Guide

Choosing an ADMT alternative for Active Directory migration.

The Active Directory Migration Tool moved a generation of forests, but it has not been updated for modern hybrid environments. This guide covers where ADMT stops, what a replacement must actually do, and how to evaluate an ADMT alternative without inheriting hidden risk.

Honest framingAny vendor claiming a "click-and-done" ADMT replacement is hiding the topology work. Migration outcomes always depend on trusts, DNS, security policy, and application behavior — the question is whether your tool makes those dependencies visible before execution.
The gap

Where ADMT stops.

ADMT 3.2 is the final release. It solved a specific problem — moving users, groups, computers, and SID history between on-premises forests — in an era before hybrid identity existed. The gaps below are structural, not bugs.

  • No cloud coverage: Entra ID, Exchange Online, SharePoint, OneDrive, and Teams are entirely out of scope
  • No modern assessment stage: it migrates what you point it at, without readiness findings, dependency analysis, or remediation queues
  • Console-bound execution: no REST API, no webhooks, no integration with ITSM or delivery pipelines
  • Thin evidence: per-wizard logs rather than a verifiable, exportable audit trail suitable for security review or compliance sign-off
  • Aging prerequisites: SQL Server dependency, Password Export Server, and OS-version constraints that fall outside current support baselines
  • No coexistence model for programs that run source and target in parallel over weeks or months
Requirements

What to require from a replacement.

Evaluate any ADMT alternative — including BridgeAD — against the full delivery lifecycle, not a feature checklist. These are the capabilities that determine whether a migration program is controllable.

CapabilityWhy it mattersHow BridgeAD covers it
Read-only discovery and assessmentYou cannot scope waves, spot collisions, or price remediation from a spreadsheet export.Read-only inventory produces ready, review, remediation, and deferred findings before any change is planned.
Object mapping with validationDuplicate accounts and UPN collisions found during execution become outages.CSV-driven and rule-based mapping with duplicate detection and target validation before scope freeze.
Dry-run stagingThe first time a change is applied should never be the first time it is evaluated.Dry runs validate scope, mappings, options, and detectable conflicts without applying destination changes.
SID history and ACL workflowsResource access continuity is the highest-risk part of a cross-forest move.SID mapping, SID-history, and ACL orchestration are included and executed as controlled-pilot capabilities with representative validation, because they depend on elevated rights, security approval, and reachable resources.
Rollback controlsReversibility differs by operation; pretending otherwise transfers risk to the operator.State recording plus rollback controls, with pilot-defined boundaries for what reverses automatically versus by runbook.
Audit evidenceSecurity and compliance teams need proof, not console screenshots.Hash-chain verified audit records, exportable mappings, reconciliation reports, and completion evidence.
Microsoft 365 continuityMost AD programs today are the first phase of a broader tenant or workload move.The same platform assesses and migrates Entra ID, Exchange Online, SharePoint, OneDrive, and Teams within documented scopes and exclusions.
Evaluation path

How to run the comparison honestly.

A tool evaluation that skips the environment always produces the wrong answer. Run the comparison against your actual topology.

InventoryRead-only discovery of both forests and any connected tenants.
FindingsReview readiness, remediation, and deferred items against your timeline.
Dry runStage a representative scope and inspect every planned change.
Bounded pilotMigrate a small wave with acceptance criteria and rollback ownership.
DecideExpand scope only after the pilot evidence supports it.
FAQ

Common questions.

Is ADMT still supported by Microsoft?

ADMT 3.2 is the final release and has not received a functional update in over a decade. It was designed for on-premises inter-forest and intra-forest migration on server versions of its era, and Microsoft has not extended it for current hybrid identity or Microsoft 365 scenarios. Organizations still run it, but they carry the validation burden themselves.

Can ADMT migrate Microsoft 365 workloads?

No. ADMT operates only on on-premises Active Directory objects and workstation resources. Entra ID objects, Exchange Online mailboxes, SharePoint and OneDrive content, and Microsoft Teams are entirely outside its scope and require separate tooling.

Does BridgeAD replace every ADMT function on day one?

BridgeAD covers AD discovery, assessment, mapping, dry runs, and orchestrated execution including SID history and ACL workflows, executed as a controlled pilot with acceptance and rollback evidence. Automated workstation rejoin and profile migration are planned and are currently assigned to a separate endpoint workstream.

See what your migration actually depends on.

Bring one forest pair to a scoped readiness assessment. You get findings, mappings, risks, and a pilot boundary — evidence you can use whether or not you choose BridgeAD.

Request an assessment