BridgeAD Cloud Workloads

A migration control plane for live migration operations.

The BridgeAD migration control plane is one application for the whole program. Choose named connections, preview proposed changes, launch bounded migration jobs, follow live item progress, resolve failures, and export acceptance evidence across identity, endpoints, servers, and Microsoft 365 workloads.

What users seeRole-specific dashboards, connection health, assessments, scoped jobs, migration waves, live operation runs, exception queues, validation, reports, approvals, and audit records.
Application workspaces

Every screen should answer the operator's next question.

The application keeps configuration, execution, and evidence connected. Users move from a validated input to an explicit action and then to a durable result, rather than translating a platform feature list into their own runbook.

BridgeAD application workspaces, operator actions, and outputs
WorkspaceWhat the user doesWhat the application returns
OverviewReview active workloads, migration phase, throughput, failed jobs, capacity, and recent activity.Programme health, attention queues, progress trends, and direct links into the affected job.
Connections and agentsAdd named source and destination environments, test permissions, pair agents, and verify health.Connection readiness, permission failures, agent heartbeat, and actionable setup errors.
Assessment and mappingDiscover inventory, inspect findings, map identities and destinations, import CSV decisions, and freeze scope.Readiness findings, unresolved mappings, collision warnings, approved objects, and repeatable scope.
Jobs, waves, and pipelinesChoose workload options, preview the run, group jobs into waves, schedule stages, and apply approval or freeze gates.Versioned options, prerequisites, queued work, dependency state, and blocked-start reasons.
Live operationsWatch current-item and processed/failed counters; inspect warnings; pause, cancel, resume, or retry where supported.Per-item outcomes, safe-boundary cancellation, retry state, throughput, and terminal summaries.
Validation and evidenceReconcile destination state, disposition exceptions, accept or reject results, and download completion artifacts.Reports, PDFs, CSV/Excel exports, migration certificates, transcripts, sign-offs, and hash-chain-verifiable audit records.
Operating model

Five stages. One decision trail.

Every stage has an owner, inputs, validation criteria, and evidence. BridgeAD is designed to make exceptions and rollback decisions visible instead of reducing migration to a copy button.

DiscoverConnections, topology, objects, dependencies.
PlanMappings, exclusions, batches, dry run.
ExecuteAgent commands, controlled jobs, recovery.
ReconcileCounts, failures, retry decisions.
ProveAudit records, exports, sign-off.
Program controls

Built around decisions migration teams make repeatedly.

Availability depends on the precise workload scope, permissions, tenant state, deployment, and engagement boundary. BridgeAD keeps those conditions attached to the jobs and evidence they govern.

  • Connection validation
    Source and target AD, Entra ID, Exchange, SharePoint, and Teams connections with explicit health and permission checks.
  • Assessment-backed scope
    Inventory objects and content, review findings, select approved assets, and freeze the definition used for execution.
  • Identity mapping
    Automatic, manual, and CSV mappings with collision checks and stable source-to-destination references.
  • Dry runs and gates
    Evaluate directory assumptions and require workload prerequisites before the first controlled execution wave.
  • Workload jobs
    Separate options, item state, concurrency controls, retries, resume behavior, and validation for each owning service.
  • Pipelines and waves
    Link workload jobs to program stages, schedules, dependency order, and terminal-state monitoring.
  • Operational control
    Live status, pause and resume behavior, failed-item review, health, metrics, and alert-ready telemetry.
  • Evidence and sign-off
    Hash-chain audit verification, correlation IDs, exports, reconciliation, migration certificates, and recorded acceptance.
Execution services

Keep workload logic with the system that owns the data.

The control plane coordinates scope and sequence. Dedicated services implement each Microsoft workload's discovery, transfer, state, retry, and validation behavior.

Platform services, execution paths, and delivery boundaries
ServiceExecution pathState and evidenceBoundary
Active DirectoryAssigned customer-network agents execute approved directory commands after mapping and dry-run gates.Object, stage, wave, agent, command, delta, rollback, and audit outcomes.Execution, SID, ACL, password, and rollback paths require topology-specific controlled pilots.
Microsoft Entra IDMicrosoft Graph creates or updates supported users, groups, devices, and membership and runs selected expansion workflows.Stable destination IDs, collision failures, source-to-target app IDs, and per-item outcomes.Synchronization authority, consent, guest governance, app credentials, assignments, and device activation remain explicit.
Exchange OnlineGraph mailbox clients copy supported content and settings between Microsoft 365 tenants and retain delta state.Mailbox and folder counters, item fidelity outcomes, delta passes, reconciliation, DNS checks, and completion evidence.On-premises mailbox anchoring stays Microsoft-native; in-place archives and public folders migrate via the certified EWS route, and delegation is reported for re-grant.
SharePoint and OneDriveGraph drive, list, permission, provisioning, upload-session, and delta APIs operate on frozen assessed scope.Site and account items, file and byte progress, conflicts, permissions, delta tokens, cutover pass, and validation.Pages, apps, workflows, sharing links, and tenant governance are not implied by content transfer.
Microsoft TeamsGraph reconstructs workspace structure; optional migration mode imports channel messages; a separate protected-API workflow re-creates private chats and writes full-history transcripts to OneDrive.Team, channel, membership, tab, tag, message, chat-run, transcript, skipped-item, and validation outcomes.Files, recordings, and meetings use other workloads; native private-chat history injection remains Microsoft-dependent.
Google Workspace directoryNamed service-account configuration reads users and groups, previews mappings, then syncs them to Entra or provisions them directly to on-premises AD.Created, updated, skipped, failed, and membership outcomes in a live background run.Passwords never leave Google; Gmail, Drive, and Calendar content are not implied.
Endpoint operationsOperators upload a customer-built provisioning package, preview device scope, then run AD unjoin, Entra join, Microsoft 365 app reset, restart, and escrow verification.Per-device readiness, current operation, conversion state, validation, BitLocker escrow confirmation, and acceptance sign-off.Supported; runs against a customer-built provisioning package with dry-run preview, per-device SYSTEM agent, and BitLocker escrow verification before acceptance.
IIS and SQL ServerOperators submit server pairs, run preflight, confirm destructive replacement when requested, and start agent-executed IIS or database moves.Live server-pair progress, preflight blocks, migrated objects, warnings, failures, and terminal summaries.Supported; TLS private keys stay manual, TDE and downgrade blocks apply, and SQL agents need scoped sysadmin — all enforced as preflight gates.

Review exact prerequisites and exclusions by workload

Deployment

Place each component where it belongs.

The control plane coordinates work and retains operational metadata. Agents perform approved directory operations from the customer network. Cloud engines access Microsoft services through customer-consented applications and approved outbound routes.

Control plane

SaaS or self-hosted

Portal, APIs, job orchestration, workers, configuration, operational metadata, reporting, audit, telemetry, and operator access.

Directory execution

Customer network agents

Outbound control-plane communication and customer-approved LDAP, LDAPS, and resource access for assigned operations.

Cloud execution

Microsoft Graph services

Customer-consented source and destination connections for enabled Entra ID and Microsoft 365 workload operations.

Control evidence

Answer what happened without reading raw logs.

Operators, migration leads, security teams, and business owners need different evidence from the same program record.

Supported · Operator

Execution state

  • Connection, agent, job, stage, and item status
  • Retries, skips, failures, warnings, and progress counters
  • Pause, resume, cancellation, and recovery decisions
Controlled pilot · Migration lead

Acceptance state

  • Scope version, options, mappings, and prerequisite gates
  • Baseline, delta, cutover, reconciliation, and remediation
  • Wave thresholds, stop conditions, and rollback ownership
Manual / planned · Assurance

Decision trail

  • Role and operator actions with correlation IDs
  • Hash-chain audit verification and export
  • Completion evidence and formal sign-off record

Evaluate against your topology, not a generic demo tenant.

Bring your forests, trusts, object counts, target model, constraints, and success criteria to a technical session.

Plan the session