Staged, reversible moves
Work moves in defined batches. A stage can be paused before it is confirmed, so you are never mid-flight across the whole environment.
Automated Okta and Ping migration to Microsoft Entra ID
PhaseArc structures and automates the repeatable work of moving applications, identities, and access from Okta or Ping Identity to Microsoft Entra ID, so your team can see every move before making it.
From first discovery run to validated cutover.
Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)
Apps in scope
142
Decisions open
9
Waves planned
6
Source-aware
Okta and Ping estates are discovered on their own terms.
Decision-led
Every object carries a recorded treatment before it moves.
Wave-based
Work is grouped, approved, and executed one wave at a time.
Evidence-backed
Validation results are captured as a reviewable record.
How PhaseArc organizes migration work. Scope and support are confirmed during the assessment.
PhaseArc is an automated identity migration platform for organizations moving from Okta or Ping Identity to Microsoft Entra ID. It inventories the source estate, maps each object to a target design, runs migration work in controlled waves, and records validation evidence, so a complex migration becomes visible, structured, and controllable from discovery through approved cutover.
Microsoft Entra ID was formerly called Azure Active Directory, and you will still see the Azure AD name in older documentation and internal runbooks.
Two starting points
Each source platform has its own inventory, protocol mix, and policy model. Start with the path that matches your estate.
Applications, federation, directory and provisioning, sign-on policies, authentication methods, and workflow integrations, each treated as its own workstream.
Ping IdentityIdentify whether you are starting from PingOne, PingFederate, or a combination, then plan applications, connections, attributes, and flows accordingly.
Migration map
Every category of source object gets a treatment before anything moves: move, map or translate, rebuild or redesign, or re-register and validate.
Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)
| Source category | Typical Entra destination | Treatment |
|---|---|---|
| Users and attributes | Entra ID users and directory attributes | Move |
| Groups and memberships | Security groups and Microsoft 365 groups | Map or translate |
| SAML applications | Enterprise applications with SAML SSO | Map or translate |
| OIDC and OAuth applications | App registrations and enterprise applications | Re-register or validate |
| Sign-on policies | Conditional Access policies | Rebuild or redesign |
| Authentication methods | Entra authentication methods and registration | Re-register or validate |
Four consistent stages
The same four stages apply to every wave, whether you are moving a focused pilot or a broader application estate.
Inventory the source estate and its dependencies.
Map objects to a target design, log exceptions, and plan waves.
Run controlled batches while the source keeps serving sign-ins.
Test access and configuration, record evidence, decide on cutover.
Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)
01 Prepare
02 Execute
03 Validate
04 Cutover
| Application | Prepare | Execute | Validate |
|---|---|---|---|
| Salesforce | Passed | Passed | Passed |
| ServiceNow | Passed | Passed | Running |
| GitHub Enterprise Cloud | Passed | Running | Pending |
Delivery model
PhaseArc is the technology layer that structures and automates repeatable migration work. Identity teams keep control of design and decisions.
| Area | Repeatable platform workflow | Identity team decision |
|---|---|---|
| Inventory | Collect source objects, applications, assignments, and dependencies into one structured record. | Confirm which parts of the estate are in scope. |
| Target design | Present mapping options and flag objects with no direct equivalent. | Own naming, group model, policy design, and licensing decisions. |
| Exceptions | Surface objects that cannot follow the standard treatment. | Decide how each exception is handled or retired. |
| Execution | Run prepared changes in defined waves and record the outcome. | Approve each wave before it runs. |
| Validation | Produce validation tasks and capture results as evidence. | Accept validation results and sign off. |
| Cutover | Prepare cutover and fallback steps for the wave. | Decide when to cut over and when to fall back. |
Read more about the platform on the identity migration platform page.
SAFETY & ROLLBACK
Migrations run in controlled stages, so nothing has to be all or nothing. If something needs a second look, you can hold the stage and keep your existing platform serving sign-ins.
Work moves in defined batches. A stage can be paused before it is confirmed, so you are never mid-flight across the whole environment.
Okta or Ping keeps serving authentication until you validate the destination and choose to switch over.
If a batch does not validate, that stage is rolled back to its previous state and re-run once the issue is resolved.
Each stage records what was discovered, prepared, moved, and validated, so your team can review and evidence the change.
Rollback behaviour depends on your source platform, scope, and cutover plan, and is agreed with you during the assessment before any migration stage runs.
Guides
Practical, ungated planning material for teams scoping a migration to Microsoft Entra ID.
Inventory, protocols, federation, policy translation, and cutover.
Identify the source architecture before planning the move.
A printable checklist across discovery, waves, cutover, and validation.
What changes in application, policy, and provisioning models.
Share your starting point and we will scope an assessment covering source architecture, application inventory, policy complexity, dependencies, and the sequencing your migration needs.