Shared drive migration: preserve effective permissions, not just folders
Inventory effective permissions, resolve group mappings, and verify access after a staged drive migration.

Before moving a shared drive, capture effective access, map source groups and rights to destination roles, and test restricted inheritance with ordinary accounts. Reconcile permission changes separately from file changes at cutover. Similar folder structures do not guarantee equivalent access after migration.
Capture effective permissions
Inventory folders, files, owners, groups, direct grants, and places where inheritance changes. Use supported administrative tools for the actual filesystem and directory. Record effective access for representative identities because a raw access list may omit nested groups or other rules. Identify obsolete users and groups without silently discarding their relevance to historical ownership. Keep a dated manifest alongside the content inventory. Permission discovery can itself expose confidential names and structure, so store the manifest appropriately. Ask business owners to approve intended access rather than assuming every legacy exception is still justified.
Build a translation table
Map source identities and rights to destination roles using verified platform capabilities. Distinguish reading, editing, deleting, sharing, and managing membership; a source write permission may not imply every administrative operation. Note unsupported distinctions and propose an explicit workflow or collection boundary for each one. When groups are consolidated, check whether the change broadens access. Preserve source identifiers in the mapping so exceptions can be audited later. Avoid using an import administrator's broad privileges as evidence that ordinary users will be able to access the right documents after migration.

Keep an exception register for access
Use a row for every permission rule that cannot be translated directly. Record the source path and identifier, intended audience, source effective rights, destination role, and owner approval. The point is to prevent a convenient destination role from quietly broadening what someone can do.
| Source intent | Potential mismatch | Required decision |
|---|---|---|
| Read but no reshare | Destination viewer includes a sharing operation | Verify separate control or approved alternative |
| Restricted child folder | Flattened destination inherits department access | Preserve an independently restricted collection |
| Nested group membership | Import includes only the immediate group | Resolve effective users or supported group mapping |
These are possible translation issues, not claims about a particular destination. Check each against actual supported behavior. Assign an approver who understands the content and the audience, not just the migration tooling.
After activation, investigate a complaint through this register and the user's effective destination access. Recopying a file will not repair a missing identity mapping, and granting a whole department access can hide the symptom while creating a disclosure. Keep correction and verification bounded to the affected rule and collection.
Test a restricted payroll branch
A departmental drive contains general procedures and a payroll subfolder with broken inheritance. Migrate a harmless replica into a test workspace. Ask a department member, payroll specialist, and unrelated employee to search, open, edit, export, and share the relevant documents according to their intended roles. Move a file between the general and restricted areas and observe the destination's inheritance behavior. This example can reveal accidental broadening when folder structures are flattened or destination roles combine several source permissions. Test denied operations directly as well as inspecting which buttons appear in the interface.

Control the final synchronization
During the transition, reconcile content changes and permission changes separately. A final file copy does not necessarily capture a new group membership or revised access exception. Define the source freeze, final mapping export, destination activation, and rollback triggers. Log migration failures against source identifiers and retain a controlled exception queue. Business owners should verify sensitive collections before the new location becomes authoritative. After activation, monitor unexpected denials and grants with safe identifiers. Do not solve an access complaint by temporarily granting everyone broad access without an approved, bounded correction.
Permission sign-off
- Retain the dated content inventory and effective access manifest.
- Approve source to destination identity and permission mappings.
- Test restricted inheritance and direct denied operations with ordinary accounts.
- Reconcile permission changes during the final transition window.
- Assign ownership to unresolved exceptions and post migration access requests.


