Execution state
- Connection, agent, job, stage, and item status
- Retries, skips, failures, warnings, and progress counters
- Pause, resume, cancellation, and recovery decisions
The BridgeAD migration control plane is one application for the whole program. Choose named connections, preview proposed changes, launch bounded migration jobs, follow live item progress, resolve failures, and export acceptance evidence across identity, endpoints, servers, and Microsoft 365 workloads.
The application keeps configuration, execution, and evidence connected. Users move from a validated input to an explicit action and then to a durable result, rather than translating a platform feature list into their own runbook.
| Workspace | What the user does | What the application returns |
|---|---|---|
| Overview | Review active workloads, migration phase, throughput, failed jobs, capacity, and recent activity. | Programme health, attention queues, progress trends, and direct links into the affected job. |
| Connections and agents | Add named source and destination environments, test permissions, pair agents, and verify health. | Connection readiness, permission failures, agent heartbeat, and actionable setup errors. |
| Assessment and mapping | Discover inventory, inspect findings, map identities and destinations, import CSV decisions, and freeze scope. | Readiness findings, unresolved mappings, collision warnings, approved objects, and repeatable scope. |
| Jobs, waves, and pipelines | Choose workload options, preview the run, group jobs into waves, schedule stages, and apply approval or freeze gates. | Versioned options, prerequisites, queued work, dependency state, and blocked-start reasons. |
| Live operations | Watch current-item and processed/failed counters; inspect warnings; pause, cancel, resume, or retry where supported. | Per-item outcomes, safe-boundary cancellation, retry state, throughput, and terminal summaries. |
| Validation and evidence | Reconcile destination state, disposition exceptions, accept or reject results, and download completion artifacts. | Reports, PDFs, CSV/Excel exports, migration certificates, transcripts, sign-offs, and hash-chain-verifiable audit records. |
Every stage has an owner, inputs, validation criteria, and evidence. BridgeAD is designed to make exceptions and rollback decisions visible instead of reducing migration to a copy button.
Availability depends on the precise workload scope, permissions, tenant state, deployment, and engagement boundary. BridgeAD keeps those conditions attached to the jobs and evidence they govern.
The control plane coordinates scope and sequence. Dedicated services implement each Microsoft workload's discovery, transfer, state, retry, and validation behavior.
| Service | Execution path | State and evidence | Boundary |
|---|---|---|---|
| Active Directory | Assigned customer-network agents execute approved directory commands after mapping and dry-run gates. | Object, stage, wave, agent, command, delta, rollback, and audit outcomes. | Execution, SID, ACL, password, and rollback paths require topology-specific controlled pilots. |
| Microsoft Entra ID | Microsoft Graph creates or updates supported users, groups, devices, and membership and runs selected expansion workflows. | Stable destination IDs, collision failures, source-to-target app IDs, and per-item outcomes. | Synchronization authority, consent, guest governance, app credentials, assignments, and device activation remain explicit. |
| Exchange Online | Graph mailbox clients copy supported content and settings between Microsoft 365 tenants and retain delta state. | Mailbox and folder counters, item fidelity outcomes, delta passes, reconciliation, DNS checks, and completion evidence. | On-premises mailbox anchoring stays Microsoft-native; in-place archives and public folders migrate via the certified EWS route, and delegation is reported for re-grant. |
| SharePoint and OneDrive | Graph drive, list, permission, provisioning, upload-session, and delta APIs operate on frozen assessed scope. | Site and account items, file and byte progress, conflicts, permissions, delta tokens, cutover pass, and validation. | Pages, apps, workflows, sharing links, and tenant governance are not implied by content transfer. |
| Microsoft Teams | Graph reconstructs workspace structure; optional migration mode imports channel messages; a separate protected-API workflow re-creates private chats and writes full-history transcripts to OneDrive. | Team, channel, membership, tab, tag, message, chat-run, transcript, skipped-item, and validation outcomes. | Files, recordings, and meetings use other workloads; native private-chat history injection remains Microsoft-dependent. |
| Google Workspace directory | Named service-account configuration reads users and groups, previews mappings, then syncs them to Entra or provisions them directly to on-premises AD. | Created, updated, skipped, failed, and membership outcomes in a live background run. | Passwords never leave Google; Gmail, Drive, and Calendar content are not implied. |
| Endpoint operations | Operators upload a customer-built provisioning package, preview device scope, then run AD unjoin, Entra join, Microsoft 365 app reset, restart, and escrow verification. | Per-device readiness, current operation, conversion state, validation, BitLocker escrow confirmation, and acceptance sign-off. | Supported; runs against a customer-built provisioning package with dry-run preview, per-device SYSTEM agent, and BitLocker escrow verification before acceptance. |
| IIS and SQL Server | Operators submit server pairs, run preflight, confirm destructive replacement when requested, and start agent-executed IIS or database moves. | Live server-pair progress, preflight blocks, migrated objects, warnings, failures, and terminal summaries. | Supported; TLS private keys stay manual, TDE and downgrade blocks apply, and SQL agents need scoped sysadmin — all enforced as preflight gates. |
The control plane coordinates work and retains operational metadata. Agents perform approved directory operations from the customer network. Cloud engines access Microsoft services through customer-consented applications and approved outbound routes.
Portal, APIs, job orchestration, workers, configuration, operational metadata, reporting, audit, telemetry, and operator access.
Outbound control-plane communication and customer-approved LDAP, LDAPS, and resource access for assigned operations.
Customer-consented source and destination connections for enabled Entra ID and Microsoft 365 workload operations.
Operators, migration leads, security teams, and business owners need different evidence from the same program record.
Bring your forests, trusts, object counts, target model, constraints, and success criteria to a technical session.