Decide what is ready before deciding when to migrate.
A BridgeAD assessment turns topology, object and content inventory, mapping quality, service dependencies, permissions, Microsoft API eligibility, cutover constraints, and operating ownership into an executable scope and remediation register.
An evidence pack, not a generic score.
The example below illustrates report structure. Names and figures are fictional and are not presented as a customer result or performance benchmark.
Destination identities and mailboxes verified; mail, calendars, contacts, tasks, and delta-pass prerequisites validated for the approved cohort.
Trust, privileges, resource reachability, representative access tests, and rollback procedure require pilot evidence.
Anonymous and organization-wide links need destination recreation under the approved sharing and access-governance policy.
Automated domain-join workstation handling is planned and excluded from the current BridgeAD execution scope.
Collect evidence at the workload boundary.
Each service has different sources of truth, prerequisites, failure modes, and manual dependencies. Assessment findings are therefore workload-specific even when they feed one program plan.
| Workload | Evidence collected | Decision enabled |
|---|---|---|
| Active Directory | Forest and trust topology, OUs, object classes, mappings, collisions, policy scope, privileges, network paths, SID/ACL/password needs, and rollback ownership. | Supported preparation scope and representative controlled-pilot cohort. |
| Microsoft Entra ID | Domains, immutable IDs, UPNs, sync authority, users, groups, devices, guests, applications, consent, licensing, and device-management dependencies. | Core identity sequence plus governed guest, application, and conditional Intune scope. |
| Exchange | Mailbox inventory and state, destination readiness, folder and item volume, calendars, rules, delegates, archives, public folders, DNS, and cutover ownership. | Supported Graph content scope and separate remediation for excluded mailbox features. |
| SharePoint and OneDrive | Sites, drives, libraries, lists, volume, paths, large files, versions, metadata, shared items, principals, custom apps, workflows, and governance. | Frozen content scope, transfer options, workload sequence, and site-application remediation. |
| Microsoft Teams | Teams, channel types, owners, members, guests, tabs, apps, message requirements, protected-API eligibility, backing sites, recordings, and meetings. | Graph reconstruction scope, conditional message path, and cross-service delivery plan. |
What the review needs.
Assessment depth depends on access and evidence. Read-only discovery is preferred; workshop-only assessments carry more assumptions and lower confidence.
- Source and destination forest, domain, and tenant topology
- Trusts, DNS, network paths, agent placement, and Graph consent
- Object and content classes, counts, exclusions, service limits, and stale-data policy
- Target OU, domain, UPN, site, mailbox, team, and identity mapping rules
- SID history, ACL, password, sharing, application, and coexistence requirements
- Change windows, freeze periods, approvals, rollback thresholds, and owners
- Workload fidelity expectations and manual remediation acceptance
- Security, residency, deployment, retention, and evidence requirements
Outputs your team can act on.
Final deliverables are agreed before data collection so stakeholders know which decisions the assessment must support.
Readiness register
Validated prerequisites, assumptions, risks, blockers, evidence, confidence, and accountable owners by workload.
Scope and fidelity matrix
Included objects and content, selected options, exclusions, conditional APIs, manual remediation, and acceptance criteria.
Execution outline
Identity preparation, baseline and delta passes, pilot or cutover gates, reconciliation, rollback decisions, and sign-off sequence.
Start with a 45-minute topology review.
No production access is required for the initial scoping conversation.
