Digital sovereignty and digital autonomy are often discussed in rather abstract terms. We talk about reducing dependence on Big Tech, keeping European data in Europe, choosing open-source technology and creating alternatives to the large American cloud platforms. But eventually, every discussion about digital autonomy runs into a very practical question: how do you actually move away from an environment such as Microsoft 365?
That question is much more complicated than simply installing Nextcloud, copying a few folders and cancelling a number of Microsoft licences. Microsoft 365 has become deeply embedded in the daily operations of many organisations. Documents, e-mail, calendars, identities, permissions and collaboration processes are interconnected in ways that are not always immediately visible.

That is why I recently spoke with Frank Dengler, director of German migration specialist Audriga. I wanted to talk to him because of his extensive practical experience with migrations between e-mail, groupware and cloud storage environments. In particular, Audriga has worked extensively on the practical challenges involved in moving organisations from Microsoft 365 towards more open environments based on technologies such as Nextcloud.
The resulting conversation, originally published by Business Meets IT, made one thing particularly clear: migrating away from Microsoft is certainly possible, but the technology itself is rarely the biggest challenge.
First understand what you already have
One of Dengler’s most important observations is that organisations should not start a migration by looking for migration tools. That may sound slightly counterintuitive. After all, when organisations start thinking about moving away from Microsoft 365, some of the first questions are usually technical. How do we migrate Exchange mailboxes? How do we copy SharePoint libraries? Which tool can move OneDrive files into Nextcloud? Those questions matter, but they come later.
The first question should be much simpler: what are we actually using? Microsoft 365 environments tend to grow organically. A SharePoint site created years ago may have become an important repository for a department. A shared mailbox may quietly function as the central workflow for customer enquiries. Teams may provide the user interface, while the actual documents are stored somewhere in SharePoint. Calendars, address books, distribution lists and access rights may have accumulated over many years.
The organisation therefore needs to map those dependencies before moving anything. In other words, migration starts with inventory rather than technology. Which users exist? Which groups? Which SharePoint sites are still active? Where are business-critical files stored? Which mailboxes are personal and which are shared or functional? Which calendars are actually being used? And which permissions have become essential to everyday processes?
Only after answering those questions can an organisation decide what needs to be migrated, redesigned, cleaned up or perhaps simply left behind.
Files are never just files
This is particularly important when migrating documents. At first sight, moving files from OneDrive or SharePoint to Nextcloud sounds relatively straightforward. But Dengler points out that documents always have context. Who owns them? Who is allowed to open them? Which folder structure is relevant? Is version history important? Are there external links? Are particular permissions attached to individual folders or documents?
SharePoint makes this particularly interesting because access rights can exist at several levels: sites, libraries, folders and even individual files. Documents opened through Teams may actually reside in SharePoint in the background. Simply copying the files therefore does not necessarily recreate the way people work. A migration can consequently be an excellent opportunity to clean things up.
Old documents, abandoned accounts, duplicate files and forgotten shared folders do not necessarily have to follow the organisation into its new environment. Moving to another platform can force an organisation to reconsider which information still has value, who owns it and who genuinely needs access to it. That is an interesting aspect of digital autonomy that often receives too little attention. It is not only about where information is stored. It is also about understanding and governing that information.
Avoid the big bang
For small and relatively simple organisations, migrating everything during one weekend may sometimes be feasible. For larger organisations, Dengler generally favours a phased migration using a period of coexistence. Microsoft 365 and the new open environment temporarily operate alongside each other. Departments, teams or particular data domains are then moved in successive waves.
There is an obvious advantage to this approach: organisations can learn. The first migration wave will almost certainly uncover things that were missed during preparation. Those lessons can then be applied to the next department or user group. Problems remain relatively contained instead of suddenly affecting the entire organisation.
But coexistence should remain temporary. If Microsoft 365 and Nextcloud continue running indefinitely without a clear plan, the organisation risks creating yet another layer of complexity. Users may no longer know which environment contains the authoritative version of a document or which system they should use for a particular task. A phased migration therefore needs an endpoint.
Identity comes first
Another lesson from Dengler’s experience is that identity should be treated as part of the foundation. Before documents, calendars or mailboxes can be moved, users and groups need to exist correctly in the new environment. Nextcloud can work with technologies such as LDAP, SAML-based single sign-on, directory synchronisation, Microsoft Entra ID or an existing Active Directory infrastructure.
This also raises a broader strategic question. An organisation may decide to continue using Microsoft Entra ID as its identity provider while moving documents and collaboration services away from Microsoft. There is nothing inherently wrong with that. A migration towards greater autonomy does not require every dependency to disappear on day one.
But organisations should understand which dependencies are temporary and which ones they intend to retain. That distinction is essential. Otherwise, an organisation may believe it has become independent because its documents have moved to Nextcloud while a critical part of its digital workplace still depends completely on another supplier.
E-mail is where things become serious
Documents are often a sensible starting point. E-mail tends to be considerably more sensitive. A personal mailbox can be relatively straightforward to migrate. Real corporate environments, however, contain shared mailboxes, aliases, distribution lists, delegation rules, functional addresses, calendars and meeting-room resources.
During a phased migration, routing becomes particularly important. Some employees may still use Exchange Online while others have already moved to the new mail and groupware environment. The infrastructure then has to know exactly where a message for each individual user should be delivered.
That sounds like a technical detail, but it is one of the areas where careful planning makes phased migration possible. Rather than switching an entire organisation at once, individual departments or groups can be migrated while mail continues to flow correctly.
Calendars deserve similar attention. Recurring meetings, time zones, attendees, shared calendars and meeting rooms can all introduce unexpected problems.
The important question is therefore not merely whether calendar data has technically been transferred. It is whether the calendar still works as a coordination system for the organisation.
Test whether people can work
That brings us to perhaps the most practical lesson from my conversation with Dengler. Testing should not simply confirm that migration software successfully moved a certain number of gigabytes. It should confirm that people can continue doing their jobs.
Early test migrations should therefore use realistic accounts, large mailboxes, complex folder structures, shared calendars and active collaboration environments. Key users from the organisation should participate as well. IT can verify that files exist, permissions have been transferred and systems respond correctly. But only actual users can determine whether their working environment still makes sense.
The ultimate test is remarkably simple: can this department arrive on Monday morning and work normally? If the answer is no, the migration is not finished.
Digital autonomy also requires an exit
Perhaps the most important point is that moving data into Nextcloud is not the end of the process. If Microsoft 365 remains permanently available as an archive, emergency environment or shadow platform, the organisation has not truly removed the dependency.
That does not mean the old environment needs to disappear immediately. There may be legal, technical or operational reasons for keeping certain services running temporarily. But there should be an exit plan.
At some point Microsoft 365 may become read-only. Licences can be terminated. Remaining information may be archived or deleted. Guest accounts can be removed and obsolete shared environments shut down.
Digital autonomy therefore involves something that organisations do not always associate with technology strategy: the ability to leave.
An organisation is much more autonomous when it knows how to move its information, understands its dependencies and can switch suppliers or platforms when circumstances change.
Control matters more than technology
That was also the central message I took away from my conversation with Frank Dengler. Nextcloud and other open-source technologies make alternatives to Microsoft 365 technically possible. But simply installing different software does not automatically create digital autonomy. Governance, identity, ownership, permissions, migration planning, user acceptance and eventually the ability to shut down the old environment matter just as much.
Digital autonomy is therefore not primarily a debate about replacing Microsoft software with open-source software. It is about regaining control. Control over data. Control over identities. Control over infrastructure. Control over suppliers. And, perhaps most importantly, control over the ability to change direction in the future.
The technology to do this already exists. The more difficult question is whether organisations are prepared to understand their current dependencies well enough to actually use that freedom. That, ultimately, is what makes migration an important part of the wider European discussion about digital sovereignty and autonomy.