How to Migrate from Google Workspace to PolarisMail

Whether you’re a reseller preparing a client’s Google Workspace domain for migration, or you’re moving your own Workspace mailbox, the same two things need to happen first: IMAP access needs to be turned on, and you need a way to authenticate that doesn’t rely on your regular Google password. Here’s exactly how to do both.

This setup applies whether you’re a reseller preparing a client’s migration or migrating your own mailbox. Once it’s done, the migration guide covers how to actually submit and run the migration.

Which tier matches your Google Workspace usage?

Before you migrate, it’s worth checking which Google Workspace features you actually rely on day to day. Some map to both Basic and Enhanced mailboxes; a few only exist on Enhanced. Here’s how they line up:

Fully included
Not available
Italics = partial support
If your team uses… The equivalent is… Basic Enhanced
Gmail Webmail
Google Chat Live Chat in Webmail
Google Meet Video calls in Webmail
Google Groups Distribution lists
Shared team calendars Shared calendars Shared folders only
Calendar synced to phone / Outlook / Apple Calendar CalDAV sync
Contacts synced to phone / Outlook CardDAV sync
Calendar and contacts on mobile devices ActiveSync
Docs, Sheets, Slides: editing and co-editing Office Docs View, upload, share only
Google Drive file storage Personal Drive 5 GB 15 GB
Booking pages for meetings EasyMeet scheduling
Threaded group discussions (Chat spaces) Zulip

If your team mostly uses Gmail, chat, video calls, and basic file sharing, Basic covers that. If you depend on shared calendars synced across devices, real-time document co-editing, or scheduling links, Enhanced is the closer match. You don’t have to pick one for the whole domain either — Basic and Enhanced mailboxes can be mixed under the same domain, so different users can be migrated to different tiers based on what they actually use.

Why Google Workspace needs extra setup

Google disabled plain username-and-password sign-in for third-party tools (what Google calls “less secure apps”) and pushes everything toward OAuth instead. Since most migration tools authenticate over IMAP rather than OAuth, you’ll need an App Password in place of your normal password. App Passwords only exist once 2-Step Verification is turned on, and only if your organization’s policies allow them.

Part A: Admin-side setup

For Workspace admins

If you manage the Google Workspace domain (or you’re a reseller working with the client’s admin), start here. These settings apply at the organization or organizational unit (OU) level.

1. Enable IMAP access for users

  1. Sign in to the Google Admin console as an admin.
  2. Go to Apps → Google Workspace → Gmail → End user access (Google labels this section “POP and IMAP access”).
  3. Under POP and IMAP access, check Enable IMAP access for all users.
  4. Choose an IMAP client policy — “Allow any mail client” is the common choice.
  5. Click Save.

If your organization uses Organizational Units, double-check you’re editing the correct OU before saving, so you don’t enable IMAP for the wrong group of users.

2. Confirm your organization allows App Passwords

App Passwords are the standard workaround for tools that can’t use OAuth, but they only appear as an option when 2-Step Verification is enabled for the user, and your org’s policies don’t block them outright.

If a user reports they can’t find “App passwords” anywhere in their account settings, it’s usually one of these:

  • 2-Step Verification isn’t enabled for that user
  • your organization’s account policy blocks App Passwords
  • the account uses Advanced Protection or a security-key-only configuration

If App Passwords are blocked at the org level, an IMAP-based migration won’t work with that user’s current setup, and you’ll need a migration path that supports OAuth instead. Contact support if you hit this.

3. Know where to inspect or revoke App Passwords (optional)

If you ever need to audit or revoke a user’s app-specific passwords: go to the Admin console → Directory → Users, click the user, then open Security. App-specific passwords can be viewed or revoked from there.

Part B: Per-user setup

For each mailbox owner

Once IMAP is enabled at the organization level, each mailbox needs these three things done individually, either by the mailbox owner or by whoever is coordinating the migration on their behalf.

1. Turn on IMAP in Gmail settings

  1. Open Gmail in a browser.
  2. Click the gear icon → See all settings.
  3. Go to the Forwarding and POP/IMAP tab.
  4. Under IMAP access, select Enable IMAP.
  5. Click Save Changes.

2. Enable 2-Step Verification

App Passwords require 2-Step Verification to be turned on first. Enable it from Google Account → Security → Signing in to Google → 2-Step Verification.

3. Generate an App Password

  1. Go to the App passwords page in your Google Account settings.
  2. Create a new App Password — choose Mail, or Other (custom name) and label it something like “IMAP Migration”.
  3. Google generates a 16-digit App Password. Copy it and store it somewhere secure — you’ll need it to authenticate the migration.

Good to know: you typically only need to enter the App Password once, at the start of the migration. If the account’s main Google password changes afterward, Google may revoke existing App Passwords automatically, which means a new one will need to be generated before the migration can continue.

What happens next

Once IMAP is enabled and you have a working App Password (or temporary password, where applicable) for each mailbox, you’re ready to start the migration itself. The full process, whether you’re moving one mailbox or a hundred, is covered in the migration guide:

Migration Guide (Wiki) →