Skip to main content

The platform

One migration path from discovery to validated cutover

PhaseArc is the technology layer that makes an identity migration visible and repeatable. It holds the inventory, the mapping decisions, the wave plan, the execution record, and the validation evidence in one place, so nobody has to reconstruct the project from spreadsheets and scripts.

DiscoverMapMoveOne migration path
Sources are inventoried separately, mapped to a single target design, then moved along one controlled path to Microsoft Entra ID.

What is the PhaseArc platform?

PhaseArc is an identity migration platform for organizations moving from Okta or Ping Identity to Microsoft Entra ID. It structures and automates repeatable migration work, from source inventory and object mapping through wave execution, validation, and the record of every change, while leaving target design, exception handling, and cutover decisions with the identity team.

Seven capabilities

What the platform does

Each capability produces something the next one depends on, which is what keeps a migration from drifting.

01

Discover and inventory

Build one structured record of the source estate: applications by protocol, users, groups, assignments, policies, provisioning connections, and known dependencies.

02

Normalize and map

Give every object a treatment against a Microsoft Entra ID target, and flag anything with no direct equivalent so it becomes a decision rather than a surprise.

03

Plan controlled waves

Group work into waves by owner, risk, protocol, and business calendar, with entry and exit criteria attached to each wave.

04

Execute repeatable work

Run the prepared changes for an approved wave consistently, instead of re-deriving the same steps by hand for every application.

05

Validate access and configuration

Turn the wave into validation tasks covering sign-in, assignments, claims, policy behaviour, and provisioning, then capture the results.

06

Prepare cutover and fallback

Keep the source active until cutover is approved, and hold the fallback position for each wave alongside the steps to use it.

07

Record migration evidence

Keep the record of what was discovered, prepared, moved, and validated so the change can be reviewed and evidenced afterwards.

Delivery model

What PhaseArc does, what identity teams decide

Being explicit about this boundary is what makes the plan credible to a security review.

Responsibility split. Exact support and scope are confirmed during the migration assessment.
AreaPhaseArcYour identity team
InventoryCollects and structures the source record.Confirms what is in scope.
MappingProposes treatment per object and flags gaps.Approves the target design.
Naming and structureApplies the agreed convention consistently.Defines the convention.
ExceptionsSurfaces objects that cannot follow the standard treatment.Decides how each is handled.
WavesBuilds the wave plan and tracks entry and exit criteria.Approves each wave before it runs.
ExecutionRuns prepared changes and records the outcome.Authorizes the change window.
ValidationGenerates validation tasks and captures results.Accepts results and signs off.
CutoverPrepares cutover and fallback steps.Makes the cutover or fallback call.
DecommissionReports on remaining dependencies.Approves retirement of the source.

Principles

How the platform behaves

  • Nothing moves without a treatment recorded against it first.
  • The source platform stays active until cutover is approved for that wave.
  • Every wave has a fallback position defined before it runs.
  • Validation results are captured as evidence, not as a verbal confirmation.
  • Objects with no clean target equivalent are escalated as decisions, not silently skipped.

For the access model behind this, see migration security and controls.

Platform questions

What is an identity migration platform?
It is software that structures the repeatable work of moving an identity estate between platforms: inventory, mapping, wave planning, execution of prepared changes, validation, and the record of what happened. It does not replace the design decisions an identity team owns.
Does PhaseArc replace the identity team?
No. PhaseArc removes repetitive execution and record keeping. Target design, exception handling, wave approval, validation sign-off, and the cutover decision remain with your identity team.
How is the scope of automation confirmed?
During the migration assessment. Automation depends on the source architecture, the protocols in use, and the permissions available, so scope is agreed for your environment rather than assumed.

See the platform against your own estate

An assessment turns your source inventory into a mapped, sequenced migration plan with the exceptions named up front.