Skip to main content

The migration workflow

Four stages, applied to every wave

Discover, Prepare, Migrate, Validate. The same sequence applies whether a wave contains a focused pilot or a broader application estate, so the project stays legible to everyone involved.

How does a PhaseArc migration run?

Discovery inventories the source estate once. Prepare turns that inventory into a target design, an exception list, and a wave plan. Migrate executes one approved wave at a time while the source platform keeps serving sign-ins. Validate proves the wave with recorded evidence, and only then is cutover approved for that scope.

Stage by stage

The timeline

Each stage has visible work and a defined deliverable.

  1. 01

    Discover

    Build the source record. Nothing can be planned honestly until the estate is inventoried and its dependencies are visible.

    Work in this stage

    • Inventory applications and group them by protocol and owner.
    • Record users, groups, memberships, and assignment paths.
    • Capture sign-on policies, authentication methods, and provisioning connections.
    • Identify integrations, scripts, and automations that depend on the source platform.

    Deliverable: A structured source inventory with dependencies and unknowns explicitly listed.

  2. 02

    Prepare

    Turn the inventory into decisions: what moves, what is translated, what is rebuilt, and in which order.

    Work in this stage

    • Assign a treatment to every object category against the Microsoft Entra ID target.
    • Agree naming, group model, claims, and policy design in the target.
    • Log exceptions with named owners and a decision date.
    • Build waves with entry and exit criteria, and write the test plan.

    Deliverable: A target design, an exception list, a wave plan, and a test plan your team has approved.

  3. 03

    Migrate

    Run one approved wave at a time. The source platform keeps serving sign-ins for everything not yet cut over.

    Work in this stage

    • Execute the prepared changes for the approved wave.
    • Coordinate application owner and vendor changes where metadata or credentials change.
    • Keep the source active and the fallback position intact.
    • Record every change made during the wave.

    Deliverable: Executed wave changes with a complete change record and an intact fallback path.

  4. 04

    Validate

    Prove the wave before accepting it, then make an explicit cutover or fallback decision.

    Work in this stage

    • Test sign-in, authorization, and claims per application.
    • Check assignments, group memberships, and policy behaviour.
    • Confirm provisioning and downstream automation.
    • Capture results as evidence and decide: accept, remediate, or fall back.

    Deliverable: Validation evidence per application and group, plus a recorded cutover or fallback decision.

Controls

What stays true in every wave

The controls that keep a staged migration recoverable.

  • Waves are approved by your identity team before they run.
  • The source platform keeps serving authentication until cutover is approved.
  • A fallback position exists before the wave starts, not after something breaks.
  • Validation is recorded as evidence, per application and per group.
  • Exceptions are named, owned, and dated rather than absorbed into the plan.
  • The change record covers what was discovered, prepared, moved, and validated.

Who does what

Stage ownership

Ownership by stage. Exact support and scope are confirmed during the migration assessment.
StagePhaseArcYour identity team
DiscoverCollects and structures the inventory.Confirms scope and grants discovery access.
PrepareProposes treatment and builds the wave plan.Approves target design and exception handling.
MigrateExecutes prepared changes and records them.Approves the wave and the change window.
ValidateGenerates and captures validation results.Accepts results and decides on cutover.

The treatment applied in Prepare is set out category by category in the source to target migration map.

Questions about the migration workflow

Do the four stages run once or repeatedly?
Repeatedly. Discovery covers the whole estate up front, then Prepare, Migrate, and Validate cycle once per wave until the last wave is accepted.
What happens if a wave fails validation?
The wave is not accepted. The issue is remediated and the wave is re-run, or the fallback position prepared before the wave is used while the problem is resolved.
When does the source platform get retired?
Only after every dependency has a confirmed owner and replacement, and after the final cutover has been validated. Decommission readiness is a deliberate step, not a side effect of the last wave.

Put your estate through Discover

The assessment is the entry point to stage one: source architecture, application inventory, scope, dependencies, and the sequencing that follows from them.