Microsoft 365How-To & HardeningRetrospectives

How to Migrate or Isolate On-Premises SharePoint Servers

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2025, written in 2026 with the benefit of hindsight.

ToolShell showed the risk of internet-facing on-premises SharePoint Server. Here is how to migrate to SharePoint Online — or isolate servers you must keep.

Option A: Migrate to SharePoint Online

  1. Inventory: sites, libraries, customizations, workflows, integrations and permissions.
  2. Clean up: archive or delete obsolete content before moving it.
  3. Plan customizations: farm solutions and classic workflows don't move as-is; rebuild with SharePoint Framework, Power Automate or alternatives.
  4. Migrate: use the SharePoint Migration Tool or Migration Manager in the SharePoint admin center for file shares and SharePoint Server content.
  5. Fix permissions during migration — don't carry over broad access that will later affect Copilot.
  6. Decommission servers after validation.

Option B: Isolate SharePoint Server you must keep

  • Remove direct internet exposure. Publish internally only, or behind an identity-aware proxy (for example, Entra application proxy) requiring Entra ID sign-in and MFA.
  • Patch immediately for all security updates; subscribe to Microsoft advisories.
  • Enable AMSI integration and run Microsoft Defender Antivirus or Defender for Endpoint.
  • Rotate ASP.NET machine keys after any suspected compromise and after applying relevant updates, then restart IIS.
  • Restrict outbound traffic from SharePoint servers.
  • Monitor for new ASPX files and unusual processes.

After ToolShell specifically

If your servers were internet-facing during the exploitation window:

  1. Apply updates.
  2. Rotate machine keys.
  3. Hunt for web shells and indicators published by Microsoft and CISA.
  4. Consider rebuilding if compromise is confirmed.
migrate sharepoint server to onlineToolShell2025

More on this story