A cloud move can simplify how a school operates, but it can also create avoidable disruption if it is treated as a simple file transfer. This cloud migration guide for schools is designed for leaders, trust teams and internal IT staff who need a clear, security-first route to modernising systems without compromising teaching, safeguarding or day-to-day administration.
The right approach is not to move everything at once. It is to decide what should move, in what order, and how each change will improve resilience, access and accountability. For a school or Multi-Academy Trust, the success of a migration is measured less by the technology itself and more by whether staff can teach, pupils can learn and critical services remain available.
Start with the educational outcome
Cloud migration should solve operational problems, not simply replace on-site servers with subscriptions. A school may need more reliable access to learning resources, stronger backup arrangements, better collaboration between sites, or a practical way to support staff working remotely. A trust may need consistent identity management, clearer oversight of data and a scalable platform for new academies.
Set these outcomes before selecting a platform or agreeing a migration date. That gives decision-makers a useful test throughout the project: does this change reduce risk or improve the experience for pupils and staff?
It also prevents a common mistake. Not every application belongs in the same cloud service, and not every legacy system should be moved without review. Some applications may require replacement, integration work or a period of hybrid operation. The sensible answer depends on the age of the application, the sensitivity of its data, the quality of the supplier’s support and the school’s available connectivity.
Build an accurate picture before moving data
A migration plan is only as reliable as the information behind it. Schools often discover that data is spread across shared drives, staff devices, departmental systems, old servers and third-party platforms. If this is not identified early, files can be missed, permissions can be recreated incorrectly and unnecessary information can be carried into the new environment.
Create an inventory of systems, data stores, user groups and integrations. This should cover the MIS, finance and HR systems, safeguarding records, pupil data, learning platforms, email, shared documents, telephony where relevant, CCTV or access-control systems, and any specialist software used in classrooms or support departments.
For each item, establish who owns it, who needs access, what information it contains and how long that information should be retained. This is where the migration becomes a governance exercise as well as an IT project. A folder structure that no one owns today will not become easier to manage simply because it sits in Microsoft 365 or another cloud platform tomorrow.
Data quality matters too. Archive records that no longer need to be actively available, remove duplicate material where appropriate and agree a clear structure for shared resources. Moving less data can reduce project time and storage costs, but records must only be deleted in line with the school’s retention requirements and legal obligations.
Treat identity and access as the foundation
Most cloud security decisions come back to identity. If an account is compromised, an attacker may gain access to email, files, systems and contacts regardless of where those services are hosted. A cloud migration is therefore the right time to standardise how accounts are created, changed and removed.
Schools should define separate access arrangements for pupils, teaching staff, governors, contractors and central trust teams. Access should be based on role and need, rather than granting broad permissions because it is quicker. Multi-factor authentication should be implemented for staff and other higher-risk accounts, with a managed approach for exceptions such as shared devices, accessibility needs and younger pupils.
Leavers and joiners deserve particular attention. Accounts, licences and group memberships should be updated promptly when staff change roles or leave. For trusts, central visibility is valuable, but it should not result in every central user having unrestricted access to every academy’s information. Clear boundaries protect privacy and make investigations easier if an incident occurs.
Plan the cloud migration for schools around the calendar
A technically sound migration can still fail operationally if it is scheduled at the wrong time. Avoid periods when schools depend heavily on stable systems, including examinations, admissions, census preparation, results processing and the first weeks of term. Summer holidays may offer more change time, but they are not automatically risk-free: staff may be unavailable for testing and other estates or IT projects may be happening at the same time.
A phased migration usually gives schools more control. A pilot group can test email, files, devices, printing, permissions and key applications before the approach is rolled out to the wider organisation. This creates time to resolve issues while the impact is contained.
Every phase needs agreed success criteria and a rollback plan. If a finance integration does not work, or staff cannot access a critical resource, who makes the decision to pause? How will users continue working? What data changes need to be captured before reverting? These questions should be answered in advance, not during a busy school morning.
Communication should be practical and timed to the audience. Teachers need to know what will change in their working day, what they need to do and where to get help. Senior leaders need visibility of risks, decisions and progress. Parents generally do not need technical detail, but they may need clear notice where a change affects portals, communication channels or the handling of pupil information.
Protect data before, during and after the move
Cloud platforms can provide strong security, but they do not remove the school’s responsibility for protecting information. Configuration, access controls, monitoring and user behaviour still determine much of the real-world risk.
Before migration, confirm where data will be stored, how it is encrypted, how it is backed up and how it can be restored. Understand the difference between service availability and backup. A platform may be available, yet a file deleted by mistake or encrypted by ransomware may still require recovery from an independent backup.
The project should include a review of security controls such as conditional access, device management, anti-malware protection, email filtering, audit logging and alerting. It should also consider the practical realities of school environments. Shared classroom devices, supply staff, personal devices and visitors can all create exceptions that need clear controls rather than informal workarounds.
Supplier agreements must be reviewed carefully. Schools should know who acts on their instructions, what happens to data when a contract ends, how incidents are reported and whether subcontractors are involved. UK GDPR responsibilities do not disappear when a service is hosted elsewhere.
Test the experience, not just the technical configuration
A successful test is more than confirming that a user can sign in. Ask staff to complete everyday tasks: retrieve a lesson resource, share work with a colleague, access a safeguarding document with appropriate permissions, print from a managed device, use a classroom application and work from another site if that is expected.
Test restore procedures as well. A backup that has never been restored is an assumption, not a recovery capability. Select representative files and systems, agree acceptable recovery times and record the results. For trusts, test both academy-level access and central reporting to make sure permissions work as intended.
Bandwidth and Wi-Fi should be assessed before a larger rollout. Moving services to the cloud can increase reliance on reliable internet access, especially for real-time teaching tools, hosted desktops and centralised storage. In some cases, improving connectivity or providing a resilient secondary connection should be part of the migration programme rather than an afterthought.
Prepare people for the new way of working
Most post-migration support calls are not caused by major technical faults. They arise because staff do not know where documents have moved, how sharing works or why a familiar process has changed. Focused training reduces frustration and helps the school gain the value it expected from the investment.
Training should be role-based and concise. Administrative teams may need guidance on secure document handling and collaborative workflows, while teachers may need practical support with classroom tools and file access. A short, well-organised support period after each phase is more effective than a single training session delivered weeks before the change.
Document the decisions made during the project, including ownership, security settings, licensing, support routes and recovery arrangements. This gives the school continuity when staff change and gives internal IT teams a clear baseline for future improvements.
Keep improving after go-live
Go-live is the start of operational management, not the finish line. Review support requests, failed sign-ins, storage growth, security alerts and user feedback in the first weeks. These measures reveal whether the design is working in practice and where a small adjustment could prevent a larger issue.
For schools without a large in-house IT function, a managed or co-managed partner can provide the additional capacity needed to monitor, secure and improve the environment over time. The value is not simply extra technical hands. It is complete accountability for making sure the platform supports the school’s priorities, rather than becoming another system that demands attention.
A well-planned cloud migration creates room for better teaching, more reliable administration and stronger protection of sensitive information. The best projects are measured by the quiet confidence of a school day that continues to run properly while its technology becomes more capable behind the scenes.





