Microsoft Graph application
- Source read and destination write permissions approved
- Credentials stored in the configured secret store
- Connection health and exact mailbox query shape tested
BridgeAD delivers Exchange Online mailbox migration between tenants and extends it across providers — Gmail, IMAP hosts, on-premises Exchange (EWS), and PST/EML archives — over one certified canonical engine. Exchange tenant-to-tenant copies mail, owned calendars, contacts, tasks, rules, selected sharing permissions, and mailbox settings through Microsoft Graph. Operators can verify each mailbox, resume interrupted work, run delta passes, reconcile outcomes, and check public DNS before source retirement. As an Exchange migration tool it treats every Exchange Online migration — mailbox by mailbox — as resumable, verifiable work.
Connections, mailbox mappings, readiness checks, job state, and reports are kept together. A failed mailbox does not erase the rest of the wave, and the operator can inspect or retry the affected item without restarting completed mailboxes.
BridgeAD uses idempotent Graph operations and records source and destination identifiers so retries can continue safely. Optional artifacts can be disabled when the tenant has not granted the corresponding Graph application permission.
| Area | Status | BridgeAD handling | Important boundary |
|---|---|---|---|
| Mail and folders | Supported | Copies messages into the destination folder hierarchy with body, recipients, dates, read state, importance, flags, categories, and supported attachments. | Per-folder delta links reduce repeat enumeration. Unsupported or oversized attachments are reported at item level. |
| Calendars | Supported | Copies owned default and additional calendars, events, recurrence, reminders, categories, and supported meeting fields. | Calendars owned by another user migrate with that owner. Tenant-scoped meeting links can require reissue. |
| Contacts and tasks | Supported | Copies root contacts, nested contact folders, and Microsoft To Do lists and tasks. | Tasks require the relevant Graph application permission; unavailable task access degrades with a reported warning. |
| Rules and settings | Supported · Optional | Copies supported inbox rules and mailbox settings such as automatic replies, time zone, language, date/time formats, and working hours. | Tenant policies and transport rules are organization configuration, not mailbox content. |
| Calendar sharing | Supported · Optional | Maps and applies non-default calendar principals where the destination identity resolves. | Unresolved principals are reported. Full Access, Send As, Send on Behalf, and broader mailbox delegation are separate. |
| Delta and reconciliation | Supported | Persists processed IDs and mail delta tokens, prepares follow-up passes, compares folder counts, and exports permission variance. | A completed copy still requires review of failed, skipped, or unresolved outcomes before sign-off. |
| DNS cutover | Supported · Validation | Checks public MX, SPF, DKIM selectors, DMARC, and Autodiscover records against Microsoft 365 expectations. | BridgeAD reports DNS state; it does not change registrar or DNS-provider configuration. |
The migration engine cannot compensate for an unprovisioned mailbox, an unresolved identity, missing application consent, or a cutover plan with no mail-flow owner.
The same job can establish a baseline, retain progress state, and prepare a delta pass. The cutover decision is informed by mailbox-level outcomes rather than a single aggregate percentage.
Validate Graph credentials, tenant reachability, mailbox access, and optional task permissions.
Discover mailboxes, import or edit source-to-target UPN mappings, and verify destination readiness.
Copy selected mailbox artifacts in waves with retries, checkpoints, and item-level telemetry.
Copy changes since the baseline, validate DNS, and switch mail flow under the approved change plan.
Compare folders and permissions, resolve exceptions, record sign-off, and retain completion evidence.
These boundaries are part of the migration plan, not footnotes. BridgeAD reports what its Graph path handles so administrators can assign every remaining task to Microsoft-native tooling or a named owner.
The mailbox engine is route-based: every source and target sits behind a provider adapter over a standards-based canonical model (MIME, iCalendar, vCard) with a structured sidecar for what the interchange format cannot carry. New routes ship only after their adapter passes a golden-mailbox conformance kit against live sandboxes — so the supported route catalog stays explicit, never assumed. Mailbox content is streamed, never stored; only hashes, identifiers, and metadata persist.
| Route | Status | Availability |
|---|---|---|
| Exchange Online → Exchange Online | Supported | Certified and available now — the production tenant-to-tenant path covered by this page. |
| Google Workspace (Gmail) → Exchange Online | Supported | Certified and available now — adapter certified against live Google Workspace environments. Runs on customer-supplied Google credentials with a signed fidelity contract per job. |
| Exchange Online → Google Workspace (Gmail) | Supported | Certified and available now — Gmail import preserves original dates; calendar and contacts map per the route's fidelity contract. |
| IMAP → Exchange Online | Supported | Certified and available now — covers long-tail IMAP hosts. Mail content only, per the route's fidelity contract. |
| Zoho Mail → Exchange Online | Supported | Certified and available now — runs over Zoho's IMAP access with per-mailbox app passwords; regional Zoho data centres (US, EU, India, Australia) supported. Mail content only, per the route's fidelity contract. |
| Exchange Online → Zoho Mail | Supported | Certified and available now — verbatim MIME appended over IMAP with original dates and read state preserved. Mail content only, per the route's fidelity contract. |
| Gmail → Zoho Mail | Supported | Certified and available now — direct route with no Microsoft 365 hop: full-fidelity MIME fetched with customer Google credentials, appended over Zoho IMAP with original dates. Mail content only, per the route's fidelity contract. |
| Zoho Mail → Gmail | Supported | Certified and available now — direct route: mail fetched over Zoho IMAP and imported into Gmail with labels and original dates. Mail content only, per the route's fidelity contract. |
| Exchange on-premises (EWS) → Exchange Online | Supported | Certified and available now — EWS protocol certified against live Exchange; modern (OAuth) and classic (Basic/NTLM) authentication both supported. Mail content only. |
| Exchange Online ↔ PST / EML archive | Supported | Certified and available now in both directions — archives live in customer-controlled storage only, with offline-verifiable custody hashes proving the round-trip; the platform never stores mailbox content. |
Every route above is certified against live systems, and each cross-provider job runs under a signed fidelity contract. Tell us your source and target — migrations are scheduled with your team.
What other tools leave as a caveat in a knowledge-base article, BridgeAD turns into a contractual line you review and approve. These controls run on the canonical cross-provider engine as routes certify.
The automated mailbox-content path is designed for Exchange Online between Microsoft 365 tenants. An on-premises source must first be moved or hybrid-onboarded through a supported Microsoft path; that prerequisite is scoped separately.
BridgeAD persists processed source IDs, created destination IDs, and per-folder mail delta links. Saga steps are designed to tolerate retries, allowing the job to continue without intentionally duplicating already processed content.
Mail uses Graph delta links. Other selected artifacts use persisted idempotency state and source identifiers. The resulting pass and any warnings are shown per mailbox and should be reviewed before cutover approval.
No. It reads public DNS and reports MX, SPF, DKIM, DMARC, and Autodiscover readiness. A customer or managed-service change owner remains responsible for publishing and approving DNS changes.
Operators can export mappings, mailbox verification, folder reconciliation, calendar-permission comparison, job outcomes, and a completion certificate containing job facts and a SHA-256 verification digest.
Mailbox cutover depends on destination identity readiness and often coincides with Teams meetings, OneDrive recordings, compliance controls, and broader tenant transition work.