobody had on the register. Stage two is the block itself, with the same page shown instead of the service.

Blocking has two honest limits, and users should hear both. It works on the company network and the company VPN; it does nothing about a phone on mobile data, and it is not meant to. The purpose of the block is to stop the consumer tool being the easy path from a work machine. It is not to build a wall, and a wall would not hold anyway. The second limit is that some outsiders will keep sending you links from their own consumer tools. Opening a link a customer sent is not shadow sharing. It is receiving a file, and the exception process should say so plainly. Our article on the exceptions process covers how to grant those without reopening the whole door.

Keep the discovery one-liners running after the block, monthly, and expect the top of the list to change. The domain you blocked disappears. If a new sharing domain appears in its place within a month, a team has a need the sanctioned path is not meeting. In that case, the right response is the parity checklist, not another block. That loop is the subject of the final article in the series.

Departments That Need Special Handling

Most teams fit the standard window. A few do not, and it is cheaper to know which in advance than to discover it in week three.

Department Why it is different Handling
Marketing and creative Multi-gigabyte files; agencies with their own tools and habits Longer window; an upload page per agency; test a five-gigabyte send in the kickoff, not after
Sales Mobile; customers send links from whatever they use Kickoff on phones; written rule that opening a customer's link is fine and sending goes through ours
HR, legal, payroll Regulated data; retention rules First windows, hash manifests on the move, privacy officer at the close
Finance Auditors and banks often insist on their own portals Receiving via the auditor's portal is an approved exception; sending goes through ours
Engineering and IT Will script around any block; needs a machine-friendly door Give them the SFTP door and ask them to help; they make excellent pilot users for the second loop
Executives Their assistants do the sending, often from the executive's account Train the assistant; give the assistant their own account with access to the executive's folder

The destination for all of them is the same: a folder per team and an account per person on the sanctioned server. Every upload and download is logged there. A transfer server with per-account folders and activity logging, such as Sysax Multi Server, gives the migrated data an owner and a record on the first day. Those are precisely the two things the migrated data never had in the consumer account.

After the Last Window

The one-minute version: prove the path, extend the amnesty, and run migration windows team by team in tier order. Move the data with a checklist that never deletes before it counts. Move the partners with a notice from someone they know. Communicate in the order helpdesk, managers, everyone, team, partners. Block in two stages only when the windows are done. Gentle is not slow. A quarter for forty rows is typical, and it is a quarter at the end of which the register is empty and nobody has been ambushed.

The register will not stay empty on its own. The final article, Keeping Shadow Sharing From Coming Back, covers the light monitoring, the new-starter path, and the request route that keep it that way. If the migration surfaced needs the path could not meet, go back to the parity checklist before you go anywhere else.

Frequently Asked Questions

What if a team refuses to move?
Find out what they think they will lose, because it is nearly always a specific feature or a specific partner rather than stubbornness. If it is a real parity gap, fix it before their window. If it is a partner, help them write the notice. A team that still refuses after that is a conversation for their manager, who has already been briefed on the schedule.
Should the consumer account be closed or just emptied?
If the company registered it, close it after the window, so it cannot quietly come back. If it is someone's personal account, it is theirs; remove the company folders, revoke the work links, and leave the rest alone. Asking people to delete a personal account is overreach and will be refused, correctly.
How long should a migration window be?
Four to six weeks per team, with several teams in parallel. Shorter than four and the partner notices do not have time to land; longer than six and the team stops paying attention. Marketing and creative teams with agencies usually need the longer end.
Can we block the domains as soon as the last window closes?
Run the warning page for two weeks first. It catches people who were on leave, contractors who were never on the register, and partners still sending to an old link. It does so with a helpful page instead of a broken one. The block after that is uneventful, which is the goal.
A customer keeps sending us links from their own consumer tool. Is that shadow sharing?
No. Receiving a file from a link someone else created is not the same as sending company data through an unsanctioned tool. Your exception process should say so plainly. Open it and save the file into the sanctioned path. If the customer sends often, offer them your upload page so the next one arrives logged.

From the Sysax team: we build secure file transfer software for Windows. Sysax Multi Server is an FTP, FTPS, SFTP, and HTTPS server. Sysax FTP Automation handles scheduled, scripted transfers. Free trials are on the download page.