Execution state
- Connection, agent, job, stage, and item status
- Retries, skips, failures, warnings, and progress counters
- Pause, resume, cancellation, and recovery decisions
BridgeAD connects assessment, approved scope, operator action, on-premises directory execution, Microsoft Graph workload engines, reconciliation, and evidence without hiding capability boundaries or migration risk.
Every stage has an owner, inputs, validation criteria, and evidence. BridgeAD is designed to make exceptions and rollback decisions visible instead of reducing migration to a copy button.
Availability depends on the precise workload scope, permissions, tenant state, deployment, and engagement boundary. BridgeAD keeps those conditions attached to the jobs and evidence they govern.
The control plane coordinates scope and sequence. Dedicated services implement each Microsoft workload's discovery, transfer, state, retry, and validation behavior.
| Service | Execution path | State and evidence | Boundary |
|---|---|---|---|
| Active Directory | Assigned customer-network agents execute approved directory commands after mapping and dry-run gates. | Object, stage, wave, agent, command, delta, rollback, and audit outcomes. | Execution, SID, ACL, password, and rollback paths require topology-specific controlled pilots. |
| Microsoft Entra ID | Microsoft Graph creates or updates supported users, groups, devices, and membership and runs selected expansion workflows. | Stable destination IDs, collision failures, source-to-target app IDs, and per-item outcomes. | Synchronization authority, consent, guest governance, app credentials, assignments, and device activation remain explicit. |
| Exchange Online | Graph mailbox clients copy supported content and settings between Microsoft 365 tenants and retain delta state. | Mailbox and folder counters, item fidelity outcomes, delta passes, reconciliation, DNS checks, and completion evidence. | On-premises onboarding, archives, public folders, and delegation use separate paths. |
| SharePoint and OneDrive | Graph drive, list, permission, provisioning, upload-session, and delta APIs operate on frozen assessed scope. | Site and account items, file and byte progress, conflicts, permissions, delta tokens, cutover pass, and validation. | Pages, apps, workflows, sharing links, and tenant governance are not implied by content transfer. |
| Microsoft Teams | Graph reconstructs workspace structure; optional migration mode imports channel messages when Microsoft approval is present. | Team, channel, membership, tab, tag, message, watermark, skipped-item, and validation outcomes. | Files, recordings, and meetings use other workloads; guests, apps, chats, and tenant policy need separate action. |
The control plane coordinates work and retains operational metadata. Agents perform approved directory operations from the customer network. Cloud engines access Microsoft services through customer-consented applications and approved outbound routes.
Portal, APIs, job orchestration, workers, configuration, operational metadata, reporting, audit, telemetry, and operator access.
Outbound control-plane communication and customer-approved LDAP, LDAPS, and resource access for assigned operations.
Customer-consented source and destination connections for enabled Entra ID and Microsoft 365 workload operations.
Operators, migration leads, security teams, and business owners need different evidence from the same program record.
Bring your forests, trusts, object counts, target model, constraints, and success criteria to a technical session.