S2Stools
Product How it works Pricing Security
Customer sign in Start free preview

Getting started

From nothing to your first preview

Site Migrate moves SharePoint sites 1:1 — version history, authors, timestamps, permissions, attachments, even the site notebook. This page takes you from nothing to your first migration preview. There is nothing to install, and previewing is free.

Before you sign in

You need exactly two things.

A work account — Microsoft Entra ID, the account you use for Microsoft 365. Personal accounts (@outlook.com, @hotmail.com) will not work.

The ability to get one admin approval. If your organization restricts app consent — most do — your first sign-in may show "Need admin approval" instead of a sign-in prompt. That is normal, and nothing is wrong. Forward this link to your IT admin; one click pre-approves sign-in for your whole organization:

https://login.microsoftonline.com/organizations/adminconsent?client_id=b729bd6b-1615-488c-82f8-f8365cbb93ba

Signing in only shares your name, email and organization id with us. It does not grant any access to your SharePoint content — that is a separate, explicit step below.

First sign-in — your workspace

The first person from your organization to sign in at portal.s2stools.com creates its workspace and becomes its admin. There is no separate sign-up form. Colleagues who sign in after you join the same workspace as read-only members; you can promote them under Users.

Every workspace starts on the Free plan: 20 migration previews (dry runs) per month, any size — full inventory and an exact cost estimate, nothing written. Real migrations run on a paid plan. No payment details are asked for.

Connect your SharePoint

To read your sites, Site Migrate needs permission — granted by you, revocable by you, in one of two ways. You choose per connection, and source and target can differ: a cross-tenant migration can use a different method on each side.

Option A — one-time admin consent

Recommended, and available on all plans.

In the portal, open Credentials → Connect with admin consent. You are sent to Microsoft's own consent page; an admin approves once, and you land back in Site Migrate with your SharePoint connected — ready for dry runs immediately, no operator involved. We store only your tenant id and the fact of the grant: no keys, no secrets, no certificates of yours are ever in our hands, and your admin can revoke the grant at any time from your own Entra portal, under Enterprise applications → S2Stools Migration Runner. Deleting the credential in Site Migrate stops us using the grant; deleting the enterprise app revokes it entirely.

What the app asks for, and why. All of these are application permissions, granted up front at consent — Site Migrate does not request them incrementally.

PermissionResourceUsed for
Sites.FullControl.AllMicrosoft Graph Reading inventory (dry runs) and writing content, permissions and metadata to the target
Sites.FullControl.AllSharePoint The CSOM operations the migration engine runs against SPO
Group.ReadWrite.AllMicrosoft Graph Creating the target when it is a group-connected (Teams/M365-group) site
User.Read.AllMicrosoft Graph Resolving the original authors/editors so Created-By and Modified-By carry across faithfully

We ask for Sites.FullControl.All rather than a narrower scope because a migration must create the target site and stamp historical authorship — Sites.Selected and Sites.Read.All cannot do either. If that blast radius is more than your organization will grant a vendor app, use Option B.

You may see a notice that S2Stools is an "unverified publisher." That is expected: Site Migrate is published by Sayar Danışmanlık, and the app is not publisher-verified with Microsoft. It does not change what you are approving — the permissions listed above. If your organization does not allow consent to apps from unverified publishers, use Option B.

Option B — your own app and certificate

Pro and above.

Security-conscious organizations often refuse FullControl to any vendor's multi-tenant app — ours included, and we think that instinct is right. On Pro and above you can register your own Entra app and certificate instead, so the identity doing the migration belongs to you, is scoped by you, and can be killed by you. In the portal: Credentials → Advanced: bring your own app + certificate.

  1. Create an app registration in your Entra tenant, and grant it the Graph application permissions above — admin consent in your own tenant, no third party involved.
  2. Create a certificate for it. Self-signed is fine; your own PKI if you have one.
  3. Register it under Credentials: your SharePoint tenant, the app's client id, and the certificate location. The private key sits in a per-tenant Key Vault, isolated to your workspace — it is read by the migration worker at run time and is never returned over any API.

Setting up the Key Vault side is something we are glad to walk through with you — write to support@s2stools.com and we will do it together. It takes about thirty minutes.

Your first dry run

New migration → enter the source and target site URLs → keep "Dry run" ticked → start.

A dry run connects to the real site, walks everything — lists, libraries, pages, permissions, version chains, the notebook — and writes nothing. You get the exact inventory in GB, items and compute-hours, so you know which plan covers the real move, plus a preview of anything that needs attention first. Dry runs are free on every plan, never count against your allowance, and are the honest way to size a migration before you commit to anything.

When you are ready to migrate for real: runs are resume-safe — a restart continues where it stopped and never copies an item twice — you can set a per-run budget, and a run that reaches your plan's allowance pauses safely where it stands rather than being killed. Add a +100 GB pack ($39) or upgrade, then resume from the same spot.

Plans, in one paragraph

Free — preview-only: 20 dry runs per month, with full inventory and exact cost. Pro $49/mo — 100 GB and 25 compute-hours per month, cross-tenant, full version history, item-level permissions, your own certificate. Business $199/mo — 500 GB, 120 compute-hours, priority queue, customer-managed keys. Larger estates: contact@s2stools.com. 1 compute-hour = 1 vCPU-hour. Migrations run on 2-vCPU workers, so 25 compute-hours is about 12.5 hours of migration time. Payments are handled by Lemon Squeezy, our merchant of record — charges appear on your statement as LEMSQZY*, and you can change or cancel your plan yourself under Plans → Manage billing.

Questions

support@s2stools.com — you are talking to the people who built it.

Start free preview

S2Stools
Product Pricing Security contact@s2stools.com support@s2stools.com Customer sign in
Contact Privacy policy Terms of service Refund policy

© 2026 S2Stools · site-to-site migration · contact@s2stools.com

S2Stools is a brand of Sayar Danışmanlık, İstanbul, Türkiye · contact@s2stools.com · Privacy policy. Our postal address is in the privacy policy; tax office and tax registration details are provided on request.