Control complex AD and Microsoft 365 migrations from one platform.
Discover dependencies, freeze approved scope, execute directory work through an outbound-only agent and cloud workloads through approved Microsoft APIs, then reconcile outcomes. Deploy BridgeAD as SaaS or inside your environment.
Representative BridgeAD workflow view. Production screens and available actions vary by role, deployment, and release.
Start with the migration you actually need to control.
BridgeAD is designed first for AD-heavy and hybrid programs where dependencies, operator control, rollback planning, and evidence matter as much as moving objects.
AD forest consolidation
Discover, map, dry-run, and migrate directory objects through controlled waves.
02M&A and divestitures
Coordinate identity scope, approvals, execution, and evidence across environments.
03Tenant-to-tenant planning
Assess identity and workload readiness before committing to content-transfer scope.
04Regulated self-hosted delivery
Keep the control plane in customer-managed infrastructure with explicit cloud egress.
05MSP migration delivery
Standardize assessment, pilot boundaries, operator roles, and evidence across client programs.
One control plane for the work that is ready.
BridgeAD separates supported capabilities from controlled pilots and planned connectors, so scope is agreed before delivery begins.
Active Directory
Supported discovery, mapping, CSV workflows, collision checks, and dry runs, followed by topology-specific controlled pilots for execution, delta, SID, ACL, password, and rollback workflows.
Exchange and Microsoft 365
Tenant-to-tenant mail, folders, owned calendars, contacts, tasks, optional rules, selected mailbox settings, resumable delta passes, reconciliation, and DNS cutover validation.
SharePoint & OneDrive
Assessment-backed site and drive scoping, resumable Graph content transfer, configurable conflicts and version depth, mapped permissions, supported lists, delta passes, and reconciliation.
Microsoft Teams
Graph reconstruction for team and channel structure, mapped membership, supported settings, tabs, and tags, with conditional Microsoft-native channel-message import.
Microsoft Entra ID
Graph-based users, groups, devices, and memberships with collision protection, plus governed guest invitations, selected application definitions, and conditional Intune policy definitions.
Audit & Compliance
Supported audit logging with hash-chain verification, correlation IDs, role-change traceability, and exportable operational reports.
Know what can enter scope before the project starts.
Status applies to the exact scope stated below. Every engagement still requires tenant state, permissions, connectivity, identity mappings, service limits, validation, and owned remediation.
| Capability | Status | Current delivery boundary |
|---|---|---|
| AD discovery, mapping, CSV validation, and dry run | Supported | Available for onboarding when connections and permissions validate. |
| AD migration orchestration and rollback | Controlled pilot | APQOR oversight, lab validation, success criteria, and reviewed rollback plan required. |
| SID history and ACL restamping | Controlled pilot | Scoped validation required; multi-forest translation limitations apply. |
| Entra users, groups, devices, and memberships | Supported | Configured Graph permissions required; synchronized attributes remain owned by Entra Connect or Cloud Sync. |
| Exchange Online mailbox content and cutover evidence | Supported | Microsoft 365 tenant-to-tenant Graph path; archives, public folders, and delegation need separate handling. |
| SharePoint, OneDrive, and supported list content | Supported | Scoped Graph transfer; full site-app fidelity, sharing links, and tenant governance are not implied. |
| Teams structure, membership, settings, tabs, and tags | Supported | Graph reconstruction; files and meetings move through their owning workloads. |
| Teams channel messages | Conditional | Requires Microsoft protected-API approval and opt-in migration mode; attachments move through SharePoint and reactions are not preserved. |
From discovery to verification — in four operational phases.
BridgeAD standardises migration delivery so teams can assess risk early, execute in controlled waves, and close with evidence-backed reporting.
Discover
Connect source and destination environments, run read-only discovery, and baseline identity, directory, and workload readiness before scope is committed.
Plan
Build mapping rules, wave strategy, and rollback guardrails. Dry-run validates assumptions and produces a clear execution plan per migration phase.
Execute
Execute dependency-ordered jobs with retry, resume, and real-time progress telemetry. Pause, resume, cancel, or retry failed items without losing control.
Verify & close
Run reconciliation checks, export audit and job reports, and complete governed handover with operational evidence for client, security, and compliance teams.
Built for delivery teams, not just demos.
BridgeAD includes the controls and integrations required to run migration programs at enterprise scale.
Assessment & reporting
Pre-migration readiness scoring, finding categorisation, and exportable reports in CSV, Excel, and PDF formats.
Real-time operations
SignalR live dashboards, health checks, metrics endpoints, and alert-ready telemetry for NOC and delivery teams.
API & automation
Comprehensive authenticated APIs and signed webhook notifications for integration with ITSM, SIEM, and internal orchestration pipelines.
On-prem execution agent
Outbound-only Windows agent with pairing, heartbeat monitoring, command dispatch, and controlled auto-update workflows.
Migration content is streamed, not retained by the control plane.
BridgeAD persists the operational metadata needed to orchestrate and audit work. Mail, file, and message bodies are not retained at rest in BridgeAD infrastructure.
- Customer migration content is streamed source → destination; no mailbox, file, or message body is persisted at rest in BridgeAD infrastructure.
- All Microsoft Graph and Exchange traffic is TLS 1.2+; internal control plane uses TLS termination and mutual authentication.
- Secrets are stored in Azure Key Vault (SaaS) or DPAPI-protected local stores (self-hosted). Access tokens are never logged.
- Multi-tenant deployments enforce per-tenant data isolation via Entity Framework query filters and database-level row filters.
- Five-tier RBAC (Viewer, Migration Operator, Tenant Admin, Platform Admin, Super Admin) with mandatory MFA for all privileged roles.
- Self-hosted edition keeps every byte of customer data inside the customer’s own infrastructure.
A Data Processing Addendum (DPA) is available on request via legal@bridgead.in.
Two deployment models. One orchestration approach.
Use managed SaaS or deploy the control plane in customer-managed infrastructure. Available features and required egress are confirmed during solution design.
SaaS
Multi-tenant managed service hosted on Azure. Region-pinned data residency. Per-seat or per-mailbox licensing. Fastest path to first migration.
Self-hosted
Single-tenant deployment inside the customer’s Azure subscription, Kubernetes environment, or Docker host. Microsoft 365 workloads still require approved outbound access to Microsoft APIs.
Common questions.
Do we need an agent on every user workstation?
No. BridgeAD uses a lightweight on-prem agent installed on server infrastructure, not on end-user devices. In many deployments, one agent per domain is sufficient when source and target connectivity is available.
Does BridgeAD store our mailbox or file content?
No. Migration content is streamed in transit from source to destination. Only metadata required for orchestration (job state, error counts, audit records) is persisted — never bodies of mail, files, or messages.
What is your Microsoft 365 workload migration readiness?
Exchange Online mailbox content, SharePoint and OneDrive content, and Teams structure reconstruction are supported within their documented prerequisites and exclusions. Teams channel-message import is conditional on Microsoft protected-API approval. See the workload directory for exact scope and manual boundaries.
Where does our data live in the SaaS edition?
You pin a primary Azure region at provisioning. All customer-scoped data (audit log, configuration, secrets in Azure Key Vault) stays in that region. Operational telemetry may be processed in additional regions under SCC-equivalent safeguards.
Can we run BridgeAD on-prem or in our own subscription?
Yes. The self-hosted edition deploys via Helm chart, raw Kubernetes manifests, or Docker Compose, and runs entirely inside your subscription or data centre. SaaS and self-hosted ship from the same codebase.
How is access controlled?
Five-tier RBAC: Viewer, Migration Operator, Tenant Admin, Platform Admin, Super Admin. MFA is mandatory for every privileged role. All sign-ins and privilege changes are recorded to the immutable audit log.
Can BridgeAD integrate with our internal tooling?
Yes. BridgeAD exposes authenticated REST APIs and webhook notifications for job events, audit automation, and downstream integrations such as ITSM, SIEM, and delivery runbooks.
Do you offer a sandbox or proof-of-concept?
Yes. Request a scoped PoC at sales@bridgead.in with your source & destination tenant context.