Platform

A governed control plane for hybrid directory migration.

BridgeAD connects planning, operator action, on-premises execution, and evidence without hiding workload maturity or migration risk.

Current strongest fitAD discovery, object mapping, dry-run planning, controlled directory migration pilots, and audit-backed handover.
Operating model

Five stages. One decision trail.

Every stage has an owner, inputs, validation criteria, and evidence. BridgeAD is designed to make exceptions and rollback decisions visible instead of reducing migration to a copy button.

DiscoverConnections, topology, objects, dependencies.
PlanMappings, exclusions, batches, dry run.
ExecuteAgent commands, controlled jobs, recovery.
ReconcileCounts, failures, retry decisions.
ProveAudit records, exports, sign-off.
Current capability

Built around decisions migration teams make repeatedly.

Availability depends on deployment and engagement scope. Supported features can enter onboarding after configuration; controlled-pilot features require APQOR oversight and explicit rollback criteria.

  • Connection validation
    Source AD, target AD, and Entra ID connection setup with explicit permissions.
  • Read-only discovery
    Inventory OUs and directory objects before committing migration scope.
  • Object mapping
    Automatic and manual mappings, CSV import/export, duplicate checks, and validation.
  • Dry-run planning
    Test assumptions before the first controlled execution wave.
  • On-premises agent
    One outbound-only agent per connected domain in common topologies.
  • Operational control
    Job status, recovery paths, live updates, health, and metrics endpoints.
  • Governance
    Role-based access, MFA expectations, role-change traceability, and session revocation.
  • Audit evidence
    Hash-chain verification, correlation IDs, and exportable operational records.
Deployment

Place each component where it belongs.

The control plane coordinates work. The agent performs directory operations from the customer network. Cloud workloads require approved outbound access to the relevant Microsoft APIs.

Control plane

SaaS or self-hosted

Portal, job orchestration, configuration, reporting, audit metadata, and operator access.

Execution

Customer network agent

Outbound HTTPS to BridgeAD and customer-approved LDAP access to domain controllers.

Systems of record

Source and destination

Directory and approved cloud APIs remain authoritative for migrated content and objects.

Evaluate against your topology, not a generic demo tenant.

Bring your forests, trusts, object counts, target model, constraints, and success criteria to a technical session.

Plan the session