Skip to main content

Automated Okta and Ping migration to Microsoft Entra ID

Identity migration, in motion.

PhaseArc structures and automates the repeatable work of moving applications, identities, and access from Okta or Ping Identity to Microsoft Entra ID, so your team can see every move before making it.

From first discovery run to validated cutover.

PhaseArc workspace / Overview

Northstar Identity Consolidation

Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)

Wave 3 of 6

Apps in scope

142

Decisions open

9

Waves planned

6

Wave 3, in progress

Running
  • Applications prepared6 of 6
  • Validation results recorded4 of 6
  • Cutover approvalWaiting
The PhaseArc portfolio overview: applications in scope, open mapping decisions, planned waves, and the state of the wave in progress.
  • Source-aware

    Okta and Ping estates are discovered on their own terms.

  • Decision-led

    Every object carries a recorded treatment before it moves.

  • Wave-based

    Work is grouped, approved, and executed one wave at a time.

  • Evidence-backed

    Validation results are captured as a reviewable record.

How PhaseArc organizes migration work. Scope and support are confirmed during the assessment.

What is PhaseArc?

PhaseArc is an automated identity migration platform for organizations moving from Okta or Ping Identity to Microsoft Entra ID. It inventories the source estate, maps each object to a target design, runs migration work in controlled waves, and records validation evidence, so a complex migration becomes visible, structured, and controllable from discovery through approved cutover.

Microsoft Entra ID was formerly called Azure Active Directory, and you will still see the Azure AD name in older documentation and internal runbooks.

Migration map

See every move before you make it

Every category of source object gets a treatment before anything moves: move, map or translate, rebuild or redesign, or re-register and validate.

PhaseArc workspace / Migration map

Northstar Identity Consolidation

Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)

Wave 3 of 6Connections healthy

Access

  • SourceSalesforce SAML application and claims contractTranslation decisionTransformMicrosoft Entra IDEnterprise application with mapped claims
  • SourceGroup assignment paths for finance applicationsTranslation decisionDirectMicrosoft Entra IDSecurity group assignment on enterprise apps

Provisioning

  • SourceWorkday outbound SCIM connectionTranslation decisionRebuildMicrosoft Entra IDEntra ID application provisioning

Policies

  • SourceOkta sign-on policy for privileged accessTranslation decisionRebuildMicrosoft Entra IDConditional Access policy set
The PhaseArc Migration Map connects source objects on the left, the recorded translation decision in the middle, and the Microsoft Entra ID target on the right. This crop shows four mappings. The full map covers access, provisioning, policies, and dependencies.
A compact extract of the PhaseArc migration map. Final scope is established during assessment.
Source categoryTypical Entra destinationTreatment
Users and attributesEntra ID users and directory attributesMove
Groups and membershipsSecurity groups and Microsoft 365 groupsMap or translate
SAML applicationsEnterprise applications with SAML SSOMap or translate
OIDC and OAuth applicationsApp registrations and enterprise applicationsRe-register or validate
Sign-on policiesConditional Access policiesRebuild or redesign
Authentication methodsEntra authentication methods and registrationRe-register or validate

Open the full source to target migration map

Four consistent stages

Discover, Prepare, Migrate, Validate

The same four stages apply to every wave, whether you are moving a focused pilot or a broader application estate.

  1. 01

    Discover

    Inventory the source estate and its dependencies.

  2. 02

    Prepare

    Map objects to a target design, log exceptions, and plan waves.

  3. 03

    Migrate

    Run controlled batches while the source keeps serving sign-ins.

  4. 04

    Validate

    Test access and configuration, record evidence, decide on cutover.

PhaseArc workspace / Waves

Northstar Identity Consolidation

Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)

Wave 3 of 6
  1. 01 Prepare

    Passed
  2. 02 Execute

    Running
  3. 03 Validate

    Running
  4. 04 Cutover

    Waiting for approval
Wave 3 execution state of the Northstar Identity Consolidation migration project.
ApplicationPrepareExecuteValidate
SalesforcePassedPassedPassed
ServiceNowPassedPassedRunning
GitHub Enterprise CloudPassedRunningPending
Wave execution in PhaseArc. Applications move through the same stages in parallel, and each one carries its own state, including the ones that fail or roll back.

See what each stage produces

Delivery model

What the platform handles, what your team decides

PhaseArc is the technology layer that structures and automates repeatable migration work. Identity teams keep control of design and decisions.

Exact support and scope are confirmed during the migration assessment.
AreaRepeatable platform workflowIdentity team decision
InventoryCollect source objects, applications, assignments, and dependencies into one structured record.Confirm which parts of the estate are in scope.
Target designPresent mapping options and flag objects with no direct equivalent.Own naming, group model, policy design, and licensing decisions.
ExceptionsSurface objects that cannot follow the standard treatment.Decide how each exception is handled or retired.
ExecutionRun prepared changes in defined waves and record the outcome.Approve each wave before it runs.
ValidationProduce validation tasks and capture results as evidence.Accept validation results and sign off.
CutoverPrepare cutover and fallback steps for the wave.Decide when to cut over and when to fall back.

Read more about the platform on the identity migration platform page.

SAFETY & ROLLBACK

Pause, revert, and keep working while you move.

Migrations run in controlled stages, so nothing has to be all or nothing. If something needs a second look, you can hold the stage and keep your existing platform serving sign-ins.

  • Staged, reversible moves

    Work moves in defined batches. A stage can be paused before it is confirmed, so you are never mid-flight across the whole environment.

  • Source stays live until cutover

    Okta or Ping keeps serving authentication until you validate the destination and choose to switch over.

  • Revert a stage

    If a batch does not validate, that stage is rolled back to its previous state and re-run once the issue is resolved.

  • A record of every change

    Each stage records what was discovered, prepared, moved, and validated, so your team can review and evidence the change.

Rollback behaviour depends on your source platform, scope, and cutover plan, and is agreed with you during the assessment before any migration stage runs.

Common questions about migrating to Microsoft Entra ID

What does PhaseArc do?
PhaseArc structures and automates the repeatable parts of an identity migration to Microsoft Entra ID: inventory, mapping, wave planning, execution of prepared changes, validation, and the record of what happened. Target design, exceptions, and the cutover decision stay with your identity team.
Which source platforms does PhaseArc cover?
Okta and Ping Identity. Ping environments differ, so discovery identifies whether you are running PingOne, PingFederate, or a combination before any migration work is planned.
Does everything migrate automatically?
No. Some objects move, some are mapped or translated into a Microsoft Entra ID equivalent, and some need to be redesigned in the target. Sign-on policies and authentication methods in particular are not one-to-one transfers. The migration map sets out the treatment for each category.
Does the source platform stay live during the migration?
A staged plan can keep the source platform serving authentication while destination waves are prepared and validated. The feasible overlap, rollback position, and cutover plan depend on your architecture and are confirmed during the assessment.
How does a project start?
With a migration assessment. You share your starting point and goals, and the assessment establishes source architecture, application and protocol inventory, scope, dependencies, and the sequencing needed before any migration stage runs.

Turn your identity estate into a migration plan

Share your starting point and we will scope an assessment covering source architecture, application inventory, policy complexity, dependencies, and the sequencing your migration needs.