How it works · What is migrated · From inventory to cutover · Reports · Quick start · Administrator guide
Important
Files downloaded from the Internet may be blocked by Windows and fail to run. Before using this project, unblock every file in the downloaded folder:
Get-ChildItem "C:\Chemin\Du\Dossier" -Recurse -File -Force | Unblock-FileReplace the example path with the folder where you downloaded or extracted this project.
The Install-Module commands in this documentation use -Force, so they also update or reinstall a module that is already installed. If an older version still conflicts, close every PowerShell window, open a new one (as administrator for -Scope AllUsers), run Uninstall-Module <ModuleName> -AllVersions -Force, then run the Install-Module command again.
Sharing Free/Busy, MailTips and calendars with another Microsoft 365 organization through an organization relationship or a sharing policy relies on Exchange Web Services, which is being retired in Exchange Online. Microsoft replaces these objects with the Microsoft 365 cross-tenant access policy (X-TAP) and documents the migration (Migrate to Microsoft 365 Cross-Tenant Access Policy). In a real tenant the hard part is not the commands, it is the inventory — which relationships belong to the Exchange hybrid, which partner hides behind which domain, which sharing policy applies to which mailboxes — and a written trace of every decision. This tool does that part, for one tenant, in two phases that different administrators can run.
Collect keeps the initial picture of the tenant in snapshot.json and Inventory.html; Plan and Apply work from it. Apply -Phase Entra creates the security groups and the Microsoft 365 collaboration trust of each partner (Security / Groups Administrator), Apply -Phase Exchange the Free/Busy, MailTips and calendar sharing capabilities (Exchange Administrator) — or both with -Phase All. Every Apply starts with the same comparison as Plan and ends by reading the tenant again: what is in place shows No change. Microsoft Graph v1.0 only.
| Exchange Online | Microsoft 365 X-TAP |
|---|---|
Organization relationship — FreeBusyAccessLevel AvailabilityOnly / LimitedDetails |
crossTenantCalendarAvailabilityBasic / …LimitedDetails, partner policy |
Organization relationship — MailTipsAccessLevel Limited / All |
crossTenantMailTipsLimited / …All, partner policy |
| Scope groups of the relationship | the same groups (Entra object ID) as the scope of the capability |
Sharing policy — <domain>: / *: / Anonymous:CalendarSharingFreeBusy* |
crossTenantCalendarSharingFreeBusy* in the partner / default policy, anonymousCalendarSharingFreeBusy* |
Availability address space (OrgWideFBToken) |
configured by the partner for your tenant ID — listed for coordination |
- One configuration per partner tenant: 25 relationships and 40 domains of 12 tenants give 12 partner policies. When Exchange gives several levels for the same partner and users, the administrator chooses (asked once, recorded).
- Partner tenant IDs are found from the domains and must be confirmed by the partner before any trust is created (
PartnersToConfirm.txt). - Out of scope, never configured, cannot be forced: Exchange hybrid with your own on-premises servers (dedicated Exchange hybrid application) and partners on Exchange Server. They appear in the inventory with the reason.
- Forced by the configuration when needed: a level, a scope (all users, a security group, a dynamic group created by the tool), a partner excluded — or item by item in
Selection.csv.
- One feature at a time:
-Feature FreeBusy, MailTipslimits Plan and Apply to some features — calendar sharing reaches the tenants after Free/Busy and MailTips. - The cutover stays manual and coordinated with each partner: X-TAP is configured but not used until the old objects are disabled on both sides. The reports give the commands, the rollback and the cleanup (
ManualCutover.txt); the guide gives the partner message, the change window, the test matrix and the GO / STOP criteria. - Troubleshooting in the browser: what the developer tools show for Free/Busy, MailTips and calendar sharing — expected or not — from real captures (guide, chapter 11).
Every report is a self-contained HTML file — light and dark themes, search and filters, details on click — next to Selection.csv, PartnersToConfirm.txt, ManualCutover.txt, the CSV of the actions and a daily log.
| Item | Requirement |
|---|---|
| PowerShell | 7.4 or later |
| Modules | Microsoft.Graph.Authentication 2.25+ for every run; ExchangeOnlineManagement 3.9+ for Collect only |
| Collect / Plan | Read only — Exchange role that can read the configuration; Graph Policy.Read.All, CrossTenantInformation.ReadBasic.All, Group.Read.All |
| Phase Entra | Creates the trusts and groups — Security Administrator (+ Groups Administrator) or Global Administrator; no Exchange role. Nothing to do when only Anonymous / * sharing entries are migrated for All users: the summary says why |
| Phase Exchange | Writes the capabilities — Exchange Administrator or Global Administrator |
git clone https://github.com/Nico77600/XTapSharingMigration.git
cd XTapSharingMigration
notepad .\config\XTapSharingMigration.config.psd1 # Tenant.TenantId, Tenant.Organization
.\Invoke-XTapSharingMigration.ps1 # inventory (read-only)
.\Invoke-XTapSharingMigration.ps1 -Mode Plan # what would be configured (read-only)
.\Invoke-XTapSharingMigration.ps1 -Mode Apply -Phase Entra # groups and trusts
.\Invoke-XTapSharingMigration.ps1 -Mode Apply -Phase Exchange # Free/Busy, MailTips, calendar sharing
.\Invoke-XTapSharingMigration.ps1 -Mode Plan -Feature FreeBusy, MailTips # only some featuresTwo administrators — each one runs its own phase, from the same Collect folder and the same configuration (copied with all its files, or on a shared copy of the tool):
$run = '.\output\contoso.onmicrosoft.com\2026-10-01_101500_Collect'
.\Invoke-XTapSharingMigration.ps1 -Mode Apply -Phase Entra -SnapshotPath $run -UserPrincipalName entra-admin@contoso.com
.\Invoke-XTapSharingMigration.ps1 -Mode Apply -Phase Exchange -SnapshotPath $run -UserPrincipalName exo-admin@contoso.comWhat to hand over, the accounts, the order and what happens if the Exchange phase runs first: guide, chapter 8 — Two administrators.
The zip of each release contains only the files needed to run, with the HTML guide.
The administrator guide covers the principles, what is in scope, the partner tenant ID confirmation, the configuration rules, Selection.csv, the reports, what to do after the script (rollout check, partner contact, change window, cutover, test matrix, browser developer tools, rollback, cleanup), troubleshooting and the internals:
- docs/XTapSharingMigration-Guide.md
docs/XTapSharingMigration-Guide.html— the same guide as a single HTML file (download it and open it locally)
Invoke-Pester -Path .\tests # Pester 5+, simulated tenant, no connection to Microsoft 365
.\tests\New-DemoReports.ps1 # the three HTML reports from the simulated tenanttools\Build-Documentation.ps1 rebuilds the HTML guide; tools\New-ReadmeImages.ps1 renders the graphics of this page from the cards and flows of the guide, in a light and a dark version.
Personal project, provided as is. It is not an official Microsoft product and is not supported by Microsoft. Test it in your environment before production use, and coordinate every cutover with the partner organizations.



