← All playbooks
Cloud storage migration

Box → Dropbox

Move files, folders, ownership, permissions, versions, native documents, shared containers, links, compliance evidence, and integrations from Box into Dropbox with an explicit exception ledger and evidence-based cutover.

Typical timeline15–40 business days75–145 hours active work
Statusneeds review
Source testedBox documentation reviewed 2026-07-19
Destination testedDropbox documentation reviewed 2026-07-19
Last reviewed2026-07-19
Sources2
Before you migrate

Should you make this move?

Both platforms have a case. Compare what you gain with what you give up before scheduling the cutover.

Current platform

Box

Reasons to stay
  • Enterprise governance, compliance, and content workflows are unusually deep
  • Managed sync, sharing, version history, and access controls reduce file-server work
Reasons to leave
  • Cost and administration can be excessive for straightforward file synchronization
  • Shared links, permissions, comments, and ownership models do not map cleanly
New platform

Dropbox

What gets better
  • Fast, dependable desktop synchronization keeps file-based collaboration simple
  • Managed sync, sharing, version history, and access controls reduce file-server work
What gets worse
  • Knowledge, office-suite, and governance workflows are less integrated than broader suites
  • Shared links, permissions, comments, and ownership models do not map cleanly
Best of the move

Dropbox: Fast, dependable desktop synchronization keeps file-based collaboration simple. This removes a major source-side concern: Cost and administration can be excessive for straightforward file synchronization.

Worst of the move

What you lose: Enterprise governance, compliance, and content workflows are unusually deep. What you inherit: Knowledge, office-suite, and governance workflows are less integrated than broader suites.

01At a glance

Know the shape of the move.

Transfer outcome12 features audited
Transfer outcome distributionClean transfer: 0, Partial transfer: 8, Manual rebuild: 2, Not transferred: 2.
Clean0
Partial8
Manual2
Lost2
Mapping route9 of 9 fields have a destination path

This timeline assumes

  • Up to 5 TB, 2 million objects, and 1,000 users
  • Administrators control both tenants and have approved user and group identity maps.
  • The source remains read-only and licensed until object, version, link, and access checks pass.
  • A representative user, shared container, and native-document set are migrated first.
  • The migration team records evidence for every blocking verification check.
02Loss matrix

What survives the move.

“Partial” and “manual” are not footnotes. They are work that must be scheduled and verified.

ItemOutcomeImpactWhat happensMitigation
Files, folders, owners, collaborators, shared links, and selected versionspartialcriticalCore files, folders, owners, collaborators, shared links, and selected versions can move, but Box and Dropbox use different models, limits, identifiers, and import behavior.Pilot every feature class, preserve source IDs, and reconcile accepted, transformed, rejected, and excluded items.
Box metadata, Relay, Notes, Shield, governance, legal holds, and app integrationsmanualcriticalBox-specific workflow and governance products require separate evidence retention and destination controls.Inventory every active dependency, approve its destination disposition, and test the replacement before source writes stop.
Files and folderspartialcriticalCore binaries and folders can move while unsupported names, sizes, paths, or object types are skipped.Reconcile every source object to a destination object, exclusion, or approved archive.
Ownership and user identitypartialcriticalOwnership depends on a complete identity map and destination licenses.Provision users first and explicitly assign orphaned content.
Sharing and permissionspartialcriticalRoles, inheritance, restricted children, groups, and external collaborators differ.Apply and test a signed destination access matrix.
File versionspartialhighMigration tools may omit versions, cap revisions, or increase duration substantially when versions are enabled.Choose a retention depth and compare revision counts on a pilot.
Cloud-native documentspartialcriticalProvider-native documents may convert, flatten, export to office formats, or remain unsupported.Classify and test every native document type before bulk migration.
Comments, tasks, and annotationslosthighCollaboration metadata rarely becomes destination-native history.Resolve active work and archive required evidence.
Shared drives, team folders, and shortcutspartialcriticalContainer and link semantics do not map one-to-one.Design target containers and detect duplicate or broken shortcut outcomes.
Public and external linksmanualcriticalExisting URLs and link permissions do not remain stable.Inventory critical links and notify owners of replacements.
Timestamps and metadatapartialhighCreated, modified, owner, classification, and custom metadata coverage varies.Define required metadata and compare a stratified sample.
Retention, legal holds, and audit evidencelostcriticalA productivity migration is not a compliance archive.Export required evidence and obtain legal approval before source cleanup.
03Field and feature mapping

Where each thing goes.

SourceDestinationMethodNotes
Box user or ownerDropbox user or ownermanualProvision and license identities before content.
Personal rootDestination personal roottransformKeep source identity and path in the manifest.
Team folder or shared spaceDestination shared containermanualApprove ownership and membership first.
FolderFolderautomaticValidate path length, characters, and item limits.
FileFileautomaticCompare size and checksum.
Cloud-native documentDestination native or office documenttransformRecord conversions and unsupported features.
Permission or collaborationDestination access roletransformMap role and inheritance explicitly.
VersionDestination revision or archivetransformApply the approved retention depth.
Shared link or shortcutDestination link or shortcutmanualDo not assume URL continuity.
04Before you begin

Make the move recoverable.

Backup procedure

Create the source-of-truth backup

Preserve Box data, configuration, and operating evidence before any destination write.

  1. Export Box file, folder, owner, permission, link, version, metadata, and shared-container inventories.
  2. Download or archive every cloud-native and otherwise unsupported content class.
  3. Record counts, bytes, versions, owners, collaborators, external links, and legal holds.
  4. Hash raw manifests and representative binaries.

Proof to capture: A signed manifest reconciles every scoped record class, runtime dependency, export file, count, and hash.

Transformation · Official inventory tools and migration workbook

Identity, container, and permission map

Preserve ownership and least-privilege access.

  1. Inventory source values and exceptions.
  2. Define explicit destination mappings.
  3. Reject unmapped critical records.

Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.

Transformation · Official migration service, checksum tool, and exception ledger

Object and native-document migration

Copy supported files and disposition every exception.

  1. Normalize encoding, dates, identifiers, and blanks.
  2. Run a representative pilot.
  3. Reconcile accepted, rejected, and transformed rows.

Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.

05Handle with care

The things most likely to hurt.

These are operating limits. Treat every “Stop if” condition as a blocked migration, not a suggestion.

Migration

A completed job hides skipped or converted objects

criticalpossible likelihood

Headline completion masks unsupported files, native documents, versions, or path errors.

Consequence
Users discover missing or altered work after cutover.
Mitigation
Reconcile every source object and exception.

Stop if: Any critical object lacks a destination, exclusion, or archive.

Access

Permissions broaden during container conversion

criticalpossible likelihood

Restricted children or external collaborators inherit unintended access.

Consequence
Confidential files are disclosed.
Mitigation
Apply and test a signed access matrix.

Stop if: An unauthorized test identity can open a restricted file.

Cutover

Both tenants accept edits

criticalpossible likelihood

Users or integrations update source and destination copies.

Consequence
File histories diverge.
Mitigation
Freeze source writers and apply one final delta.

Stop if: An unexplained post-freeze source change appears.

06Precise timeline

Do the work in this order.

Estimate forUp to 5 TB, 2 million objects, and 1,000 users
Total elapsed15–40 business days
Active work75–145 hours
BufferAdd time for large exports, unsupported Box features, destination limits, identity exceptions, regulated data, or strict downtime requirements.
01
Days 1–3Inventory and decisions2–3 days
02
Days 3–5Backup and reconcile1–3 days
03
Days 5–12Map and pilot3–8 days
04
Days 10–20Final delta and switch1–5 days
05
Days 12–40Observe and close3–10 days
  1. Days 1–3 · inventory

    Inventory and decisions

    6–12 hours active2–3 days elapsedOwner review waiting
    • Inventory Box data, features, users, domains, and integrations.
    • Approve scope, owners, mappings, and exclusions.

    Depends on: Box and Dropbox administrator access

    Stop / go checkpoint

    Export?

    Go when: Every critical item has an owner and disposition.

    Stop when: Consent, billing, access, or system ownership is unclear.

  2. Days 3–5 · backup

    Backup and reconcile

    5–10 hours active1–3 days elapsedExport processing waiting
    • Create immutable exports and configuration evidence.
    • Reconcile counts, totals, and hashes.

    Depends on: Approved inventory

    Stop / go checkpoint

    Transform?

    Go when: Source totals and export manifests agree.

    Stop when: Any critical dataset or configuration is absent.

  3. Days 5–12 · pilot

    Map and pilot

    10–35 hours active3–8 days elapsedDestination processing and review waiting
    • Configure Dropbox and transform representative data.
    • Run a pilot containing normal records and every critical edge case.

    Depends on: Verified backup

    Stop / go checkpoint

    Scale?

    Go when: Pilot mappings, behavior, access, and evidence pass.

    Stop when: Any critical check fails or produces unexplained variance.

  4. Days 10–20 · cutover

    Final delta and switch

    5–25 hours active1–5 days elapsedDNS, import, or sync propagation waiting
    • Freeze production writes in Box.
    • Apply the final delta, switch ownership, and run blocking checks.

    Depends on: Passed pilot and approved rollback

    Stop / go checkpoint

    Open production?

    Go when: Counts reconcile and one destination system owns production.

    Stop when: A source writer remains active or a blocking check fails.

  5. Days 12–40 · observe

    Observe and close

    3–18 hours active3–10 days elapsedOperating-cycle evidence waiting
    • Monitor one complete operating cycle.
    • Sign the verification report and close rollback only after stability.

    Depends on: Verified cutover

    Stop / go checkpoint

    Close rollback?

    Go when: No trigger occurs during the agreed observation period.

    Stop when: Data, access, delivery, routing, or business results regress.

07The point of change

Cut over with a way back.

Go live

Cutover

Make Dropbox the only production system without losing the final Box delta.

Recommended window: A low-volume weekday morning with platform, data, DNS, and business owners available.

  1. Freeze production writes and scheduled actions in Box.
  2. Export, transform, and reconcile the final delta.
  3. Apply the approved delta to Dropbox.
  4. Switch domains, forms, integrations, sending, or sync ownership as applicable.
  5. Run every blocking verification check and keep the source intact.

Proof to capture: Dropbox owns production, totals reconcile, and every blocking check has durable evidence.

Return to safety

Rollback

Return production ownership to Box without losing destination-era changes.

Deadline: Within seven days and before source data, plans, credentials, domains, or billing are changed.

  1. Stop new writes and scheduled actions in Dropbox.
  2. Restore the prior Box routing, forms, integrations, sending, or sync ownership.
  3. Export the Dropbox post-cutover delta.
  4. Review and apply safe destination-era changes to Box.
  5. Run the same blocking checks against the restored source.

Proof to capture: Box again owns production with current data and no duplicate destination action.

Rollback immediately when
  • Unexplained critical count or value variance
  • Missing or exposed critical data
  • Duplicate production action
  • Failed access, routing, delivery, or integration check
  • A critical feature has no safe destination replacement
08Verification report

Prove the migration worked.

Every blocking check must pass. Capture the evidence before cleanup begins.

0%
Interactive report preview0 / 8 checks passed
PassIDCheckMethodExpected resultEvidence
V-01BlockingFile and folder reconciliationCompare source, accepted, skipped, failed, and destination counts and bytes.Every scoped object is accounted for.Object ledger.
V-02BlockingBinary parityCompare checksums and sizes for a stratified and critical-file set.Every tested binary matches.Checksum report.
V-03BlockingConversion fidelityOpen every source-native type and exercise required features.Meaning and critical behavior are preserved or archived.Conversion matrix.
V-04BlockingRevision coverageCompare approved version counts and timestamps.Retention depth matches the signed policy.Version report.
V-05BlockingOwnership mappingQuery active, inactive, group, and orphaned owners.Every object has an approved owner.Ownership ledger.
V-06BlockingInternal and external permissionsTest representative identities and shared links.Least privilege matches the signed matrix.Access evidence.
V-07BlockingShortcut and embedded-link behaviorExercise critical links from documents and integrations.Every critical reference resolves or has a replacement.Link report.
V-08BlockingSingle file authorityInspect sync clients, integrations, and source changes.Dropbox alone accepts approved edits.Cutover checklist.
09Post-migration cleanup

Remove the scaffolding safely.

Safe after: One complete operating cycle, at least seven stable days, and owner sign-off on every blocking check.

  1. Create final Box exports and archive verification evidence.
  2. Revoke temporary credentials, API keys, webhooks, and elevated roles.
  3. Remove obsolete embeds, forms, jobs, integrations, and DNS records.
  4. Keep the source intact through the approved retention window.
  5. Cancel paid plans only after billing, legal, and recovery review.
  6. Schedule the next Dropbox backup, access, and migration-playbook review.
Sources and maintenance

Built to be reviewed.

Tested 2026-07-19. Next scheduled review: 2026-10-19.

  1. Box: official migration documentationAccessed 2026-07-19
  2. Dropbox: official migration documentationAccessed 2026-07-19