Choosing an ADMT alternative for Active Directory migration.
The Active Directory Migration Tool moved a generation of forests, but it has not been updated for modern hybrid environments. This guide covers where ADMT stops, what a replacement must actually do, and how to evaluate an ADMT alternative without inheriting hidden risk.
Where ADMT stops.
ADMT 3.2 is the final release. It solved a specific problem — moving users, groups, computers, and SID history between on-premises forests — in an era before hybrid identity existed. The gaps below are structural, not bugs.
- No cloud coverage: Entra ID, Exchange Online, SharePoint, OneDrive, and Teams are entirely out of scope
- No modern assessment stage: it migrates what you point it at, without readiness findings, dependency analysis, or remediation queues
- Console-bound execution: no REST API, no webhooks, no integration with ITSM or delivery pipelines
- Thin evidence: per-wizard logs rather than a verifiable, exportable audit trail suitable for security review or compliance sign-off
- Aging prerequisites: SQL Server dependency, Password Export Server, and OS-version constraints that fall outside current support baselines
- No coexistence model for programs that run source and target in parallel over weeks or months
What to require from a replacement.
Evaluate any ADMT alternative — including BridgeAD — against the full delivery lifecycle, not a feature checklist. These are the capabilities that determine whether a migration program is controllable.
| Capability | Why it matters | How BridgeAD covers it |
|---|---|---|
| Read-only discovery and assessment | You cannot scope waves, spot collisions, or price remediation from a spreadsheet export. | Read-only inventory produces ready, review, remediation, and deferred findings before any change is planned. |
| Object mapping with validation | Duplicate accounts and UPN collisions found during execution become outages. | CSV-driven and rule-based mapping with duplicate detection and target validation before scope freeze. |
| Dry-run staging | The first time a change is applied should never be the first time it is evaluated. | Dry runs validate scope, mappings, options, and detectable conflicts without applying destination changes. |
| SID history and ACL workflows | Resource access continuity is the highest-risk part of a cross-forest move. | SID mapping, SID-history, and ACL orchestration are included and executed as controlled-pilot capabilities with representative validation, because they depend on elevated rights, security approval, and reachable resources. |
| Rollback controls | Reversibility differs by operation; pretending otherwise transfers risk to the operator. | State recording plus rollback controls, with pilot-defined boundaries for what reverses automatically versus by runbook. |
| Audit evidence | Security and compliance teams need proof, not console screenshots. | Hash-chain verified audit records, exportable mappings, reconciliation reports, and completion evidence. |
| Microsoft 365 continuity | Most AD programs today are the first phase of a broader tenant or workload move. | The same platform assesses and migrates Entra ID, Exchange Online, SharePoint, OneDrive, and Teams within documented scopes and exclusions. |
How to run the comparison honestly.
A tool evaluation that skips the environment always produces the wrong answer. Run the comparison against your actual topology.
Common questions.
Is ADMT still supported by Microsoft?
ADMT 3.2 is the final release and has not received a functional update in over a decade. It was designed for on-premises inter-forest and intra-forest migration on server versions of its era, and Microsoft has not extended it for current hybrid identity or Microsoft 365 scenarios. Organizations still run it, but they carry the validation burden themselves.
Can ADMT migrate Microsoft 365 workloads?
No. ADMT operates only on on-premises Active Directory objects and workstation resources. Entra ID objects, Exchange Online mailboxes, SharePoint and OneDrive content, and Microsoft Teams are entirely outside its scope and require separate tooling.
Does BridgeAD replace every ADMT function on day one?
BridgeAD covers AD discovery, assessment, mapping, dry runs, and orchestrated execution including SID history and ACL workflows, executed as a controlled pilot with acceptance and rollback evidence. Automated workstation rejoin and profile migration are planned and are currently assigned to a separate endpoint workstream.
See what your migration actually depends on.
Bring one forest pair to a scoped readiness assessment. You get findings, mappings, risks, and a pilot boundary — evidence you can use whether or not you choose BridgeAD.
