Skip to main content
man-on-phone-in-office

Move from Microsoft Identity Manager (MIM) and other legacy IAM platforms to a modern, cloud aligned identity governance model safely, efficiently, and without disruption.

Supports all stages of the Microsoft 365 journey:

  • M365 E3: foundational lifecycle automation
  • M365 E5: advanced identity protection and governance
  • M365 E7: comprehensive governance across human, workload and AI/agent identities

Identity Governance and Entra Suite capabilities can also be licensed as standalone add-ons.

This solution is designed for organisations that need to:

  • Operate a legacy or custom IAM solution, such as MIM, SailPoint, ForgeRock, Okta or NetIQ, that is increasingly complex to maintain
  • Address Microsoft Identity Manager (MIM) end of support (January 2029) and related platform risk
  • Remove SharePoint 2016/2019 dependencies approaching end of life
  • Reduce operational risk and reliance on bespoke configurations and hard to source specialist skillsets
  • Consolidate identity tooling to simplify architecture and reduce licensing and support costs
  • Modernise joiner, mover, leaver (JML) processes to improve identity accuracy, governance, and automation
  • Establish a modern identity foundation that supports AI driven automation

“I can honestly say working with Condatis has been a great experience from start to finish. I’ve worked with many vendors over the years, and this has been one of the best engagements I’ve experienced. Aside from the competence of your team in delivering on time and on budget the integration of Condatis into our project team was such an easy and pleasurable process. I particularly liked how open and collaborative everyone in the team was and in particular the ability to see the project and challenges from our perspective.”

Technical Project Manager, Brewin Dolphin

Business Challenge and Context


Many organisations still rely on ageing, heavily customised identity systems that create security, operational and financial risk

End of Support Identity Platforms

Legacy identity platforms such as MIM are already out of mainstream support, with full support ending in January 2029 – increasing exposure to security, stability, and compliance risk.

Disruption to Critical Identity Processes

Identity failures directly impact onboarding, access changes, and leaver processes – resulting in users unable to access systems, orphaned accounts, and increased attack surface.

Rising Cost and Inefficiency

Licensing, maintenance, and support costs for legacy tools continue to increase – often duplicating capabilities already available natively within Microsoft Entra.

Operational Fragility and Silent Failure

Unsupported IAM systems receive no security patches, cannot be escalated to Microsoft, and often fail without warning – leaving identity changes unprocessed and issues unnoticed.

Complex, Brittle Customisations

Hard coded flows, custom scripts, unclear data dependencies, and undocumented workflows make change slow, risky, and dependent on a small number of specialists.

Modern Identity Controls Disconnection

Legacy IAM platforms do not integrate with modern security and governance capabilities such as Conditional Access, MFA, risk based policies, dynamic groups, Purview/DLP, or AI governance.

Our solution

Condatis delivers controlled, low risk migrations from MIM and legacy IAM
platforms to Microsoft Entra, using a proven, staged approach that minimises
disruption.

What We Deliver

  • Full assessment of your current identity platform and all traditional/non traditional use cases
  • Mapping of legacy functionality to Entra capabilities
  • A clear, de-risked migration roadmap
  • Parallel running of old and new systems to prevent service interruption
  • Staged transition of identity flows, applications and business units
  • Safe retirement and cleanup of legacy IAM infrastructure

Core Entra Capabilities Used in Migration

  • Lifecycle Workflows (automated JML)
  • Access Packages & Catalogues
  • Dynamic Groups
  • Conditional Access & MFA
  • Identity Governance • HR → Entra attribute lifecycle
  • Azure SQL / Data Lake intermediary stores
  • AI/agent identity governance (E7)

Condatis Services


  • IAM analyst call (30-minute complimentary session)
  • Discovery Lite (60–120-minute remote session)
  • Discovery Workshop (deep dive architecture and maturity assessment)
  • Proof of Concept (targeted validation of specific Entra capabilities)
  • Production ready MVP
  • Full implementation & decommissioning

Our Proven Migration Methodology


These phases describe how we deliver a full migration programme. Each customer engagement (Discovery → Workshop → PoC → MVP → Full Implementation) enters this lifecycle at the appropriate point and scales as needed.

Stage

What This Delivers


01

Identify Requirements

Analyse your identity platform, including:

  • Attribute management
  • GAL synchronisation
  • Custom provisioning flows
  • Multi directory environments
  • Traditional & non traditional MIM use cases

02

Define Core Modern Identity Platform

Establish the minimal Entra configuration required to safely run in parallel with your existing system, including:

  • Lifecycle Workflows
  • Access Packages & Catalogues
  • Dynamic Groups
  • Conditional Access & MFA policies
  • Intermediary data store design

03

Move to Parallel Running

Stand up Entra alongside your current platform so both operate at the same time, ensuring:

  • New starters continue onboarding
  • Movers and leavers process correctly
  • Policies and access controls behave as expected

04

Staged Transfer of Responsibility

Move identities, applications or business units in structured cohorts, avoiding the operational failures and legal issues caused by “big bang” changes.


05

Decommission & Clean Up

Safely retire the legacy IAM platform once all identities and processes have migrated, removing operational risk, cost and technical debt.


Business Impact and Outcomes

Security & Governance


  • Remove unsupported and high risk identity platforms
  • Reduce vulnerability exposure
  • Modern MFA, CA, PIM and governance
  • Ensure compliance with identity and data regulations

Operational Efficiency


  • Faster onboarding and identity lifecycle changes
  • Reduced dependency on scarce legacy skills
  • Parallel running eliminates disruption
  • Improved data accuracy and process reliability

Cost Reduction


  • Retire expensive legacy IAM tooling
  • Reduce licensing and support overhead
  • Decommission on prem infrastructure
  • Leverage capabilities already included in M365

Future Ready Identity


  • Integrated lifecycle automation
  • Access governance aligned with Microsoft standards
  • Foundation for Copilot and AI agent identity governance
Let’s talk.

Start your journey with a free briefing

Sense-check your identity approach, discuss challenges, and get practical guidance on governance, security, and modern identity, with a dedicated Condatis specialist.

Get started

Get in touch


Move from Microsoft Identity Manager (MIM) and other legacy IAM platforms to a modern, cloud aligned identity governance model safely, efficiently, and without disruption.

Supports all stages of the Microsoft 365 journey:

  • M365 E3: foundational lifecycle automation
  • M365 E5: advanced identity protection and governance
  • M365 E7: comprehensive governance across human, workload and AI/agent identities

Identity Governance and Entra Suite capabilities can also be licensed as standalone add-ons.

This solution is designed for organisations that need to:

  • Operate a legacy or custom IAM solution, such as MIM, SailPoint, ForgeRock, Okta or NetIQ, that is increasingly complex to maintain
  • Address Microsoft Identity Manager (MIM) end of support (January 2029) and related platform risk
  • Remove SharePoint 2016/2019 dependencies approaching end of life
  • Reduce operational risk and reliance on bespoke configurations and hard to source specialist skillsets
  • Consolidate identity tooling to simplify architecture and reduce licensing and support costs
  • Modernise joiner, mover, leaver (JML) processes to improve identity accuracy, governance, and automation
  • Establish a modern identity foundation that supports AI driven automation

“I can honestly say working with Condatis has been a great experience from start to finish. I’ve worked with many vendors over the years, and this has been one of the best engagements I’ve experienced. Aside from the competence of your team in delivering on time and on budget the integration of Condatis into our project team was such an easy and pleasurable process. I particularly liked how open and collaborative everyone in the team was and in particular the ability to see the project and challenges from our perspective.”

Technical Project Manager, Brewin Dolphin

Business Challenge and Context


Many organisations still rely on ageing, heavily customised identity systems that create security, operational and financial risk

End of Support Identity Platforms

Legacy identity platforms such as MIM are already out of mainstream support, with full support ending in January 2029 – increasing exposure to security, stability, and compliance risk.

Disruption to Critical Identity Processes

Identity failures directly impact onboarding, access changes, and leaver processes – resulting in users unable to access systems, orphaned accounts, and increased attack surface.

Rising Cost and Inefficiency

Licensing, maintenance, and support costs for legacy tools continue to increase – often duplicating capabilities already available natively within Microsoft Entra.

Operational Fragility and Silent Failure

Unsupported IAM systems receive no security patches, cannot be escalated to Microsoft, and often fail without warning – leaving identity changes unprocessed and issues unnoticed.

Complex, Brittle Customisations

Hard coded flows, custom scripts, unclear data dependencies, and undocumented workflows make change slow, risky, and dependent on a small number of specialists.

Modern Identity Controls Disconnection

Legacy IAM platforms do not integrate with modern security and governance capabilities such as Conditional Access, MFA, risk based policies, dynamic groups, Purview/DLP, or AI governance.

Our solution

Condatis delivers controlled, low risk migrations from MIM and legacy IAM
platforms to Microsoft Entra, using a proven, staged approach that minimises
disruption.

What We Deliver

  • Full assessment of your current identity platform and all traditional/non traditional use cases
  • Mapping of legacy functionality to Entra capabilities
  • A clear, de-risked migration roadmap
  • Parallel running of old and new systems to prevent service interruption
  • Staged transition of identity flows, applications and business units
  • Safe retirement and cleanup of legacy IAM infrastructure

Core Entra Capabilities Used in Migration

  • Lifecycle Workflows (automated JML)
  • Access Packages & Catalogues
  • Dynamic Groups
  • Conditional Access & MFA
  • Identity Governance • HR → Entra attribute lifecycle
  • Azure SQL / Data Lake intermediary stores
  • AI/agent identity governance (E7)

Condatis Services


  • IAM analyst call (30-minute complimentary session)
  • Discovery Lite (60–120-minute remote session)
  • Discovery Workshop (deep dive architecture and maturity assessment)
  • Proof of Concept (targeted validation of specific Entra capabilities)
  • Production ready MVP
  • Full implementation & decommissioning

Our Proven Migration Methodology


These phases describe how we deliver a full migration programme. Each customer engagement (Discovery → Workshop → PoC → MVP → Full Implementation) enters this lifecycle at the appropriate point and scales as needed.

Stage

What This Delivers


01

Identify Requirements

Analyse your identity platform, including:

  • Attribute management
  • GAL synchronisation
  • Custom provisioning flows
  • Multi directory environments
  • Traditional & non traditional MIM use cases

02

Define Core Modern Identity Platform

Establish the minimal Entra configuration required to safely run in parallel with your existing system, including:

  • Lifecycle Workflows
  • Access Packages & Catalogues
  • Dynamic Groups
  • Conditional Access & MFA policies
  • Intermediary data store design

03

Move to Parallel Running

Stand up Entra alongside your current platform so both operate at the same time, ensuring:

  • New starters continue onboarding
  • Movers and leavers process correctly
  • Policies and access controls behave as expected

04

Staged Transfer of Responsibility

Move identities, applications or business units in structured cohorts, avoiding the operational failures and legal issues caused by “big bang” changes.


05

Decommission & Clean Up

Safely retire the legacy IAM platform once all identities and processes have migrated, removing operational risk, cost and technical debt.


Business Impact and Outcomes

Security & Governance


  • Remove unsupported and high risk identity platforms
  • Reduce vulnerability exposure
  • Modern MFA, CA, PIM and governance
  • Ensure compliance with identity and data regulations

Operational Efficiency


  • Faster onboarding and identity lifecycle changes
  • Reduced dependency on scarce legacy skills
  • Parallel running eliminates disruption
  • Improved data accuracy and process reliability

Cost Reduction


  • Retire expensive legacy IAM tooling
  • Reduce licensing and support overhead
  • Decommission on prem infrastructure
  • Leverage capabilities already included in M365

Future Ready Identity


  • Integrated lifecycle automation
  • Access governance aligned with Microsoft standards
  • Foundation for Copilot and AI agent identity governance
Let’s talk.

Start your journey with a free briefing

Sense-check your identity approach, discuss challenges, and get practical guidance on governance, security, and modern identity, with a dedicated Condatis specialist.

Get started

Get in touch


Protecting organisations, connecting people.

Condatis is your partner in Identity and Access Management

Privacy Preference Center

Condatis
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.