Migrate as planned
Clean objects with resolved mappings, no collisions, and no blocking dependencies.
A cross-forest Active Directory migration fails in the gaps between phases, not inside them. This checklist sequences the work — discovery through decommission — so each phase produces the evidence the next one depends on.
Everything downstream is scoped from this baseline. Run it read-only and keep the output.
Convert the inventory into decisions. Each object or dependency should land in exactly one bucket.
Clean objects with resolved mappings, no collisions, and no blocking dependencies.
Duplicates, ambiguous matches, disabled-but-referenced accounts, or objects with unclear ownership.
UPN collisions, broken ACL inheritance, orphaned SIDs, stale trusts, or application hard-coding.
Objects excluded by business decision, recorded so nobody assumes they moved.
This is the half of the project that determines whether execution is boring — which is the goal.
Never scale a wave pattern that has not survived a representative pilot with defined acceptance criteria.
The migration is finished when the old forest is safely gone — not when the last wave completes.
A BridgeAD readiness assessment executes phases 1 and 2 for you — read-only discovery, findings, mappings, and a recommended pilot boundary you can take to change control.