Governed hybrid migration for complex environments

Control complex AD and Microsoft 365 migrations from one platform.

Discover dependencies, freeze approved scope, execute directory work through an outbound-only agent and cloud workloads through approved Microsoft APIs, then reconcile outcomes. Deploy BridgeAD as SaaS or inside your environment.

Supported AD discovery and mapping Dry-run before execution Hash-chain audit verification SaaS and self-hosted deployment

Representative BridgeAD workflow view. Production screens and available actions vary by role, deployment, and release.

Outbound-onlyon-premises agent connection
Dry-run firstrecommended for every initial wave
Hash-chain verifiedaudit records and role changes
Two deployment modelsmanaged SaaS or customer-controlled
Workload readiness

Know what can enter scope before the project starts.

Status applies to the exact scope stated below. Every engagement still requires tenant state, permissions, connectivity, identity mappings, service limits, validation, and owned remediation.

CapabilityStatusCurrent delivery boundary
AD discovery, mapping, CSV validation, and dry runSupportedAvailable for onboarding when connections and permissions validate.
AD migration orchestration and rollbackControlled pilotAPQOR oversight, lab validation, success criteria, and reviewed rollback plan required.
SID history and ACL restampingControlled pilotScoped validation required; multi-forest translation limitations apply.
Entra users, groups, devices, and membershipsSupportedConfigured Graph permissions required; synchronized attributes remain owned by Entra Connect or Cloud Sync.
Exchange Online mailbox content and cutover evidenceSupportedMicrosoft 365 tenant-to-tenant Graph path; archives, public folders, and delegation need separate handling.
SharePoint, OneDrive, and supported list contentSupportedScoped Graph transfer; full site-app fidelity, sharing links, and tenant governance are not implied.
Teams structure, membership, settings, tabs, and tagsSupportedGraph reconstruction; files and meetings move through their owning workloads.
Teams channel messagesConditionalRequires Microsoft protected-API approval and opt-in migration mode; attachments move through SharePoint and reactions are not preserved.

Read the status definitions and delivery assumptions

How it works

From discovery to verification — in four operational phases.

BridgeAD standardises migration delivery so teams can assess risk early, execute in controlled waves, and close with evidence-backed reporting.

Discover

Connect source and destination environments, run read-only discovery, and baseline identity, directory, and workload readiness before scope is committed.

Plan

Build mapping rules, wave strategy, and rollback guardrails. Dry-run validates assumptions and produces a clear execution plan per migration phase.

Execute

Execute dependency-ordered jobs with retry, resume, and real-time progress telemetry. Pause, resume, cancel, or retry failed items without losing control.

Verify & close

Run reconciliation checks, export audit and job reports, and complete governed handover with operational evidence for client, security, and compliance teams.

Operations

Built for delivery teams, not just demos.

BridgeAD includes the controls and integrations required to run migration programs at enterprise scale.

Assessment & reporting

Pre-migration readiness scoring, finding categorisation, and exportable reports in CSV, Excel, and PDF formats.

Real-time operations

SignalR live dashboards, health checks, metrics endpoints, and alert-ready telemetry for NOC and delivery teams.

API & automation

Comprehensive authenticated APIs and signed webhook notifications for integration with ITSM, SIEM, and internal orchestration pipelines.

On-prem execution agent

Outbound-only Windows agent with pairing, heartbeat monitoring, command dispatch, and controlled auto-update workflows.

Security

Migration content is streamed, not retained by the control plane.

BridgeAD persists the operational metadata needed to orchestrate and audit work. Mail, file, and message bodies are not retained at rest in BridgeAD infrastructure.

  • Customer migration content is streamed source → destination; no mailbox, file, or message body is persisted at rest in BridgeAD infrastructure.
  • All Microsoft Graph and Exchange traffic is TLS 1.2+; internal control plane uses TLS termination and mutual authentication.
  • Secrets are stored in Azure Key Vault (SaaS) or DPAPI-protected local stores (self-hosted). Access tokens are never logged.
  • Multi-tenant deployments enforce per-tenant data isolation via Entity Framework query filters and database-level row filters.
  • Five-tier RBAC (Viewer, Migration Operator, Tenant Admin, Platform Admin, Super Admin) with mandatory MFA for all privileged roles.
  • Self-hosted edition keeps every byte of customer data inside the customer’s own infrastructure.

A Data Processing Addendum (DPA) is available on request via legal@bridgead.in.

Deployment

Two deployment models. One orchestration approach.

Use managed SaaS or deploy the control plane in customer-managed infrastructure. Available features and required egress are confirmed during solution design.

SaaS

Multi-tenant managed service hosted on Azure. Region-pinned data residency. Per-seat or per-mailbox licensing. Fastest path to first migration.

Self-hosted

Single-tenant deployment inside the customer’s Azure subscription, Kubernetes environment, or Docker host. Microsoft 365 workloads still require approved outbound access to Microsoft APIs.

FAQ

Common questions.

Do we need an agent on every user workstation?

No. BridgeAD uses a lightweight on-prem agent installed on server infrastructure, not on end-user devices. In many deployments, one agent per domain is sufficient when source and target connectivity is available.

Does BridgeAD store our mailbox or file content?

No. Migration content is streamed in transit from source to destination. Only metadata required for orchestration (job state, error counts, audit records) is persisted — never bodies of mail, files, or messages.

What is your Microsoft 365 workload migration readiness?

Exchange Online mailbox content, SharePoint and OneDrive content, and Teams structure reconstruction are supported within their documented prerequisites and exclusions. Teams channel-message import is conditional on Microsoft protected-API approval. See the workload directory for exact scope and manual boundaries.

Where does our data live in the SaaS edition?

You pin a primary Azure region at provisioning. All customer-scoped data (audit log, configuration, secrets in Azure Key Vault) stays in that region. Operational telemetry may be processed in additional regions under SCC-equivalent safeguards.

Can we run BridgeAD on-prem or in our own subscription?

Yes. The self-hosted edition deploys via Helm chart, raw Kubernetes manifests, or Docker Compose, and runs entirely inside your subscription or data centre. SaaS and self-hosted ship from the same codebase.

How is access controlled?

Five-tier RBAC: Viewer, Migration Operator, Tenant Admin, Platform Admin, Super Admin. MFA is mandatory for every privileged role. All sign-ins and privilege changes are recorded to the immutable audit log.

Can BridgeAD integrate with our internal tooling?

Yes. BridgeAD exposes authenticated REST APIs and webhook notifications for job events, audit automation, and downstream integrations such as ITSM, SIEM, and delivery runbooks.

Do you offer a sandbox or proof-of-concept?

Yes. Request a scoped PoC at sales@bridgead.in with your source & destination tenant context.

Ready to plan your migration?

Tell us about your tenants and timeline. We respond within one business day.