l0grisk intelligence · english

// analysis

Leaving Microsoft, 1/7: the dependencies a migration uncovers

Illustration for the analysis: Leaving Microsoft, 1/7: the dependencies a migration uncovers

From Schleswig-Holstein to the CNRS, an investigation into the applications, identities and skills a public administration must rebuild to leave Microsoft.

dated revision: October 08, 2026French originalprimary sourcesno tracker

Schleswig-Holstein was removing Microsoft Office. At its roads agency, an application still called Excel. Five additional licences had to be bought.

The episode occupies a few lines in the Schleswig-Holstein government’s reply to its parliament, dated 5 January 2026. The application was SIB-Bauwerke; the agency was the LBV. Its direct call to Excel came to light during the migration. It is a small detail with a large bearing on digital sovereignty: replacing an office suite also means dealing with software that staff open to do an entirely different job. [1]

This series begins with a practical question: what must a public administration be able to do elsewhere before it can leave Microsoft? Migrations already under way offer the first answers, through both their achievements and their setbacks. Public records from Schleswig-Holstein, the experience reported by France’s CNRS research organisation and Microsoft’s own technical guides let us examine the work in detail.

This opening instalment looks at the capacity to leave. Later parts will trace contracts, licensing, business applications and costs, then compare migrations and the ways organisations can preserve their choices. The common concern is keeping a public service running when its supplier, commercial terms or political environment changes.

Five licences at the edge of a large migration

Schleswig-Holstein has made a substantial change. On 4 December 2025, its government reported that almost 80% of administrative workstations, excluding the tax administration, had moved to LibreOffice. It also reported that almost 44,000 of its mailboxes had moved to Open-Xchange. These are the regional government’s figures, tied to a specific date and scope. [2]

The parliamentary reply exposes some of the connections that a progress announcement can miss. Alongside the roads agency case, it describes reinstalls of Access and Word to meet needs identified during the transition. The government explains that it asked ministries for information to answer the parliamentary questions; it did not maintain a continuously updated central register of these reinstalls. The document records identified cases while making that coverage limit explicit. [1]

A member of staff sees a form, a table or an export button. Behind it, an application may expect a particular Office component. That connection is where the dependency sits. Another suite may be able to open the finished file while the software producing it still needs adaptation. SIB-Bauwerke’s call to Excel makes the distinction tangible.

On 7 July 2026, the state announced a further stage: the gradual replacement of more than a hundred business applications built on Access. Some were due to be replaced during 2026. The announcement also presented the programme as preparation for a future introduction of Linux on workstations. Office, the business applications and the operating system each have a migration timetable of their own. [3]

This suggests a more useful measure of progress than the number of programs uninstalled: which tasks can now be completed from beginning to end in the new environment?

The relationships that travel with a document

Consider a hypothetical public service processing an application for financial assistance. Its case file includes supporting documents, access permissions, an assigned officer, an approval and a notification. Copying the documents moves the information. Rebuilding the procedure requires the right people to be connected to the right actions.

Microsoft’s documentation makes this distinction visible within its own ecosystem. Its guide to moving SharePoint sites between customer environments, known as tenants, requires users and groups to be prepared at the destination. Permissions can be preserved if the identities have been correctly mapped. Applications must be republished and sometimes modified; Power Apps and automated tasks must be recreated and reconnected. [4]

A file has a destination. Its use depends on several other things: an account, an authorised group, an application and the steps that application triggers. Portability means, in this context, the ability to transfer data to another environment. Reversibility, as French public technology policy uses the term, extends the question to taking over the service itself, with the resources needed to operate it.

The connections behind a working serviceEducational SharePoint-to-SharePoint migration diagram. Content is transferred, identities mapped, access is retained if identities are mapped, apps republished and automation recreated and reconnected at the destination. Solid arrows show content; dashed arrows show relationships to address. This Microsoft-to-Microsoft scope does not measure a move to another provider.l0g / DEPENDENCIESThe connections behind a working serviceSharePoint → SharePoint: content and the service relationships to rebuild.SourceDestinationFilesAccountsApps and automationFilesAccountsApps and automationMigrate contentMap identitiesAccess retainedif identitiesare mappedRepublish apps,recreate flows,then reconnect themContent transferRelationships to map or restoreSource: Microsoft Learn · SharePoint across Microsoft tenants · 7 May 2026.
The connections behind a working serviceEducational SharePoint-to-SharePoint migration diagram. Content is transferred, identities mapped, access is retained if identities are mapped, apps republished and automation recreated and reconnected at the destination. Solid arrows show content; dashed arrows show relationships to address. This Microsoft-to-Microsoft scope does not measure a move to another provider.l0g / DEPENDENCIESThe connectionsbehind a working serviceSharePoint → SharePoint: contentand the service relationships to rebuild.SourceDestinationFilesAccountsApps andautomationFilesAccountsApps andautomationMigratecontentMapidentitiesAccess retainedif identitiesare mappedRepublish apps,recreate flows,then reconnect themContent transferRelationships to map or restoreScope: migration between Microsoftenvironments. Steps depend on the tool.Source: Microsoft Learn, 7 May 2026.
FIG. 01 A migration must reconnect content, identities, permissions and the applications that use them.[4]
How to read this diagram

A functional diagram based on Microsoft’s guide to moving SharePoint sites between tenants. It describes a transfer between two Microsoft environments: permissions can be preserved when identities are mapped correctly, while applications and automations require further work. The arrows show functional dependencies, without assigning any costs. This case illustrates the work involved beyond copying files; it provides no cost estimate for moving to another vendor. [4]

The documentation also provides evidence in Microsoft’s favour. The company supplies migration mechanisms, link redirection and conditional preservation of access. The remaining work depends on each use case. This example concerns a move within Microsoft; leaving for other software requires a separate assessment of compatibility with that software. [4]

For a public buyer, the distinction changes how a contract should be prepared. A buyer can specify an export format, then check whether an exported case file retains the information needed to continue processing it. Interoperability, the ability of different systems to work together, can then be assessed through a completed action: opening a record, understanding it, authorising access and handling the case.

The workstations that remain have their own timetable

Schleswig-Holstein has published a schedule for the exceptions that still require Microsoft Office, excluding the tax administration. An October 2025 count recorded 5,042 exceptions. Ministries expected 2,944 to remain at the end of 2028, followed by 101 at the end of 2029. The numbers appear in the January 2026 parliamentary reply. The future values are ministry forecasts. [1]

Exceptions have a timetableSchleswig-Holstein workstations still requiring Microsoft Office, excluding the tax administration. Reported position: 5,042 in October 2025. Forecasts published on 5 January 2026: 4,107 at end-2026, 3,320 at end-2027, 2,944 at end-2028 and 101 at end-2029. All connections to targets are dashed. Vertical axis runs from zero to six thousand. No assessment of 2026 delivery is shown.l0g / THE REMAINING JOURNEYExceptions have a timetableWorkstations still requiring Microsoft Office. Schleswig-Holstein · tax administration excludedFORECASTS PUBLISHED ON 5 JANUARY 202602 0004 0006 0005,0422025Oct4,1072026end3,3202027end2,9442028end1012029endReported position in October 2025Forecasts published in January 2026Source: Landtag, reply 20/3911 of 5 January 2026, question 4. Vertical axis starts at zero.No 2026 delivery assessment is shown.
Exceptions have a timetableSchleswig-Holstein workstations still requiring Microsoft Office, excluding the tax administration. Reported position: 5,042 in October 2025. Forecasts published on 5 January 2026: 4,107 at end-2026, 3,320 at end-2027, 2,944 at end-2028 and 101 at end-2029. All connections to targets are dashed. Vertical axis runs from zero to six thousand. No assessment of 2026 delivery is shown.l0g / THE REMAINING JOURNEYExceptions havea timetableWorkstations still requiring Microsoft Office.Schleswig-Holstein · tax administration excludedForecasts published5 January 202602 0004 0006 0005,0422025Oct4,1072026end3,3202027end2,9442028end1012029endReported position in October 2025Forecasts published in January 2026Source: Landtag, reply 20/3911, question 4.5 January 2026. Vertical axis starts at zero.No 2026 delivery assessment is shown.
FIG. 02 Microsoft Office exceptions: an October 2025 count, followed by the path ministries forecast through the end of 2029.[1]
Scope and method

Source: parliamentary reply 20/3911, question 4, page 5, dated 5 January 2026. The tax administration is excluded. Values: 5,042 exceptions counted in October 2025; forecasts of 4,107, 3,320, 2,944 and 101 at the ends of 2026, 2027, 2028 and 2029 respectively. The vertical scale starts at zero. The chart separates the count from the forecasts; future milestones are not presented as outcomes achieved by 8 October 2026. [1]

The chart reveals a second phase of migration. After deployment across most of the organisation comes the adaptation of applications needed for a remaining set of tasks. The source explicitly connects its forecasts to when those applications will allow Office to be uninstalled. Whether the timetable will be met, and how difficult each case will prove, remain open questions. [1]

A practical implication follows: progress needs to be assessed from two directions. One tracks the workstations and users that have changed tools. The other tracks the functions still attached to the old environment. A single application can sustain a need for support, specialist skills or licences long after most staff have moved. The published schedule makes this period of coexistence visible in a way that a headline migration rate cannot.

One sorted column, 790 accounts affected

The German migration provides another, more sensitive lesson. Overnight on 6–7 August 2025, an operation in the second phase of the email migration assigned messages more than seven days old to the wrong accounts. The final report by Dataport, the public IT provider responsible for the work, records 790 affected accounts. It was published as an annex to a parliamentary reply on 7 October 2025. [5]

The report describes a preparation error. A list paired account names with directory identifiers. When several batches were combined, the column containing the names was sorted without the associated columns moving with it. The rows still appeared complete, but the pairings had changed. The second-person check required by the procedure had not been performed. [5]

The mistake is easy to picture. Sort the names in an address book while leaving the telephone numbers in place, and each row can become misleading. In an email migration, that relationship determines which account receives the messages.

A broken pairing, a different mailboxTeaching example with fictional data: C maps to ID 03, A to ID 01 and B to ID 02. Sorting only the address column yields A with ID 03, B with ID 01 and C with ID 02. Comparing against the original pairs and performing a second check verifies A–01, B–02 and C–03. Separately, Dataport’s report of 15 August 2025 documents 790 accounts affected by a mapping error during the 6–7 August migration. The three fictional rows do not reproduce those accounts.l0g / MIGRATION INTEGRITYA broken pairing, a different mailboxTeaching example, fictional data. Address and identifier must remain paired.01 · Original pairsAddressIdentifierMailbox CID 03Mailbox AID 01Mailbox BID 0202 · One column sortedAddressIdentifierMailbox AID 03Mailbox BID 01Mailbox CID 0203 · Verified pairsAddressIdentifierMailbox AID 01Mailbox BID 02Mailbox CID 03Order does not matter.Each address retainsits own identifier.Identifiers did not movewith their addresses.A is now paired with ID 03.Compare with the original file.Have a second operatorverify the pairs.DOCUMENTED INCIDENT · 6–7 AUGUST 2025790accounts affectedaccording to DataportThe report attributes the incident to a partial sort and a missing four-eyes check.Source: Dataport report of 15 August 2025, annexed to Landtag reply 20/3628.
A broken pairing, a different mailboxTeaching example with fictional data: C maps to ID 03, A to ID 01 and B to ID 02. Sorting only the address column yields A with ID 03, B with ID 01 and C with ID 02. Comparing against the original pairs and performing a second check verifies A–01, B–02 and C–03. Separately, Dataport’s report of 15 August 2025 documents 790 accounts affected by a mapping error during the 6–7 August migration. The three fictional rows do not reproduce those accounts.l0g / MIGRATION INTEGRITYA broken pairing,a different mailboxTeaching example, fictional data.Address and identifier must remain paired.01 · Original pairsAddressIdentifierMailbox CID 03Mailbox AID 01Mailbox BID 0202 · One column sortedAddressIdentifierMailbox AID 03Mailbox BID 01Mailbox CID 0203 · Verified pairsAddressIdentifierMailbox AID 01Mailbox BID 02Mailbox CID 03A was linked to C’s identifier.Compare pairs with the original file.Have a second operatorverify the mapping.DOCUMENTED INCIDENT · 6–7 AUGUST 2025790accounts affectedaccording to DataportThe report attributes the incident to a partialsort and a missing four-eyes check.Source: Dataport report, 15 August 2025,annexed to Landtag reply 20/3628.
FIG. 03 A migration depends on preserving the relationship between an account and its identifier. Sorting a single column can break that relationship.[5]
An explanatory example, separate from the incident data

The rows in this diagram are fictional and serve only to illustrate the error Dataport describes. The figure of 790 accounts comes from its final report dated 15 August 2025, annexed to parliamentary reply 20/3628. Sections 4 and 6 describe the cause and corrective measures, including automated matching checks and checks by more than one person. The document concerns the migration of old emails; it does not establish how many messages were actually read by unauthorised people. [5]

Dataport says it blocked the affected mailboxes, suspended subsequent migrations and restored the previous Exchange operation. The report then describes additional checks on the mappings and stronger human oversight. It attributes the incident to an error in migration preparation. The documented explanation concerns that operation, its controls and the way the work was organised. [5]

For a public administration, the freedom to change supplier therefore includes a specific competence: moving the relationships between people, data and permissions correctly. This connects with the questions examined in our investigation of digital identity under contract. Safeguards become effective through the people and operations that implement them.

In our assessment, a reversibility exercise should follow a case through to processing at the destination, verify access and test a return to the previous system. That temporary return is part of controlling the transition. It gives teams time to correct a fault without extending an interruption.

At the CNRS, email is the first stage of a wider change

The CNRS offers another perspective. In an account published on 7 July 2026, its IT department says it left Exchange as its server solution in April, moving to Zimbra operated by Renater. It acknowledges a worse user experience during the transition, difficulties with the Outlook client and stability problems that it said had since been resolved. The account distinguishes the replaced server from the software on the user’s workstation. [6]

The next horizon is broader. The CNRS plans to leave SharePoint by the end of 2029, a change involving 2,000 collaboration spaces and business applications. Its IT department stresses the variety of functions that must be carried over and is considering several tools. The schedule and assessment come from the organisation itself. Their value lies in showing how a sovereignty decision becomes a set of architectural choices and a reconstruction effort. [6]

Email carries exchanges. A collaboration space may also organise documents, access and procedures. Replacing a server is an identifiable step; taking over a collection of uses requires decisions about which functions to retain, simplify or distribute across several tools.

Those choices involve people. Preserving familiar ways of working can ease a transition. Redesigning a procedure may reduce future dependencies while requiring staff to learn something new today. The CNRS account makes that cost tangible: staff also bear the disruption of the changeover. [6]

Sovereignty also rests on the contract and the team

Data location, applicable law, the ability to operate a service and the ability to change its software answer different questions. France’s SecNumCloud qualification assesses a defined service against security requirements, including protection from extraterritorial laws. ANSSI, the French cybersecurity agency, explains that an application hosted on qualified infrastructure does not automatically inherit the qualification. The exact service boundary matters. [11]

Microsoft has made European continuity commitments of its own. Annex D of its Data Protection Addendum, checked in the May 2026 version, commits it to challenging suspension orders affecting the government customers covered by its terms. The contract provides for legal proceedings and, where necessary, applications for interim or final relief to maintain service during litigation. Its scope includes national, federal and regional governments in the listed countries, as well as the European Commission. [10]

The company has also announced continuity arrangements with European partners. The contractual duty to pursue legal remedies, whose outcome rests with the courts, is distinct from the announced technical arrangements for continued operation. We have observed no exercise that would allow us to assess these arrangements under an imposed suspension, and they do not establish an automatic technical handover. [9] [10]

These arrangements aim to keep a service based on Microsoft technology running. An exit strategy prepares the transfer of its functions to another environment. Both approaches can serve the same organisation: maintaining today’s service while retaining an alternative.

Regulatory proceedings also need to be followed through to their outcome. In March 2024, the European Data Protection Supervisor found infringements in the European Commission’s use of Microsoft 365. In July 2025, it announced that the Commission had remedied the infringements concerned and closed the proceedings. This case addresses a specific use and specific obligations. Any account of the original finding needs to include the subsequent outcome. [14] [15]

The economic evidence requires the same precision. In its UK cloud investigation, the Competition and Markets Authority concluded in July 2025 that certain Microsoft licensing practices weakened AWS’s and Google’s ability to compete with Azure for the software concerned. That finding has a defined market and scope. In March 2026, the authority noted steps taken or announced on egress fees and interoperability, with their effectiveness in improving customer choice still to be assessed. It had identified no material progress on licensing. Its investigation, opened in May 2026, into a possible strategic market status designation for Microsoft’s business software ecosystem remains ongoing as of 8 October. [12] [16] [13]

These issues meet at the negotiating table. An administration with a usable export, a replacement operator and a trained team has more options when a contract comes up for renewal. That is an assessment of its room to act, separate from any calculation of savings. The documents examined do not allow that room to be quantified across governments as a whole.

Plan the departure when the service arrives

France’s “cloud at the centre” policy already sets out this requirement. A circular dated 31 May 2023 requires projects to plan the human, technical and financial resources for reversibility from the outset. It also calls for avoiding dependencies that significantly hinder portability and for maintaining a range of suppliers, including in office software and collaboration. The means of leaving become part of service design and funding. [7]

The EU Data Act adds obligations intended to make it easier to switch providers of data processing services. Applicable since 12 September 2025, it provides, among other things, for the removal of switching charges for covered services from 12 January 2027. The rules vary with the service: functional equivalence provisions for certain infrastructure services do not impose a general duty to reproduce every function of a software suite. Training people or rewriting an application remains work that somebody must fund. [8]

Free and open-source software gives rights to study, modify and redistribute code under the terms of its licence. Turning those rights into operational autonomy requires people who can maintain and run the system. Schleswig-Holstein’s account of service contracts for its new tools illustrates this too. Dependence may move towards services whose providers are easier to replace; the replacement still has to be organised. [1]

The cases examined suggest a demanding but understandable test. An administration gains autonomy when it can take over a function, preserve the right access and maintain the service with resources it controls. Testing can begin on a small scale, with a representative procedure, before committing an entire organisation.

In Schleswig-Holstein, one call to Excel was enough to bring five licences back into the programme. At the CNRS, departure from the email server leaves several years of work ahead on SharePoint. Between those two scales lies the practical work of sovereignty: finding out what holds a service together, then gaining the ability to put it together elsewhere.

Continue with part two: how one contract shapes the next.

Sources and limits of this investigation

This instalment draws on public documents consulted on 8 October 2026: parliamentary replies and an incident report, statements by the organisations concerned, technical documentation, legislation and decisions by the relevant authorities. Migration figures are attributed to the organisations reporting them. Forecasts retain their publication dates. We have not audited the systems, interviewed the teams or run a migration test; this is a documentary investigation. The three infographics distinguish an explanatory mechanism, recorded data, a forecast timetable and a fictional example. The cover illustration is a conceptual creation.

  1. Schleswig-Holstein Parliament, reply 20/3911, 5 January 2026. Question 4, p. 5: Office exceptions and forecasts excluding the tax administration; question 5, p. 6: reinstalls, SIB-Bauwerke and the information-gathering method; question 6: contracts for the new services.
  2. Schleswig-Holstein government, LibreOffice and email migration update, 4 December 2025. Statements by the regional government; workstation figures exclude the tax administration.
  3. Schleswig-Holstein government, replacement of Access applications, 7 July 2026. Announced programme and its relationship to a future introduction of Linux.
  4. Microsoft Learn, Cross-tenant SharePoint migration, updated 7 May 2026. Sections on destination users and groups, permissions, applications and Power Apps/Power Automate. Migration within Microsoft 365.
  5. Schleswig-Holstein Parliament, reply 20/3628 and Dataport final report, 7 October 2025; report dated 15 August 2025. Annex, sections 1 and 4: scope and cause; sections 3, 5 and 6: incident response, restoration and corrective measures.
  6. CNRS, Le CNRS accélère sa transition vers la souveraineté numérique, 7 July 2026. The IT department’s account of Exchange/Zimbra and the SharePoint programme; statements by the organisation.
  7. French Prime Minister, circular 6404/SG, “cloud at the centre”, 31 May 2023. Rules R4, R10 and R15: resources for reversibility, dependencies and supplier diversity.
  8. Regulation (EU) 2023/2854, Data Act. Chapter VI, particularly Articles 23, 25 and 29–31, and Article 50 on application. Service-specific obligations, the timetable for switching charges, limitations and exemptions. Link to the French text.
  9. Microsoft, European digital commitments, 30 April 2025. The supplier’s announced commitments on continuity and European partners.
  10. Microsoft Products and Services Data Protection Addendum, May 2026, Annex D. Contractual commitment concerning legal challenges to suspension orders affecting the national, federal or regional governments covered by its terms; scope and legal remedies. Word document.
  11. ANSSI, SecNumCloud qualification FAQ, consulted 8 October 2026. Scope of qualification and protection from extraterritorial laws.
  12. CMA, Cloud services market investigation, final report, 31 July 2025. Executive summary, particularly paragraphs 23–36: switching barriers and Microsoft licensing; the UK cloud services market.
  13. CMA, Microsoft’s business software ecosystem investigation, opened 14 May 2026; status consulted 8 October 2026. Examination of a potential strategic market status designation; proceedings ongoing.
  14. EDPS, decision on the European Commission’s use of Microsoft 365, 8 March 2024, case 2021-0518. Read alongside the outcome of the proceedings in source 15.
  15. EDPS, announcement of compliance and closure, 28 July 2025. Remedial measures addressing the infringements covered by these proceedings.
  16. CMA, Actions on cloud and business software through the UK digital markets competition regime, 31 March 2026. Paragraphs 33, 34 and 36: steps taken or announced on egress fees and interoperability, their effectiveness still to be assessed, and the assessment of licensing.

This analysis is not investment advice.

// cite this analysis

l0g, “Leaving Microsoft, 1/7: the dependencies a migration uncovers”, l0g.fr, published October 08, 2026, updated October 08, 2026, https://l0g.fr/en/analysis/leaving-microsoft-1-government-dependencies/


$ cd ../analysis