Select
Choose validated source and destination connections, agents, assessed objects, users, sites, mailboxes, or servers.
Use BridgeAD — the Active Directory migration tool for Microsoft 365, Entra ID and cloud migrations — to govern Active Directory and Microsoft 365 delivery. Or assess cloud estates, design target architecture, and produce defensible plans with BridgeAD Intelligence.


Product views use synthetic demonstration data. Available screens vary by role and release.
BridgeAD is not only a capability catalog. Operators work through named source and destination connections. They preview changes, start bounded jobs, and watch individual items move. They can intervene safely and close each wave with inspectable outputs.
Choose validated source and destination connections, agents, assessed objects, users, sites, mailboxes, or servers.
Run dry-run or readiness checks, inspect collisions and unsupported items, then revise mappings or scope before writes begin.
Launch a job, wave, cloud-directory run, endpoint conversion, or server operation with the options attached to that run.
See the current item, processed and failed counts, warnings, throughput, and live state; pause, cancel, resume, or retry where supported.
Review exceptions and validation, record acceptance, and export reports, certificates, transcripts, and audit evidence.
See a migration run — tour the application workspaces and outputs
BridgeAD is designed first for AD-heavy and hybrid programs. In these programs, dependencies, operator control, rollback planning, and evidence matter as much as moving objects.
Discover, map, dry-run, and migrate directory objects through controlled waves.
02Coordinate identity scope, approvals, execution, and evidence across environments.
03Assess identity and workload readiness before committing to content-transfer scope.
04Keep the control plane in customer-managed infrastructure with explicit cloud egress.
05Standardize assessment, pilot boundaries, operator roles, and evidence across client programs.
Choose Cloud Workloads for AD and Microsoft 365 migration. Choose Intelligence for cloud assessment, planning, controlled execution, analysis, and reporting.
Assess, scope, execute, reconcile, and prove Active Directory, Entra ID, Exchange, SharePoint, OneDrive, and Teams migrations — plus any-to-any mailbox moves across Gmail, IMAP, on-premises Exchange, and archives.
Assess cloud estates, compare target designs, verify plans, govern execution, investigate failures, and prepare cited reports.
Supported discovery, mapping, CSV workflows, collision checks, and dry runs. Topology-specific controlled pilots then cover execution, delta, SID, ACL, password, and rollback workflows.
Certified routes between Exchange Online tenants, Gmail, IMAP hosts, on-premises Exchange (EWS), and PST/EML archives — mail, owned calendars, contacts, and tasks with resumable delta passes, signed fidelity contracts, and offline-verifiable custody evidence.
Assessment-backed site and drive scoping with resumable Graph content transfer. Conflict handling and version depth are configurable. Permissions are mapped, lists are supported, and delta passes end in reconciliation.
Graph reconstruction for team and channel structure, mapped membership, supported settings, tabs, and tags. Microsoft-native channel-message import is conditional.
Graph-based users, groups, devices, and memberships with collision protection. Adds governed guest invitations, selected application definitions, and conditional Intune policy definitions.
Supported audit logging with hash-chain verification, correlation IDs, role-change traceability, and exportable operational reports.
Status applies to the exact scope stated below. Every engagement still depends on tenant state, permissions, connectivity, and identity mappings. Service limits, validation, and owned remediation also apply.
| Capability | Status | Current delivery boundary |
|---|---|---|
| AD discovery, mapping, CSV validation, and dry run | Supported | Available for onboarding when connections and permissions validate. |
| AD migration orchestration and rollback | Supported | Dry-run first with success criteria; per-item rollback, automated rollback rules, and connectivity circuit breakers are built in. |
| SID history and ACL restamping | Supported | Agent-executed with streamed progress and evidence; multi-forest translation limitations apply and are reported per item. |
| Entra users, groups, devices, and memberships | Supported | Configured Graph permissions required; synchronized attributes remain owned by Entra Connect or Cloud Sync. |
| Entra tenant-to-tenant users and static groups | Supported | Preview-first route with UPN transformation, optional update-existing re-runs, and membership reconciliation; licenses, mailboxes, and MFA registration remain separate. |
| Google Workspace directory to Entra or AD | Supported | Users and groups only through domain-wide delegation; Gmail, Drive, Calendar, and source passwords are outside this route. |
| Cloud-native device conversion | Supported | AD unjoin, Entra join, Microsoft 365 app reset, and BitLocker escrow verification — dry-run first, using a customer-built provisioning package and a per-device SYSTEM agent. |
| IIS and SQL Server migration | Supported | Agent-executed configuration and database moves with preview and confirmation gates; TLS keys, TDE prerequisites, and linked-server secrets retain explicit boundaries. |
| Exchange Online mailbox content and cutover evidence | Supported | Microsoft 365 tenant-to-tenant Graph path plus certified any-to-any routes (Gmail, IMAP, EWS, archives); in-place archives and public folders migrate via the certified EWS route, and delegation is reported for re-grant. |
| SharePoint, OneDrive, and supported list content | Supported | Scoped Graph transfer; full site-app fidelity, sharing links, and tenant governance are not implied. |
| Teams structure, membership, settings, tabs, and tags | Supported | Graph reconstruction; files and meetings move through their owning workloads. |
| Teams channel messages | Conditional | Requires Microsoft protected-API approval and opt-in migration mode; attachments move through SharePoint and reactions are not preserved. |
| Teams private chats | Conditional | Re-creates mapped chat shells and writes full-history transcripts to destination OneDrive; requires source `Chat.Read.All`, and history is not injected into destination threads. |
BridgeAD standardises migration delivery so teams can assess risk early, execute in controlled waves, and close with evidence-backed reporting.
Connect source and destination environments and run read-only discovery. Baseline identity, directory, and workload readiness before scope is committed.
Build mapping rules, wave strategy, and rollback guardrails. Dry-run validates assumptions. It produces a clear execution plan per migration phase.
Execute dependency-ordered jobs with retry, resume, and real-time progress telemetry. Pause, resume, cancel, or retry failed items without losing control.
Run reconciliation checks and export audit and job reports. Close with governed handover and operational evidence for client, security, and compliance teams.
BridgeAD includes the controls and integrations required to run migration programs at enterprise scale.
Pre-migration readiness scoring, finding categorisation, and exportable reports in CSV, Excel, and PDF formats.
SignalR live dashboards, health checks, metrics endpoints, and alert-ready telemetry for NOC and delivery teams.
Comprehensive authenticated APIs and signed webhook notifications. Integrates with ITSM, SIEM, and internal orchestration pipelines.
Outbound-only Windows agent with pairing, heartbeat monitoring, command dispatch, and controlled auto-update workflows.
BridgeAD persists the operational metadata needed to orchestrate and audit work. Mail, file, and message bodies are not retained at rest in BridgeAD infrastructure.
A Data Processing Addendum (DPA) is available on request via legal[at]bridgead[dot]in.
Use managed SaaS or deploy the control plane in customer-managed infrastructure. Available features and required egress are confirmed during solution design.
Multi-tenant managed service hosted on Azure. Region-pinned data residency. Per-seat or per-mailbox licensing. Fastest path to first migration.
Single-tenant deployment inside the customer’s Azure subscription, Kubernetes environment, or Docker host. Microsoft 365 workloads still require approved outbound access to Microsoft APIs.
BridgeAD is a product of Apqor Technologies Pvt Ltd, an engineering company based in Hyderabad, India. There is no reseller layer or outsourced support desk between you and the people who build the platform.
Migration engineering, security review, and commercial questions route to the team that ships the product. The same engineers who write the orchestration review your controlled-pilot plan.
Every public capability statement maps to a reviewed claim ledger and a readiness status — Supported, Conditional, Controlled pilot, or Manual. We publish boundaries next to claims rather than behind a sales call.
Run managed SaaS with region-pinned residency, or self-host inside your own subscription, Kubernetes cluster, or Docker host. Your compliance boundary is a first-class design input, not an afterthought.
Assessment findings, dry runs, reconciliation, and sign-off exports are produced as verifiable artifacts. You evaluate us on what the platform records, not on what we promise.
Not for directory or Microsoft 365 workload migrations: one healthy agent per reachable domain is often sufficient. Device-local workflows such as controlled-pilot cloud-native conversion are different. They require a healthy agent running as SYSTEM on each target Windows device for the conversion window.
No. Migration content is streamed in transit from source to destination. Only metadata required for orchestration (job state, error counts, audit records) is persisted — never bodies of mail, files, or messages.
Exchange Online mailbox content (including certified any-to-any routes to and from Gmail, IMAP, on-premises Exchange, and PST/EML archives), SharePoint and OneDrive content, and Teams structure reconstruction are supported within their documented prerequisites and exclusions. Teams channel-message import is conditional on Microsoft protected-API approval. See the workload directory for exact scope and manual boundaries.
You pin a primary Azure region at provisioning. All customer-scoped data (audit log, configuration, secrets in Azure Key Vault) stays in that region. Operational telemetry may be processed in additional regions under SCC-equivalent safeguards.
Yes. The self-hosted edition deploys via Helm chart, raw Kubernetes manifests, or Docker Compose, and runs entirely inside your subscription or data centre. SaaS and self-hosted ship from the same codebase.
Five-tier RBAC: Viewer, Migration Operator, Tenant Admin, Platform Admin, Super Admin. MFA is mandatory for every privileged role. All sign-ins and privilege changes are recorded to the immutable audit log.
Yes. BridgeAD exposes authenticated REST APIs and webhook notifications for job events and audit automation. Downstream integrations include ITSM, SIEM, and delivery runbooks.
Yes. Request a scoped PoC at sales[at]bridgead[dot]in with your source & destination tenant context.