Graph application permissions
- Source team, channel, member, tab, app, and setting reads
- Destination group, team, channel, membership, tab, and tag writes
- Protected `Teamwork.Migrate.All` approval for message import
BridgeAD assesses teams, channel types, owners, members, guests, tabs, apps, and identity gaps. It reconstructs supported workspace structure through Microsoft Graph, can use Microsoft migration mode for channel messages when protected-API approval is present, and routes files, recordings, and meetings through their owning Microsoft 365 services.
The Teams workspace combines assessment, capability boundaries, job telemetry, and per-team outcomes. Operators can identify unmapped owners, shared-channel trust, unavailable tabs, and custom apps before choosing the destination route or enabling message import.
Illustrative values; the interface displays customer-specific assessment data.
BridgeAD exposes Microsoft-native import, Graph reconstruction, cross-service migration, and manual remediation as different states. That distinction prevents a successful team-shell job from being mistaken for complete workspace fidelity.
| Area | Status | BridgeAD handling | Important boundary |
|---|---|---|---|
| Team shell and settings | Reconstructed | Creates or resolves the Microsoft 365 group and team idempotently, then applies supported member, messaging, and fun settings. | Team photos and sensitivity labels are not currently applied. |
| Channels | Reconstructed | Recreates standard, private, and shared channel structure with membership type preserved. | Shared-channel B2B Direct Connect trust must be re-established and validated in the destination. |
| Owners and members | Mapped identities | Maps source identities, adds resolvable owners and members, and counts skipped assignments. | Unmapped identities are skipped. Guest accounts must be invited and governed in the destination. |
| Channel messages | Conditional | With protected-API approval, opt-in native migration mode imports posts and replies with original author and timestamp and resumes from channel watermarks. | Requires new destination teams in Graph migration mode. Attachments are deferred to SharePoint and counted; reactions are not preserved. |
| Tabs | Supported subset | Re-pins supported app-backed tabs with name, application, URLs, and available configuration. | Tabs backed by custom, unpublished, or unavailable apps are reported for manual recreation. |
| Team tags | Reconstructed | Recreates tags by display name with mapped members after membership exists. | Requires `TeamworkTag.ReadWrite.All`. Unmapped members are counted; tags with no mapped member need manual recreation. |
| Channel files | Cross-service | Resolves source and destination backing-site URLs and coordinates binary transfer through the SharePoint migration service. | Files do not move through the Teams message engine and need a sequenced SharePoint pass. |
| Apps, bots, and connectors | Inventory / manual | Inventories installed apps and classifies store versus organization-published or sideloaded apps during assessment. | Secrets, webhooks, consent grants, bot configuration, and custom publishing are never copied automatically. |
| Validation | Supported | Compares destination teams, channels, mapped membership, and recorded item outcomes; reports mismatches and errors per team. | Cross-service content and manual remediation have their own evidence and sign-off. |
A professional migration sequence assigns each artifact to the service that stores it. BridgeAD makes these dependencies visible so the collaboration plan is not reduced to team and channel provisioning.
| Artifact | Owning path | Required action | Boundary |
|---|---|---|---|
| Channel files and wiki content | SharePoint | Run the backing site through the SharePoint content pass after destination team and channels exist. | Assess unsupported pages or legacy wiki behavior separately. |
| Meeting recordings and transcripts | SharePoint / OneDrive | Include organizer OneDrive and channel-site recording locations in the content scope. | Retention, labels, and meeting metadata are separate controls. |
| Calendar meetings and webinars | Exchange | Migrate calendar items with the organizer mailbox and communicate link changes. | Webinar registration data is not migrated. |
| Meeting join URLs | Administrator action | Recreate or update recurring meetings after cutover so new destination-tenant URLs are issued. | Source-tenant join URLs are not portable. |
| Personal and group chats | Microsoft native roadmap | Set user expectations and evaluate Microsoft cross-tenant chat migration availability for the engagement. | BridgeAD does not currently migrate 1:1 or group chat history. |
| App secrets and webhooks | Application owner | Republish custom apps, re-consent permissions, rotate credentials, and recreate connectors. | Secrets and tenant-scoped integration endpoints are never copied. |
Teams migration behavior depends on Microsoft Graph roles, destination identities, group and channel constraints, and whether Microsoft has approved the tenant application for protected message-import APIs.
Owners and members must exist before tags and private-channel membership can be applied. Backing sites must be addressable before files move. Native message import has its own eligibility and finalization sequence.
Inventory teams, channels, identities, tabs, apps, archived state, and cross-tenant requirements.
Resolve owners and members, destination naming, guest handling, trust, and app remediation.
Create team shells and channels, add mapped membership, then apply settings, tabs, and tags.
Use native message mode when eligible; run SharePoint and Exchange passes for connected artifacts.
Compare structure and membership, review skipped items, finish manual work, and retain evidence.
A structurally complete team can still have missing chat history, changed meeting links, unconfigured apps, or governance variance. These outcomes belong in the acceptance criteria and communications plan.
Yes, only through Microsoft Graph migration mode when the application has Microsoft protected-API approval and native import is enabled. That path creates new destination teams in migration mode, imports posts and replies, and then completes migration mode before normal use.
No. Messages with attachments are imported without those attachments and counted. The underlying files are migrated through the relevant SharePoint or OneDrive content pass.
Mapped destination identities are added. Unmapped users are skipped and counted. Guests must be invited and governed in the destination tenant, and their access should be reviewed before the workspace is released.
Installed apps are inventoried and classified, but organization-published or sideloaded apps need republishing. Secrets, webhooks, consent grants, bot configuration, and connectors must be recreated by the application owner.
The channel membership type is preserved during reconstruction. Private-channel members depend on identity mapping. Shared channels additionally require destination cross-tenant access and B2B Direct Connect trust to be established and tested.
Teams migration is strongest when identity, content, mailbox, and governance work share one assessed scope and one cutover plan.