Mailbox migration — any source, any target

Exchange Online mailbox migration, extended any-to-any.

BridgeAD delivers Exchange Online mailbox migration between tenants and extends it across providers — Gmail, IMAP hosts, on-premises Exchange (EWS), and PST/EML archives — over one certified canonical engine. Exchange tenant-to-tenant copies mail, owned calendars, contacts, tasks, rules, selected sharing permissions, and mailbox settings through Microsoft Graph. Operators can verify each mailbox, resume interrupted work, run delta passes, reconcile outcomes, and check public DNS before source retirement. As an Exchange migration tool it treats every Exchange Online migration — mailbox by mailbox — as resumable, verifiable work.

Supported Microsoft 365 tenant-to-tenantThe automated path covers mailbox content in Exchange Online. On-premises Exchange must first be onboarded through a supported Microsoft migration or hybrid path. Archives, public folders, and mailbox delegation require separate handling.
BridgeAD Cloud WorkloadsMailbox migration workspace
BridgeAD Cloud Workloads workspace showing mailbox programme phases, migration metrics, workload health, progress, throughput, and job status
Mailbox waves measured through reconciliationScope, throughput, delta passes, exceptions, cutover readiness, and completion evidence remain measurable from pilot through final validation.
Product view · synthetic demonstration data
Operator experience

Control the mailbox move at item level.

Connections, mailbox mappings, readiness checks, job state, and reports are kept together. A failed mailbox does not erase the rest of the wave, and the operator can inspect or retry the affected item without restarting completed mailboxes.

  • Source and destination connection health checks
  • Mailbox discovery, CSV mappings, and destination verification
  • Start, pause, cancel, retry, and resumable execution
  • Baseline and delta-run counters with per-mailbox errors
  • Folder-count and calendar-permission comparison reports
  • Completion certificate with job facts and verification digest
Capability scope

Know exactly which mailbox artifacts move.

BridgeAD uses idempotent Graph operations and records source and destination identifiers so retries can continue safely. Optional artifacts can be disabled when the tenant has not granted the corresponding Graph application permission.

Exchange capability scope and status
AreaStatusBridgeAD handlingImportant boundary
Mail and foldersSupportedCopies messages into the destination folder hierarchy with body, recipients, dates, read state, importance, flags, categories, and supported attachments.Per-folder delta links reduce repeat enumeration. Unsupported or oversized attachments are reported at item level.
CalendarsSupportedCopies owned default and additional calendars, events, recurrence, reminders, categories, and supported meeting fields.Calendars owned by another user migrate with that owner. Tenant-scoped meeting links can require reissue.
Contacts and tasksSupportedCopies root contacts, nested contact folders, and Microsoft To Do lists and tasks.Tasks require the relevant Graph application permission; unavailable task access degrades with a reported warning.
Rules and settingsSupported · OptionalCopies supported inbox rules and mailbox settings such as automatic replies, time zone, language, date/time formats, and working hours.Tenant policies and transport rules are organization configuration, not mailbox content.
Calendar sharingSupported · OptionalMaps and applies non-default calendar principals where the destination identity resolves.Unresolved principals are reported. Full Access, Send As, Send on Behalf, and broader mailbox delegation are separate.
Delta and reconciliationSupportedPersists processed IDs and mail delta tokens, prepares follow-up passes, compares folder counts, and exports permission variance.A completed copy still requires review of failed, skipped, or unresolved outcomes before sign-off.
DNS cutoverSupported · ValidationChecks public MX, SPF, DKIM selectors, DMARC, and Autodiscover records against Microsoft 365 expectations.BridgeAD reports DNS state; it does not change registrar or DNS-provider configuration.
Prerequisites

Prepare the destination before copying content.

The migration engine cannot compensate for an unprovisioned mailbox, an unresolved identity, missing application consent, or a cutover plan with no mail-flow owner.

01 / Tenant access

Microsoft Graph application

  • Source read and destination write permissions approved
  • Credentials stored in the configured secret store
  • Connection health and exact mailbox query shape tested
02 / Mailbox readiness

Destination objects and licensing

  • Destination identities and UPN mappings agreed
  • User mailboxes licensed and provisioned
  • Shared, room, and equipment purpose verified
03 / Change readiness

Wave, coexistence, and DNS plan

  • Baseline and final-delta windows approved
  • MX and Autodiscover change ownership assigned
  • Rollback, support, and unresolved-item decisions documented
Migration workflow

Reduce the final window with staged passes.

The same job can establish a baseline, retain progress state, and prepare a delta pass. The cutover decision is informed by mailbox-level outcomes rather than a single aggregate percentage.

01

Connect

Validate Graph credentials, tenant reachability, mailbox access, and optional task permissions.

02

Map

Discover mailboxes, import or edit source-to-target UPN mappings, and verify destination readiness.

03

Baseline

Copy selected mailbox artifacts in waves with retries, checkpoints, and item-level telemetry.

04

Delta and cutover

Copy changes since the baseline, validate DNS, and switch mail flow under the approved change plan.

05

Reconcile

Compare folders and permissions, resolve exceptions, record sign-off, and retain completion evidence.

Delivery boundaries

Content migration does not move tenant configuration.

These boundaries are part of the migration plan, not footnotes. BridgeAD reports what its Graph path handles so administrators can assign every remaining task to Microsoft-native tooling or a named owner.

Supported · Automated scope

Mailbox content and validation

  • Mail, folders, calendars, contacts, and tasks
  • In-place archive mailbox content and public-folder hierarchy (via the certified EWS route)
  • Optional rules, settings, and calendar sharing
  • Delta passes, reconciliation, and DNS readiness
Microsoft-native path · Coordinated in the plan

Mailbox anchoring and hybrid moves

  • On-premises mailbox onboarding or hybrid MRS moves (BridgeAD migrates the content; Microsoft tooling moves the mailbox anchor)
  • Mail-flow coexistence during staged cutover
Administrator owned · Guided by the plan

Organization configuration

  • Mailbox delegation and send permissions (reported for re-grant; calendar sharing carries where supported)
  • Transport, journaling, retention, holds, and DLP policy design
  • DNS registrar changes, license purchasing, and source retirement decisions — BridgeAD validates DNS readiness and reports completion evidence
Any-to-any mailbox migration

One canonical model, routes released by certification.

The mailbox engine is route-based: every source and target sits behind a provider adapter over a standards-based canonical model (MIME, iCalendar, vCard) with a structured sidecar for what the interchange format cannot carry. New routes ship only after their adapter passes a golden-mailbox conformance kit against live sandboxes — so the supported route catalog stays explicit, never assumed. Mailbox content is streamed, never stored; only hashes, identifiers, and metadata persist.

Mailbox migration route certification
RouteStatusAvailability
Exchange Online → Exchange OnlineSupportedCertified and available now — the production tenant-to-tenant path covered by this page.
Google Workspace (Gmail) → Exchange OnlineSupportedCertified and available now — adapter certified against live Google Workspace environments. Runs on customer-supplied Google credentials with a signed fidelity contract per job.
Exchange Online → Google Workspace (Gmail)SupportedCertified and available now — Gmail import preserves original dates; calendar and contacts map per the route's fidelity contract.
IMAP → Exchange OnlineSupportedCertified and available now — covers long-tail IMAP hosts. Mail content only, per the route's fidelity contract.
Zoho Mail → Exchange OnlineSupportedCertified and available now — runs over Zoho's IMAP access with per-mailbox app passwords; regional Zoho data centres (US, EU, India, Australia) supported. Mail content only, per the route's fidelity contract.
Exchange Online → Zoho MailSupportedCertified and available now — verbatim MIME appended over IMAP with original dates and read state preserved. Mail content only, per the route's fidelity contract.
Gmail → Zoho MailSupportedCertified and available now — direct route with no Microsoft 365 hop: full-fidelity MIME fetched with customer Google credentials, appended over Zoho IMAP with original dates. Mail content only, per the route's fidelity contract.
Zoho Mail → GmailSupportedCertified and available now — direct route: mail fetched over Zoho IMAP and imported into Gmail with labels and original dates. Mail content only, per the route's fidelity contract.
Exchange on-premises (EWS) → Exchange OnlineSupportedCertified and available now — EWS protocol certified against live Exchange; modern (OAuth) and classic (Basic/NTLM) authentication both supported. Mail content only.
Exchange Online ↔ PST / EML archiveSupportedCertified and available now in both directions — archives live in customer-controlled storage only, with offline-verifiable custody hashes proving the round-trip; the platform never stores mailbox content.

Every route above is certified against live systems, and each cross-provider job runs under a signed fidelity contract. Tell us your source and target — migrations are scheduled with your team.

Fidelity & evidence

Every cross-provider job is signed off before it starts.

What other tools leave as a caveat in a knowledge-base article, BridgeAD turns into a contractual line you review and approve. These controls run on the canonical cross-provider engine as routes certify.

Supported

Signed fidelity contract

  • Generated from the route's fidelity policy and the actual mailbox probe
  • Hash-bound and approved before the job can start
  • Changing job options invalidates the contract until re-approved
Supported

Chain-of-custody evidence

  • Each item hashed at source and re-read and verified at target
  • Batches sealed into Merkle-rooted, hash-chained, tamper-evident records
  • Exportable as an offline-verifiable evidence pack
Supported

Adaptive, self-healing delivery

  • Throttle-adaptive scheduling backs off on provider rate limits
  • Typed failure triage applies a fixed remediation catalog
  • No silent loss — every skip is recorded against its contract line
Frequently asked questions

Exchange migration questions

Can BridgeAD migrate directly from on-premises Exchange?

The automated mailbox-content path is designed for Exchange Online between Microsoft 365 tenants. An on-premises source must first be moved or hybrid-onboarded through a supported Microsoft path; that prerequisite is scoped separately.

How does an interrupted mailbox resume?

BridgeAD persists processed source IDs, created destination IDs, and per-folder mail delta links. Saga steps are designed to tolerate retries, allowing the job to continue without intentionally duplicating already processed content.

Does a delta pass include every mailbox artifact?

Mail uses Graph delta links. Other selected artifacts use persisted idempotency state and source identifiers. The resulting pass and any warnings are shown per mailbox and should be reviewed before cutover approval.

Does BridgeAD change DNS records?

No. It reads public DNS and reports MX, SPF, DKIM, DMARC, and Autodiscover readiness. A customer or managed-service change owner remains responsible for publishing and approving DNS changes.

What evidence is available after completion?

Operators can export mappings, mailbox verification, folder reconciliation, calendar-permission comparison, job outcomes, and a completion certificate containing job facts and a SHA-256 verification digest.

Build a mailbox wave from verified scope.

Bring mailbox counts, source and destination tenants, required artifacts, DNS ownership, and the desired cutover window.