A professional monitors email, contacts, and calendar migration from Microsoft 365 to Proton Mail, with security and DNS checks shown.
Proton has put Microsoft 365 on its list of platforms it will help businesses leave. The Swiss company has extended Easy Switch for Business, its guided migration tool, to cover Microsoft 365 tenants. According to IT Security Guru, organisations can now move email, calendars and contacts from Outlook or Google Workspace to Proton's end-to-end encrypted platform without taking their teams offline. The tool first launched for Google Workspace in June.

TechRadar's headline says the move takes "days rather than months." Proton's own setup documentation tells a narrower story. This is a migration for mail, contacts and calendars. It is not a full Microsoft 365 exit, and some parts of the tenant don't come across at all. Here is what the tool does, what it skips, and the step-by-step process Proton documents.

What's new​

In June, Easy Switch for Business supported Google Workspace only. When AlternativeTo covered that launch, it said the company also planned to add Microsoft 365 migration support later this year. That support is now documented. According to TechRadar, for M365 in particular, Proton will automatically handle migration across three main categories – emails, contacts and calendars.

The "days, not months" wording comes from Proton's COO. IT Security Guru quotes Raphael Auphan saying that "moving off Google or Microsoft is now a matter of days, not months." Treat that as the vendor's pitch, not a promise. Proton's support guide gives no completion time. It does say several DNS steps can take up to 24 hours to propagate, and that incoming mail may take up to 24 hours to route after the final MX change.

In short: this is an admin-run, organisation-wide migration for mail, contacts and calendars. It is new for Microsoft 365 and follows the Google Workspace version by about three months.

Why this is different from the old Easy Switch​

Proton has offered an Outlook importer for a while. The change here is who runs it.

In an April 2026 guide, admin Pete Mahon described the earlier approach: if you had more than one user in your M365 tenant, each user needed to run Easy Switch from their own Proton account, after the M365 tenant admin had granted access to the Easy Switch app across the tenant. For a 40-person firm, that meant 40 separate imports and 40 people who could forget to do theirs.

The business version puts the whole job in the administrator's hands. The admin picks the data, connects the tenant, selects the users and starts their migrations from one dashboard. For IT teams that have tried to get staff to run their own mailbox imports, that alone is worth a look.

Requirements before you start​

Proton's support page lists four prerequisites:

  • You are a Proton admin.
  • You are a Microsoft 365 administrator. Proton says a standard user account won't have the permissions needed.
  • Your tenant is cloud-hosted. Proton states that your Microsoft 365 account must be cloud-hosted. On-premises accounts are not supported. On-premises Exchange shops need a different plan.
  • You have access to your domain provider. You'll be editing DNS records several times.

The migration, step by step​

To start, log in to Proton Mail. A Set up your organization modal appears in your inbox. Select Easy Switch for Business and click Next. You will land on the Import via Easy Switch settings page. Click Microsoft to start the migration wizard. You can return to this page at any time via Settings → Import via Easy Switch in the left sidebar.

The wizard has five stages.

1. Configure migration​

Select the data you want to migrate. By default, all three options are selected: Emails, Contacts, and Calendars. Deselect any you do not need, then click Next.

2. Authenticate with Microsoft​

Click Sign-in to Microsoft. A Microsoft sign-in window will open. Sign in using a Microsoft 365 administrator account and grant Proton the requested permissions. Before you click Accept, check the permission list and make sure your security team has approved it, just as you would for any third-party app consent.

3. Configure the domain​

This stage has four DNS sub-steps:

Sub-stepRecord typeHost namePurpose
Verify domainTXTDefault (usually @)Proves you own the domain
SPFTXT@Lets mail go out from both Proton and Microsoft
DKIM3 × CNAMEprotonmail._domainkey, protonmail2._domainkey, protonmail3._domainkeySigns outgoing mail
DMARCTXT_dmarcProtects the domain from impersonation

The status shows "Verification record not found" while DNS propagates, then changes to "Valid verification found." Proton says the verification record can take up to 24 hours to sync.

The SPF step is what allows the gradual cutover. Proton says the SPF record allows your team to send emails from both Proton and Microsoft simultaneously during the migration period. DKIM adds a digital signature to each email so recipients can verify that the message really came from your domain and was not altered in transit. DMARC builds on SPF and DKIM to protect your domain from impersonation and improve email delivery reliability.

A tip from general practice, not from Proton's guide: if your domain already has an SPF record for Microsoft, don't add a second one. A domain should have only one SPF TXT record. Check what Proton's record contains, and merge carefully if your registrar shows an existing entry.

4. Configure users​

A list of all users in your Microsoft 365 tenant will appear, showing each person's name, email address, and estimated data size. You can move the whole organisation at once or start with a small batch and add the rest later. A pilot group is the sensible choice for most firms.

The mailbox-size column comes with a catch. Proton notes that by default, Microsoft may hide mailbox usage data in reports for privacy. To show the sizes, the guide says to go to Microsoft 365 admin center → Settings → Org Settings → Reports and turn off "Conceal user, group and site names in all reports." That is an organisation-wide reporting privacy setting. Proton doesn't say it's required for the migration. It just enables the size estimates. If your organisation turned concealment on for compliance reasons, get sign-off before changing it, or leave it on and do without the numbers.

Migrations then run in the background. Each user shows an "In progress" status, and you can move to the next sub-step without waiting for them to finish.

Onboarding: once accounts have migrated, Proton generates one invitation link for all migrated users. Each user opens it, enters their email address, receives a verification code, verifies and sets a Proton password. One oddity: this Microsoft-specific guide says the code arrives in the user's existing Gmail inbox. That looks like leftover text from the Google Workspace version. Presumably the code goes to the current Microsoft 365 mailbox, but Proton hasn't said so, so check this with your pilot group.

5. Final step: the MX cutover​

This is where you commit. The guide tells admins to change the domain's MX records to Proton's two records, mail.protonmail.ch and mailsec.protonmail.ch, and delete all other MX records. Incoming mail may take up to 24 hours to route to Proton. Until then, the migration summary shows "Waiting for MX…" and tracks account migration, user activation and MX status.

After MX routing switches, Proton treats the migration as final. Activation links stop working at that point. Anyone who hasn't activated needs an admin to reset their password manually. Chase stragglers before you change the MX records.

In short: there are five wizard stages, four DNS changes, and one MX change you can't easily undo. The parallel-sending period is the safety net, so make sure everyone is activated before you remove it.

What doesn't come across​

Proton's documentation is clear about the limits:

  • Shared mailboxes: Microsoft 365 shared mailboxes aren't currently supported and won't appear in the user list. For many firms, info@, accounts@ and support@ are the most important mailboxes, so plan for them separately.
  • Files and documents: TechRadar notes there's no simple switch for other parts of the M365 stack, like file storage. Consultancy iFeeltech, which moved an eight-person firm to Proton, put it plainly: Drive files must be migrated manually — Easy Switch does not handle file storage.
  • Everything else in the tenant: Teams chats, SharePoint sites, Intune policies, Power Automate flows and Entra-based SSO integrations are all outside Easy Switch's scope. Proton has its own Drive, Docs, Sheets, Meet and Pass, but none of that means your Microsoft 365 data moves into them automatically.

So "leaving Microsoft 365 in days" really means moving your email in days. The rest of the stack takes longer.

The sovereignty pitch, and how to read it​

Proton ties the launch to European worries about depending on US vendors. The 74% figure in TechRadar's report comes from Proton's own survey. Cybernews summarises it this way: a 2026 Proton survey of 1,500 European business leaders found that 74% worry that a US kill switch could disrupt their operations. The kill switch refers to a scenario in which the US government could order American companies to discontinue their services to users elsewhere.

Proton's methodology note says the survey covered the UK, Germany and France, with 500 respondents per country, between July 15 and 24, 2026. Keep two points in mind. Proton commissioned the survey, and Proton sells the alternative. The survey also measures how worried people are, not how likely a cutoff is. The concern isn't made up: Proton points to the US blocking the International Criminal Court's use of Microsoft as an example. But the survey is a vendor's marketing research, not an independent risk assessment.

There's a sensible middle ground. IT Security Guru reports that Proton says many customers begin by running its platform in parallel as a business continuity fallback, one that keeps running through an outage, ransomware attack or geopolitical disruption. It is also how most of the CISOs it works with start testing a migration. A dormant backup mail system is easier to justify to a board than ripping everything out.

Should you do it?​

Based on Proton's own documentation, Easy Switch for Business suits:

  • Small, email-centred organisations on cloud-hosted Microsoft 365 that make little use of shared mailboxes and SharePoint.
  • Teams that want a continuity fallback outside US jurisdiction and can run two platforms side by side for a while.

It is harder to justify for organisations that rely on Teams, SharePoint, shared mailboxes, conditional access or Power Platform. For them, Easy Switch covers only the email piece of a much bigger project.

The tool itself is a real improvement. An admin-driven, batch-capable migration with dual sending during the transition beats asking every employee to run their own import. Just plan for the parts Proton's guide says it doesn't handle: shared mailboxes, files, and anyone who hasn't activated their account when the MX records change.

 

References

  1. Proton Easy Switch lets businesses move from Microsoft 365 in just days, rather than months TechRadar 2026-09-30T15:15:00+00:00
  2. Proton Mail launches Easy Switch for Business to help companies move away from Google | AlternativeTo alternativeto.net
  3. Proton Easy Switch now allows email migration from Microsoft 365 cybernews.com