Exchange and Microsoft 365

Move mailbox content in controlled, verifiable tenant-to-tenant waves.

BridgeAD copies mail, owned calendars, contacts, tasks, rules, selected sharing permissions, and mailbox settings through Microsoft Graph. Operators can verify each mailbox, resume interrupted work, run delta passes, reconcile outcomes, and check public DNS before source retirement.

Supported Microsoft 365 tenant-to-tenantThe automated path covers mailbox content in Exchange Online. On-premises Exchange must first be onboarded through a supported Microsoft migration or hybrid path. Archives, public folders, and mailbox delegation require separate handling.
Operator experience

Control the mailbox move at item level.

Connections, mailbox mappings, readiness checks, job state, and reports are kept together. A failed mailbox does not erase the rest of the wave, and the operator can inspect or retry the affected item without restarting completed mailboxes.

  • Source and destination connection health checks
  • Mailbox discovery, CSV mappings, and destination verification
  • Start, pause, cancel, retry, and resumable execution
  • Baseline and delta-run counters with per-mailbox errors
  • Folder-count and calendar-permission comparison reports
  • Completion certificate with job facts and verification digest
Capability scope

Know exactly which mailbox artifacts move.

BridgeAD uses idempotent Graph operations and records source and destination identifiers so retries can continue safely. Optional artifacts can be disabled when the tenant has not granted the corresponding Graph application permission.

AreaStatusBridgeAD handlingImportant boundary
Mail and foldersSupportedCopies messages into the destination folder hierarchy with body, recipients, dates, read state, importance, flags, categories, and supported attachments.Per-folder delta links reduce repeat enumeration. Unsupported or oversized attachments are reported at item level.
CalendarsSupportedCopies owned default and additional calendars, events, recurrence, reminders, categories, and supported meeting fields.Calendars owned by another user migrate with that owner. Tenant-scoped meeting links can require reissue.
Contacts and tasksSupportedCopies root contacts, nested contact folders, and Microsoft To Do lists and tasks.Tasks require the relevant Graph application permission; unavailable task access degrades with a reported warning.
Rules and settingsOptionalCopies supported inbox rules and mailbox settings such as automatic replies, time zone, language, date/time formats, and working hours.Tenant policies and transport rules are organization configuration, not mailbox content.
Calendar sharingOptionalMaps and applies non-default calendar principals where the destination identity resolves.Unresolved principals are reported. Full Access, Send As, Send on Behalf, and broader mailbox delegation are separate.
Delta and reconciliationSupportedPersists processed IDs and mail delta tokens, prepares follow-up passes, compares folder counts, and exports permission variance.A completed copy still requires review of failed, skipped, or unresolved outcomes before sign-off.
DNS cutoverValidationChecks public MX, SPF, DKIM selectors, DMARC, and Autodiscover records against Microsoft 365 expectations.BridgeAD reports DNS state; it does not change registrar or DNS-provider configuration.
Prerequisites

Prepare the destination before copying content.

The migration engine cannot compensate for an unprovisioned mailbox, an unresolved identity, missing application consent, or a cutover plan with no mail-flow owner.

01 / Tenant access

Microsoft Graph application

  • Source read and destination write permissions approved
  • Credentials stored in the configured secret store
  • Connection health and exact mailbox query shape tested
02 / Mailbox readiness

Destination objects and licensing

  • Destination identities and UPN mappings agreed
  • User mailboxes licensed and provisioned
  • Shared, room, and equipment purpose verified
03 / Change readiness

Wave, coexistence, and DNS plan

  • Baseline and final-delta windows approved
  • MX and Autodiscover change ownership assigned
  • Rollback, support, and unresolved-item decisions documented
Migration workflow

Reduce the final window with staged passes.

The same job can establish a baseline, retain progress state, and prepare a delta pass. The cutover decision is informed by mailbox-level outcomes rather than a single aggregate percentage.

01

Connect

Validate Graph credentials, tenant reachability, mailbox access, and optional task permissions.

02

Map

Discover mailboxes, import or edit source-to-target UPN mappings, and verify destination readiness.

03

Baseline

Copy selected mailbox artifacts in waves with retries, checkpoints, and item-level telemetry.

04

Delta and cutover

Copy changes since the baseline, validate DNS, and switch mail flow under the approved change plan.

05

Reconcile

Compare folders and permissions, resolve exceptions, record sign-off, and retain completion evidence.

Delivery boundaries

Content migration does not move tenant configuration.

These boundaries are part of the migration plan, not footnotes. BridgeAD reports what its Graph path handles so administrators can assign every remaining task to Microsoft-native tooling or a named owner.

Automated scope

Mailbox content and validation

  • Mail, folders, calendars, contacts, and tasks
  • Optional rules, settings, and calendar sharing
  • Delta passes, reconciliation, and DNS readiness
Separate Microsoft path

Source and archive constraints

  • On-premises Exchange onboarding or hybrid move
  • In-place archive mailbox content
  • Public-folder hierarchy and content
Administrator owned

Organization configuration

  • Mailbox delegation and send permissions
  • Transport, journaling, retention, holds, and DLP
  • DNS changes, license assignment, and source retirement
Frequently asked questions

Exchange migration questions

Can BridgeAD migrate directly from on-premises Exchange?

The automated mailbox-content path is designed for Exchange Online between Microsoft 365 tenants. An on-premises source must first be moved or hybrid-onboarded through a supported Microsoft path; that prerequisite is scoped separately.

How does an interrupted mailbox resume?

BridgeAD persists processed source IDs, created destination IDs, and per-folder mail delta links. Saga steps are designed to tolerate retries, allowing the job to continue without intentionally duplicating already processed content.

Does a delta pass include every mailbox artifact?

Mail uses Graph delta links. Other selected artifacts use persisted idempotency state and source identifiers. The resulting pass and any warnings are shown per mailbox and should be reviewed before cutover approval.

Does BridgeAD change DNS records?

No. It reads public DNS and reports MX, SPF, DKIM, DMARC, and Autodiscover readiness. A customer or managed-service change owner remains responsible for publishing and approving DNS changes.

What evidence is available after completion?

Operators can export mappings, mailbox verification, folder reconciliation, calendar-permission comparison, job outcomes, and a completion certificate containing job facts and a SHA-256 verification digest.

Build a mailbox wave from verified scope.

Bring mailbox counts, source and destination tenants, required artifacts, DNS ownership, and the desired cutover window.