Active Directory

Make every directory change inspectable before execution.

BridgeAD discovers users, groups, computers, organizational units, contacts, and policy scope; builds source-to-target mappings; detects conflicts; and runs dry-run validation. Execution then moves through topology-specific pilot gates for staged orchestration, delta sync, SID history, ACL restamping, password options, cutover, and rollback.

Controlled pilot Execution boundaryDiscovery, mapping, conflict checks, CSV workflows, and dry runs are supported. Object execution and parity workflows require representative lab validation, approved privileges and network paths, acceptance criteria, change control, and named rollback ownership.
Operator experience

Move from inventory to approved waves.

Operators validate source and destination connections, inspect discovered objects and findings, resolve automatic or manual mappings, run preflight and dry-run checks, and organize approved cohorts into migration jobs, pipelines, or scheduled waves.

  • Agent-backed source and destination connection validation
  • OU-scoped users, groups, computers, contacts, and policy discovery
  • Automatic, manual, and CSV mapping workflows
  • Duplicate anchor, naming, UPN, and target-conflict checks
  • Preflight findings and non-destructive dry runs
  • Job, stage, wave, rollback, and audit evidence
Capability scope

Separate supported preparation from pilot execution.

A valid dry run proves that the configured scope and checks can be evaluated. It does not certify trust design, target delegation, network reachability, application compatibility, or rollback behavior for every topology.

AreaStatusBridgeAD handlingImportant boundary
Discovery and assessmentSupportedDiscovers scoped users, groups, computers, OUs, contacts, and policy information and records preflight findings.Discovery results must be reviewed against authoritative CMDB, application, security, and business-owner inventories.
Object mappingsSupportedBuilds automatic or manual source-to-target mappings, supports CSV workflows, and validates duplicate or conflicting anchors.Accepted mappings remain a customer design decision; an automatic match is not business-owner approval.
Dry runSupportedEvaluates job options, mappings, target conflicts, and execution assumptions without intentionally applying destination changes.A dry run cannot replace representative write, authentication, ACL, password, and rollback testing.
Object creation and membershipControlled pilotStages directory object operations and group membership in dependency order through agent-dispatched commands.Target OU delegation, naming, attribute authority, nesting, and application behavior must be validated in the customer topology.
Delta synchronizationControlled pilotCoordinates repeat synchronization for approved objects before final cutover.Source-of-authority, freeze period, conflict ownership, and stopping conditions must be defined.
SID history and ACL restampingControlled pilotProvides SID mapping, SID-history workflow, and ACL translation/restamp orchestration with recorded outcomes.Requires elevated rights, trust and security-policy approval, reachable resources, and representative file/application validation.
Password optionsControlled pilotProvides opt-in password-sync orchestration and account-enable sequencing with encrypted payload support.Requires LDAPS, delegated password rights, secure agent configuration, policy compatibility, and an agreed fallback.
Rollback and auditControlled pilotRecords migration state, exposes rollback controls, and retains operator and stage evidence.Rollback scope and reversibility vary by operation. Business continuity and application rollback remain jointly owned.
Prerequisites

Prove the topology and controls in a representative lab.

The pilot should use the same trust direction, DNS behavior, agent placement, delegation model, network route, security controls, and representative applications expected in production.

01 / Directory design

Topology and authority

  • Source and target forests, trusts, DNS, and OU design approved
  • Attribute authority, UPN, naming, and collision rules documented
  • Service accounts and least-privilege delegation tested
02 / Execution path

Agents and network

  • Outbound agent communication and command routing healthy
  • LDAP/LDAPS, domain controllers, target OUs, and resources reachable
  • Encryption keys, certificates, logging, and secret handling verified
03 / Change control

Pilot acceptance

  • Representative user, group, computer, ACL, and application cohort selected
  • Success thresholds, monitoring, freeze, support, and escalation agreed
  • Rollback owner, decision point, and recovery procedure rehearsed
Migration workflow

Advance only when the current gate has evidence.

BridgeAD supports staged orchestration, but stage progression remains governed by the approved migration plan. Pilot outcomes should update the runbook before a larger wave is scheduled.

01

Discover

Validate connections, inventory the agreed OUs, and collect object, policy, and conflict findings.

02

Map and preflight

Resolve identities and targets, import or export mappings, clear blockers, and run dry validation.

03

Pilot

Execute a representative cohort through object, membership, password, SID, and ACL gates as approved.

04

Delta and cutover

Synchronize agreed changes, enforce the source freeze, complete final operations, and monitor access.

05

Reconcile

Validate authentication, groups, resources, applications, errors, evidence, and rollback thresholds.

Rollback design

Define reversibility per operation.

Rollback is not one universal undo. Destination object creation, membership changes, passwords, SID history, ACLs, source disablement, workstation state, and application configuration each have different recovery mechanics.

Before execution

Record the baseline

  • Approved scope, mappings, job options, and owners
  • Source and target object state and relevant ACL evidence
  • Application authentication and business acceptance checks
During pilot

Hold at stage gates

  • Pause on threshold breach or unresolved critical outcome
  • Retain command, stage, agent, and operator evidence
  • Exercise the documented rollback path before expansion
Customer owned

Restore service

  • DNS, trust, application, endpoint, and support actions
  • Business continuity and user communication decisions
  • Manual remediation where an operation is not reversible
Current exclusions

Do not infer endpoint and resource migration from directory orchestration.

The current product coordinates directory-centric workflows. The following areas are planned or require a separate, validated delivery path unless explicitly included in an engagement.

Endpoint

Device transition

  • Automated workstation domain rejoin
  • User State Migration Tool profile transfer
  • Application packaging and endpoint reconfiguration
Policy and print

GPO dependencies

  • WMI filter migration
  • GPO security-filter translation
  • Print queue and printer deployment migration
Files and applications

Resource modernization

  • SMB or RoboCopy file transfer
  • Application service accounts and embedded identities
  • Non-ACL configuration and vendor-specific integration
Frequently asked questions

Active Directory migration questions

Why is execution described as a controlled pilot?

The orchestration exists, but AD outcomes depend on topology, trusts, delegation, DNS, security policy, network reachability, applications, and operational ownership. A representative pilot validates those dependencies and establishes acceptance and rollback evidence.

What does a dry run prove?

It validates the configured scope, mappings, options, and detectable conflicts without intentionally applying destination changes. It does not prove credentials, application sign-in, workstation behavior, SID history, ACL access, or password outcomes under production conditions.

Can BridgeAD migrate SID history and restamp ACLs?

BridgeAD includes SID mapping, SID-history, and ACL orchestration workflows. They remain controlled-pilot capabilities because they require elevated rights, security approval, reachable resources, and validation against representative file and application access.

Does BridgeAD automatically rejoin workstations?

No. Automated workstation rejoin and profile migration are planned and should be assigned to a separate endpoint workstream for current engagements.

Is rollback guaranteed for every change?

No. BridgeAD records state and provides rollback controls, but reversibility differs by operation. The pilot must define what can be automatically reversed, what requires a manual runbook, and when business continuity procedures take precedence.

Design the pilot around your actual topology.

Bring forest and trust diagrams, OU and object counts, identity rules, application dependencies, privilege constraints, representative resources, and the required cutover window.