The platform
From discovery to validated cutover
PhaseArc holds the inventory, the mapping decisions, the wave plan, the execution record, and the validation evidence in one place.
Northstar Identity Consolidation
Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)
Apps in scope
142
Decisions open
9
Waves planned
6
Wave 3, in progress
Running- Applications prepared6 of 6
- Validation results recorded4 of 6
- Cutover approvalWaiting
The workspace
What the workspace looks like
Five sections carry a migration project: Overview, Applications, Migration Map, Waves, and Evidence. Each one hands its output to the next.
Applications
Northstar Identity Consolidation
Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)
| Application | Protocol | Mapping | Readiness |
|---|---|---|---|
| Salesforce(selected row) | SAML 2.0 | Transform | Ready |
| ServiceNow | SAML 2.0 | Direct | Ready |
| GitHub Enterprise Cloud | OIDC | Transform | Re-registration pending |
| Workday | SAML 2.0 | Rebuild | Needs review |
Migration map
Northstar Identity Consolidation
Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)
Access
- SourceSalesforce SAML application and claims contractTranslation decisionTransformMicrosoft Entra IDEnterprise application with mapped claims
- SourceGroup assignment paths for finance applicationsTranslation decisionDirectMicrosoft Entra IDSecurity group assignment on enterprise apps
Provisioning
- SourceWorkday outbound SCIM connectionTranslation decisionRebuildMicrosoft Entra IDEntra ID application provisioning
Policies
- SourceOkta sign-on policy for privileged accessTranslation decisionRebuildMicrosoft Entra IDConditional Access policy set
| Source object | Treatment | Microsoft Entra ID target |
|---|---|---|
| SAML application and claims contract | Transform | Enterprise application with mapped claims |
| Group assignment paths | Direct | Security group assignment on the enterprise application |
| Outbound SCIM connection | Rebuild | Entra ID application provisioning |
| Sign-on or authentication policy | Rebuild | Conditional Access policy set |
| Identity platform automation | Manual | Rebuilt outside the identity platform |
| Header based access enforcement | Excluded | No direct equivalent, retirement or proxy decision required |
Waves
Northstar Identity Consolidation
Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)
01 Prepare
Passed02 Execute
Running03 Validate
Running04 Cutover
Waiting for approval
| Application | Prepare | Execute | Validate |
|---|---|---|---|
| Salesforce | Passed | Passed | Passed |
| ServiceNow | Passed | Passed | Running |
| GitHub Enterprise Cloud | Passed | Running | Pending |
Evidence
Northstar Identity Consolidation
Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)
Salesforce SAML sign-in succeeds for finance group
Ready- Observed
- Sign-in completed, claims match contract
- Source
- Entra sign-in logs
ServiceNow group assignment matches source
Ready- Observed
- 7 groups assigned
- Source
- Assignment export
What is the PhaseArc platform?
PhaseArc is an identity migration platform for organizations moving from Okta or Ping Identity to Microsoft Entra ID. It structures and automates repeatable migration work, from source inventory and object mapping through wave execution, validation, and the record of every change, while leaving target design, exception handling, and cutover decisions with the identity team.
Seven capabilities
What the platform does
Each capability produces something the next one depends on, which is what keeps a migration from drifting.
01
Discover and inventory
02
Normalize and map
03
Plan controlled waves
04
Execute repeatable work
05
Validate access and configuration
06
Prepare cutover and fallback
07
Record migration evidence
Delivery model
What PhaseArc does, what identity teams decide
Being explicit about this boundary is what makes the plan credible to a security review.
| Area | PhaseArc | Your identity team |
|---|---|---|
| Inventory | Collects and structures the source record. | Confirms what is in scope. |
| Mapping | Proposes treatment per object and flags gaps. | Approves the target design. |
| Naming and structure | Applies the agreed convention consistently. | Defines the convention. |
| Exceptions | Surfaces objects that cannot follow the standard treatment. | Decides how each is handled. |
| Waves | Builds the wave plan and tracks entry and exit criteria. | Approves each wave before it runs. |
| Execution | Runs prepared changes and records the outcome. | Authorizes the change window. |
| Validation | Generates validation tasks and captures results. | Accepts results and signs off. |
| Cutover | Prepares cutover and fallback steps. | Makes the cutover or fallback call. |
| Decommission | Reports on remaining dependencies. | Approves retirement of the source. |
Principles
How the platform behaves
- Nothing moves without a treatment recorded against it first.
- The source platform stays active until cutover is approved for that wave.
- Every wave has a fallback position defined before it runs.
- Validation results are captured as evidence, not as a verbal confirmation.
- Objects with no clean target equivalent are escalated as decisions, not silently skipped.
For the access model behind this, see migration security and controls.
Platform questions
What is an identity migration platform?
Does PhaseArc replace the identity team?
How is the scope of automation confirmed?
See the platform against your own estate
An assessment turns your source inventory into a mapped, sequenced migration plan with the exceptions named up front.