Microsoft Graph application
- Source read and destination write permissions approved
- Credentials stored in the configured secret store
- Connection health and exact mailbox query shape tested
BridgeAD copies mail, owned calendars, contacts, tasks, rules, selected sharing permissions, and mailbox settings through Microsoft Graph. Operators can verify each mailbox, resume interrupted work, run delta passes, reconcile outcomes, and check public DNS before source retirement.
Connections, mailbox mappings, readiness checks, job state, and reports are kept together. A failed mailbox does not erase the rest of the wave, and the operator can inspect or retry the affected item without restarting completed mailboxes.
Illustrative values; the interface displays customer-specific job data.
BridgeAD uses idempotent Graph operations and records source and destination identifiers so retries can continue safely. Optional artifacts can be disabled when the tenant has not granted the corresponding Graph application permission.
| Area | Status | BridgeAD handling | Important boundary |
|---|---|---|---|
| Mail and folders | Supported | Copies messages into the destination folder hierarchy with body, recipients, dates, read state, importance, flags, categories, and supported attachments. | Per-folder delta links reduce repeat enumeration. Unsupported or oversized attachments are reported at item level. |
| Calendars | Supported | Copies owned default and additional calendars, events, recurrence, reminders, categories, and supported meeting fields. | Calendars owned by another user migrate with that owner. Tenant-scoped meeting links can require reissue. |
| Contacts and tasks | Supported | Copies root contacts, nested contact folders, and Microsoft To Do lists and tasks. | Tasks require the relevant Graph application permission; unavailable task access degrades with a reported warning. |
| Rules and settings | Optional | Copies supported inbox rules and mailbox settings such as automatic replies, time zone, language, date/time formats, and working hours. | Tenant policies and transport rules are organization configuration, not mailbox content. |
| Calendar sharing | Optional | Maps and applies non-default calendar principals where the destination identity resolves. | Unresolved principals are reported. Full Access, Send As, Send on Behalf, and broader mailbox delegation are separate. |
| Delta and reconciliation | Supported | Persists processed IDs and mail delta tokens, prepares follow-up passes, compares folder counts, and exports permission variance. | A completed copy still requires review of failed, skipped, or unresolved outcomes before sign-off. |
| DNS cutover | Validation | Checks public MX, SPF, DKIM selectors, DMARC, and Autodiscover records against Microsoft 365 expectations. | BridgeAD reports DNS state; it does not change registrar or DNS-provider configuration. |
The migration engine cannot compensate for an unprovisioned mailbox, an unresolved identity, missing application consent, or a cutover plan with no mail-flow owner.
The same job can establish a baseline, retain progress state, and prepare a delta pass. The cutover decision is informed by mailbox-level outcomes rather than a single aggregate percentage.
Validate Graph credentials, tenant reachability, mailbox access, and optional task permissions.
Discover mailboxes, import or edit source-to-target UPN mappings, and verify destination readiness.
Copy selected mailbox artifacts in waves with retries, checkpoints, and item-level telemetry.
Copy changes since the baseline, validate DNS, and switch mail flow under the approved change plan.
Compare folders and permissions, resolve exceptions, record sign-off, and retain completion evidence.
These boundaries are part of the migration plan, not footnotes. BridgeAD reports what its Graph path handles so administrators can assign every remaining task to Microsoft-native tooling or a named owner.
The automated mailbox-content path is designed for Exchange Online between Microsoft 365 tenants. An on-premises source must first be moved or hybrid-onboarded through a supported Microsoft path; that prerequisite is scoped separately.
BridgeAD persists processed source IDs, created destination IDs, and per-folder mail delta links. Saga steps are designed to tolerate retries, allowing the job to continue without intentionally duplicating already processed content.
Mail uses Graph delta links. Other selected artifacts use persisted idempotency state and source identifiers. The resulting pass and any warnings are shown per mailbox and should be reviewed before cutover approval.
No. It reads public DNS and reports MX, SPF, DKIM, DMARC, and Autodiscover readiness. A customer or managed-service change owner remains responsible for publishing and approving DNS changes.
Operators can export mappings, mailbox verification, folder reconciliation, calendar-permission comparison, job outcomes, and a completion certificate containing job facts and a SHA-256 verification digest.
Mailbox cutover depends on destination identity readiness and often coincides with Teams meetings, OneDrive recordings, compliance controls, and broader tenant transition work.