
Move from Microsoft Identity Manager (MIM) and other legacy IAM platforms to a modern, cloud aligned identity governance model safely, efficiently, and without disruption.
Supports all stages of the Microsoft 365 journey:
- M365 E3: foundational lifecycle automation
- M365 E5: advanced identity protection and governance
- M365 E7: comprehensive governance across human, workload and AI/agent identities
Identity Governance and Entra Suite capabilities can also be licensed as standalone add-ons.
This solution is designed for organisations that need to:
- Operate a legacy or custom IAM solution, such as MIM, SailPoint, ForgeRock, Okta or NetIQ, that is increasingly complex to maintain
- Address Microsoft Identity Manager (MIM) end of support (January 2029) and related platform risk
- Remove SharePoint 2016/2019 dependencies approaching end of life
- Reduce operational risk and reliance on bespoke configurations and hard to source specialist skillsets
- Consolidate identity tooling to simplify architecture and reduce licensing and support costs
- Modernise joiner, mover, leaver (JML) processes to improve identity accuracy, governance, and automation
- Establish a modern identity foundation that supports AI driven automation
“I can honestly say working with Condatis has been a great experience from start to finish. I’ve worked with many vendors over the years, and this has been one of the best engagements I’ve experienced. Aside from the competence of your team in delivering on time and on budget the integration of Condatis into our project team was such an easy and pleasurable process. I particularly liked how open and collaborative everyone in the team was and in particular the ability to see the project and challenges from our perspective.”
Technical Project Manager, Brewin Dolphin

Business Challenge and Context
Many organisations still rely on ageing, heavily customised identity systems that create security, operational and financial risk
End of Support Identity Platforms
Legacy identity platforms such as MIM are already out of mainstream support, with full support ending in January 2029 – increasing exposure to security, stability, and compliance risk.
Disruption to Critical Identity Processes
Identity failures directly impact onboarding, access changes, and leaver processes – resulting in users unable to access systems, orphaned accounts, and increased attack surface.
Rising Cost and Inefficiency
Licensing, maintenance, and support costs for legacy tools continue to increase – often duplicating capabilities already available natively within Microsoft Entra.
Operational Fragility and Silent Failure
Unsupported IAM systems receive no security patches, cannot be escalated to Microsoft, and often fail without warning – leaving identity changes unprocessed and issues unnoticed.
Complex, Brittle Customisations
Hard coded flows, custom scripts, unclear data dependencies, and undocumented workflows make change slow, risky, and dependent on a small number of specialists.
Modern Identity Controls Disconnection
Legacy IAM platforms do not integrate with modern security and governance capabilities such as Conditional Access, MFA, risk based policies, dynamic groups, Purview/DLP, or AI governance.
Our solution
Condatis delivers controlled, low risk migrations from MIM and legacy IAM
platforms to Microsoft Entra, using a proven, staged approach that minimises
disruption.
What We Deliver
- Full assessment of your current identity platform and all traditional/non traditional use cases
- Mapping of legacy functionality to Entra capabilities
- A clear, de-risked migration roadmap
- Parallel running of old and new systems to prevent service interruption
- Staged transition of identity flows, applications and business units
- Safe retirement and cleanup of legacy IAM infrastructure
Core Entra Capabilities Used in Migration
- Lifecycle Workflows (automated JML)
- Access Packages & Catalogues
- Dynamic Groups
- Conditional Access & MFA
- Identity Governance • HR → Entra attribute lifecycle
- Azure SQL / Data Lake intermediary stores
- AI/agent identity governance (E7)
Condatis Services
- IAM analyst call (30-minute complimentary session)
- Discovery Lite (60–120-minute remote session)
- Discovery Workshop (deep dive architecture and maturity assessment)
- Proof of Concept (targeted validation of specific Entra capabilities)
- Production ready MVP
- Full implementation & decommissioning
Our Proven Migration Methodology
These phases describe how we deliver a full migration programme. Each customer engagement (Discovery → Workshop → PoC → MVP → Full Implementation) enters this lifecycle at the appropriate point and scales as needed.
Stage
What This Delivers
01
Identify Requirements
Analyse your identity platform, including:
- Attribute management
- GAL synchronisation
- Custom provisioning flows
- Multi directory environments
- Traditional & non traditional MIM use cases
02
Define Core Modern Identity Platform
Establish the minimal Entra configuration required to safely run in parallel with your existing system, including:
- Lifecycle Workflows
- Access Packages & Catalogues
- Dynamic Groups
- Conditional Access & MFA policies
- Intermediary data store design
03
Move to Parallel Running
Stand up Entra alongside your current platform so both operate at the same time, ensuring:
- New starters continue onboarding
- Movers and leavers process correctly
- Policies and access controls behave as expected
04
Staged Transfer of Responsibility
Move identities, applications or business units in structured cohorts, avoiding the operational failures and legal issues caused by “big bang” changes.
05
Decommission & Clean Up
Safely retire the legacy IAM platform once all identities and processes have migrated, removing operational risk, cost and technical debt.
Business Impact and Outcomes
Security & Governance
- Remove unsupported and high risk identity platforms
- Reduce vulnerability exposure
- Modern MFA, CA, PIM and governance
- Ensure compliance with identity and data regulations
Operational Efficiency
- Faster onboarding and identity lifecycle changes
- Reduced dependency on scarce legacy skills
- Parallel running eliminates disruption
- Improved data accuracy and process reliability
Cost Reduction
- Retire expensive legacy IAM tooling
- Reduce licensing and support overhead
- Decommission on prem infrastructure
- Leverage capabilities already included in M365
Future Ready Identity
- Integrated lifecycle automation
- Access governance aligned with Microsoft standards
- Foundation for Copilot and AI agent identity governance
Let’s talk.
Start your journey with a free briefing
Sense-check your identity approach, discuss challenges, and get practical guidance on governance, security, and modern identity, with a dedicated Condatis specialist.
Get in touch
Move from Microsoft Identity Manager (MIM) and other legacy IAM platforms to a modern, cloud aligned identity governance model safely, efficiently, and without disruption.
Supports all stages of the Microsoft 365 journey:
- M365 E3: foundational lifecycle automation
- M365 E5: advanced identity protection and governance
- M365 E7: comprehensive governance across human, workload and AI/agent identities
Identity Governance and Entra Suite capabilities can also be licensed as standalone add-ons.
This solution is designed for organisations that need to:
- Operate a legacy or custom IAM solution, such as MIM, SailPoint, ForgeRock, Okta or NetIQ, that is increasingly complex to maintain
- Address Microsoft Identity Manager (MIM) end of support (January 2029) and related platform risk
- Remove SharePoint 2016/2019 dependencies approaching end of life
- Reduce operational risk and reliance on bespoke configurations and hard to source specialist skillsets
- Consolidate identity tooling to simplify architecture and reduce licensing and support costs
- Modernise joiner, mover, leaver (JML) processes to improve identity accuracy, governance, and automation
- Establish a modern identity foundation that supports AI driven automation
“I can honestly say working with Condatis has been a great experience from start to finish. I’ve worked with many vendors over the years, and this has been one of the best engagements I’ve experienced. Aside from the competence of your team in delivering on time and on budget the integration of Condatis into our project team was such an easy and pleasurable process. I particularly liked how open and collaborative everyone in the team was and in particular the ability to see the project and challenges from our perspective.”
Technical Project Manager, Brewin Dolphin

Business Challenge and Context
Many organisations still rely on ageing, heavily customised identity systems that create security, operational and financial risk
End of Support Identity Platforms
Legacy identity platforms such as MIM are already out of mainstream support, with full support ending in January 2029 – increasing exposure to security, stability, and compliance risk.
Disruption to Critical Identity Processes
Identity failures directly impact onboarding, access changes, and leaver processes – resulting in users unable to access systems, orphaned accounts, and increased attack surface.
Rising Cost and Inefficiency
Licensing, maintenance, and support costs for legacy tools continue to increase – often duplicating capabilities already available natively within Microsoft Entra.
Operational Fragility and Silent Failure
Unsupported IAM systems receive no security patches, cannot be escalated to Microsoft, and often fail without warning – leaving identity changes unprocessed and issues unnoticed.
Complex, Brittle Customisations
Hard coded flows, custom scripts, unclear data dependencies, and undocumented workflows make change slow, risky, and dependent on a small number of specialists.
Modern Identity Controls Disconnection
Legacy IAM platforms do not integrate with modern security and governance capabilities such as Conditional Access, MFA, risk based policies, dynamic groups, Purview/DLP, or AI governance.
Our solution
Condatis delivers controlled, low risk migrations from MIM and legacy IAM
platforms to Microsoft Entra, using a proven, staged approach that minimises
disruption.
What We Deliver
- Full assessment of your current identity platform and all traditional/non traditional use cases
- Mapping of legacy functionality to Entra capabilities
- A clear, de-risked migration roadmap
- Parallel running of old and new systems to prevent service interruption
- Staged transition of identity flows, applications and business units
- Safe retirement and cleanup of legacy IAM infrastructure
Core Entra Capabilities Used in Migration
- Lifecycle Workflows (automated JML)
- Access Packages & Catalogues
- Dynamic Groups
- Conditional Access & MFA
- Identity Governance • HR → Entra attribute lifecycle
- Azure SQL / Data Lake intermediary stores
- AI/agent identity governance (E7)
Condatis Services
- IAM analyst call (30-minute complimentary session)
- Discovery Lite (60–120-minute remote session)
- Discovery Workshop (deep dive architecture and maturity assessment)
- Proof of Concept (targeted validation of specific Entra capabilities)
- Production ready MVP
- Full implementation & decommissioning
Our Proven Migration Methodology
These phases describe how we deliver a full migration programme. Each customer engagement (Discovery → Workshop → PoC → MVP → Full Implementation) enters this lifecycle at the appropriate point and scales as needed.
Stage
What This Delivers
01
Identify Requirements
Analyse your identity platform, including:
- Attribute management
- GAL synchronisation
- Custom provisioning flows
- Multi directory environments
- Traditional & non traditional MIM use cases
02
Define Core Modern Identity Platform
Establish the minimal Entra configuration required to safely run in parallel with your existing system, including:
- Lifecycle Workflows
- Access Packages & Catalogues
- Dynamic Groups
- Conditional Access & MFA policies
- Intermediary data store design
03
Move to Parallel Running
Stand up Entra alongside your current platform so both operate at the same time, ensuring:
- New starters continue onboarding
- Movers and leavers process correctly
- Policies and access controls behave as expected
04
Staged Transfer of Responsibility
Move identities, applications or business units in structured cohorts, avoiding the operational failures and legal issues caused by “big bang” changes.
05
Decommission & Clean Up
Safely retire the legacy IAM platform once all identities and processes have migrated, removing operational risk, cost and technical debt.
Business Impact and Outcomes
Security & Governance
- Remove unsupported and high risk identity platforms
- Reduce vulnerability exposure
- Modern MFA, CA, PIM and governance
- Ensure compliance with identity and data regulations
Operational Efficiency
- Faster onboarding and identity lifecycle changes
- Reduced dependency on scarce legacy skills
- Parallel running eliminates disruption
- Improved data accuracy and process reliability
Cost Reduction
- Retire expensive legacy IAM tooling
- Reduce licensing and support overhead
- Decommission on prem infrastructure
- Leverage capabilities already included in M365
Future Ready Identity
- Integrated lifecycle automation
- Access governance aligned with Microsoft standards
- Foundation for Copilot and AI agent identity governance
Let’s talk.
Start your journey with a free briefing
Sense-check your identity approach, discuss challenges, and get practical guidance on governance, security, and modern identity, with a dedicated Condatis specialist.
Get in touch
Protecting organisations, connecting people.
Condatis is your partner in Identity and Access Management



















