How to Migrate or Isolate On-Premises SharePoint Servers
Retrospective: this article looks back at events from July 2025, written in 2026 with the benefit of hindsight.
ToolShell showed the risk of internet-facing on-premises SharePoint Server. Here is how to migrate to SharePoint Online — or isolate servers you must keep.
Option A: Migrate to SharePoint Online
- Inventory: sites, libraries, customizations, workflows, integrations and permissions.
- Clean up: archive or delete obsolete content before moving it.
- Plan customizations: farm solutions and classic workflows don't move as-is; rebuild with SharePoint Framework, Power Automate or alternatives.
- Migrate: use the SharePoint Migration Tool or Migration Manager in the SharePoint admin center for file shares and SharePoint Server content.
- Fix permissions during migration — don't carry over broad access that will later affect Copilot.
- Decommission servers after validation.
Option B: Isolate SharePoint Server you must keep
- Remove direct internet exposure. Publish internally only, or behind an identity-aware proxy (for example, Entra application proxy) requiring Entra ID sign-in and MFA.
- Patch immediately for all security updates; subscribe to Microsoft advisories.
- Enable AMSI integration and run Microsoft Defender Antivirus or Defender for Endpoint.
- Rotate ASP.NET machine keys after any suspected compromise and after applying relevant updates, then restart IIS.
- Restrict outbound traffic from SharePoint servers.
- Monitor for new ASPX files and unusual processes.
After ToolShell specifically
If your servers were internet-facing during the exploitation window:
- Apply updates.
- Rotate machine keys.
- Hunt for web shells and indicators published by Microsoft and CISA.
- Consider rebuilding if compromise is confirmed.
- ToolShell (July 2025): On-Prem SharePoint Zero-Days Exploited Worldwide Incident Teardowns
- Detecting SharePoint Server Exploitation: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: On-Prem SharePoint Is Now a Liability CIO Briefings