A profiling tool that reads before anything moves
Microsoft's Dynamics 365 Activate, described by Microsoft Apps and Agents chief Jeff Teper in a September 9 post on the Dynamics 365 Blog, analyzes a company's existing CRM environment and profiles its data and dependencies. From that profile it generates migration recommendations with built-in safeguards. It's in public preview now for Salesforce-to-Dynamics 365 moves, with ERP migration capabilities planned later this year.
The pitch is speed. Less manual discovery, fewer surprises once the actual cutover starts. But get past the pitch and there's a simpler fact sitting underneath it: before Activate can recommend anything, it has to read everything. Account records, contact records, opportunity records, custom objects nobody outside the admin team remembers building. If you run data governance or security for a company weighing this tool, that read access is the story, not the migration timeline.
What the six billion records actually tell you
Teper's post says early engagements already involve more than 6 billion records. That figure describes production data from live Salesforce orgs, profiled by an AI system at a scale most companies never expose to any single vendor tool, migration-related or not.
Comcast's Sathish Arumugam is quoted in the post saying Activate's discovery capabilities "helped accelerate our migration assessment by providing greater visibility into our Salesforce landscape and key migration considerations." Read that quote as a customer, and it sounds like a win. Read it as the person who has to answer for what happened to that visibility afterward, and it raises the questions Microsoft's post doesn't spend much time on.
The access question to ask before onboarding
To profile dependencies across a Salesforce org, a tool needs read access closer to admin-level than to a single scoped export. It needs field-level metadata, automation logic, validation rules, and enough visibility into how objects relate to each other to map what actually depends on what. That's the whole value proposition. It's also a bigger grant than most companies plan for when they build out a migration risk register for a project like this.
The scope matters more once you notice how it's being expanded. Teper's post lists agentic mapping, test sampling, natural-language guidance, and executive summaries as planned additions. Every one of those is a new thing Activate produces from what it reads, not just a new thing it reads. Summaries and generated documentation about your CRM data are themselves artifacts. Someone has to govern them the same way they would any other sensitive export, and someone has to know when to delete them.
Where the profiling data goes and how long it sits there
Microsoft's announcement covers what Activate does and what it's adding. It doesn't say where the profiled data and the artifacts it generates are stored, how long they're retained after an engagement ends, who at Microsoft or its partners can see them, or whether any of it touches model training. Those are four separate questions, and a security review should get separate answers to each one, not a single reassurance that covers all four at once.
This is the kind of scoping problem the guide on CMDB access before agents read it covers in a different context: an automated system gets granted broad read access to solve a real problem, and the retention and downstream-use terms get worked out after the fact instead of before. Activate's public preview status makes this the right moment to ask, before ERP migration capabilities extend that same read pattern into financial and HR systems later this year, a moment the ERP master data governance starter is built for.
How this compares to a consultant's access
A traditional migration engagement scopes access tightly by design. A consultant doing discovery work typically gets a sandbox copy or scoped, time-boxed read access to a defined set of systems, under a statement of work that names retention and deletion terms in writing. The guide on scoping a statement of work for a platform migration walks through what that scoping should look like when a human is doing the reading.
Activate's read scope is broader than that by design, since dependency mapping across a whole org is the feature. Broader scope should mean more contract language around retention and use, not less. Nothing in Teper's post suggests Microsoft's public preview terms currently spell that out at the level of detail a negotiated statement of work would.
The customer list is the scale signal
Comcast isn't the only name attached to this launch. Microsoft's post also quotes Ziwi Pets CEO Benjamin Boase and congruentX CEO Marty Priest. It quotes Fusion5's Kristy Brown too, whose title on the page is Chief Executive, New Zealand, Fusion5, a country-specific role, not the company's global one. That's a spread of company sizes and at least two continents already running discovery-level engagements with Activate before the tool has left public preview for its core migration path.
Read next to the customization-to-capability framing Microsoft has used to position Activate, the pattern is consistent: this is a tool Microsoft wants inside a company's data early, well before a migration decision gets made. That's a reasonable ambition for a migration product. It's also exactly why the access conversation belongs in a security review now, while the tool is still Salesforce-focused, rather than after ERP capabilities put payroll and general ledger data in scope too.
Before you grant access
If your company is even considering Activate, the request to your Microsoft account team should be specific. Ask for written retention limits on profiled data and generated summaries. Ask whether any of it can be used for model training beyond your own engagement. Ask who at Microsoft or its partners can see the results, and get that answer in writing too. None of that shows up in a marketing post, which means none of it should be assumed.
Ask for the same terms a consultant's statement of work would already give you, in writing, before the discovery phase starts, not after 6 billion records have already been read.



