Regulated self-hosted delivery

Run the control plane inside customer-managed infrastructure.

Deploy BridgeAD in customer-managed Azure, Kubernetes, or Docker infrastructure and document who owns identity, secrets, backups, monitoring, updates, incident response, and egress.

Important boundarySelf-hosted does not mean air-gapped Microsoft 365 migration. Enabled cloud workloads still require approved outbound access to Microsoft APIs.
Design review

Agree the responsibility model before installation.

A self-hosted deployment changes operational ownership. It does not by itself provide certification, eliminate cloud dependencies, or make every product capability available.

  • Infrastructure subscription, cluster, host, and network ownership
  • Identity provider, privileged roles, MFA, and break-glass access
  • Secret store, key rotation, and credential recovery
  • Database, backup, restore verification, and retention
  • Observability, alert routing, and incident response
  • Release promotion, update signing, and maintenance windows
  • Agent-to-control-plane and agent-to-directory network paths
  • Microsoft API endpoints required by approved cloud scope
Customer zone

Control plane

Portal, API, workers, database, message infrastructure, secrets, telemetry, and backups.

Directory zone

Execution agent

Outbound HTTPS to the control plane and approved LDAP access to domain controllers.

Optional cloud path

Microsoft APIs

Approved outbound TLS for Entra ID or enabled Microsoft 365 assessment operations.

Bring the target hosting standard to the review.

We will map deployment assumptions to customer controls, operating owners, and current product status.

Schedule architecture review