Skip to main content

The platform

From discovery to validated cutover

PhaseArc holds the inventory, the mapping decisions, the wave plan, the execution record, and the validation evidence in one place.

PhaseArc workspace / Overview

Northstar Identity Consolidation

Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)

Wave 3 of 6

Apps in scope

142

Decisions open

9

Waves planned

6

Wave 3, in progress

Running
  • Applications prepared6 of 6
  • Validation results recorded4 of 6
  • Cutover approvalWaiting
The PhaseArc portfolio overview for a single migration project: applications in scope, open mapping decisions, planned waves, and the wave in progress.

The workspace

What the workspace looks like

Five sections carry a migration project: Overview, Applications, Migration Map, Waves, and Evidence. Each one hands its output to the next.

Applications

PhaseArc workspace / Applications

Northstar Identity Consolidation

Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)

Wave 3 of 6Connections healthy
Application inventory for the Northstar Identity Consolidation migration project.
ApplicationProtocolMappingReadiness
Salesforce(selected row)SAML 2.0TransformReady
ServiceNowSAML 2.0DirectReady
GitHub Enterprise CloudOIDCTransformRe-registration pending
WorkdaySAML 2.0RebuildNeeds review
The PhaseArc application inventory puts protocol, provisioning, assignments, target, mapping treatment, readiness, wave, owner, and open issues on one row, with the selected application expanded alongside.

Migration map

PhaseArc workspace / Migration map

Northstar Identity Consolidation

Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)

Wave 3 of 6Connections healthy

Access

  • SourceSalesforce SAML application and claims contractTranslation decisionTransformMicrosoft Entra IDEnterprise application with mapped claims
  • SourceGroup assignment paths for finance applicationsTranslation decisionDirectMicrosoft Entra IDSecurity group assignment on enterprise apps

Provisioning

  • SourceWorkday outbound SCIM connectionTranslation decisionRebuildMicrosoft Entra IDEntra ID application provisioning

Policies

  • SourceOkta sign-on policy for privileged accessTranslation decisionRebuildMicrosoft Entra IDConditional Access policy set
The PhaseArc Migration Map connects source objects, the recorded translation decision, and the Microsoft Entra ID target. This crop shows four mappings. The table below carries the full set of treatments.
Representative source objects, the recorded treatment, and the Microsoft Entra ID target.
Source objectTreatmentMicrosoft Entra ID target
SAML application and claims contractTransformEnterprise application with mapped claims
Group assignment pathsDirectSecurity group assignment on the enterprise application
Outbound SCIM connectionRebuildEntra ID application provisioning
Sign-on or authentication policyRebuildConditional Access policy set
Identity platform automationManualRebuilt outside the identity platform
Header based access enforcementExcludedNo direct equivalent, retirement or proxy decision required

Waves

PhaseArc workspace / Waves

Northstar Identity Consolidation

Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)

Wave 3 of 6
  1. 01 Prepare

    Passed
  2. 02 Execute

    Running
  3. 03 Validate

    Running
  4. 04 Cutover

    Waiting for approval
Wave 3 execution state of the Northstar Identity Consolidation migration project.
ApplicationPrepareExecuteValidate
SalesforcePassedPassedPassed
ServiceNowPassedPassedRunning
GitHub Enterprise CloudPassedRunningPending
Wave execution in PhaseArc. PhaseArc records execution state for each application and stage in the active wave.

Evidence

PhaseArc workspace / Evidence

Northstar Identity Consolidation

Okta Workforce + PingFederate to Microsoft Entra ID (northstar.onmicrosoft.com)

Wave 3 of 6
  • Salesforce SAML sign-in succeeds for finance group

    Ready
    Observed
    Sign-in completed, claims match contract
    Source
    Entra sign-in logs
  • ServiceNow group assignment matches source

    Ready
    Observed
    7 groups assigned
    Source
    Assignment export
PhaseArc validation evidence. This crop shows two records with the requirement, the observed result, the provenance, and the review state. Each record also carries the expected result, timestamp, owner, reviewer, and version.

What is the PhaseArc platform?

PhaseArc is an identity migration platform for organizations moving from Okta or Ping Identity to Microsoft Entra ID. It structures and automates repeatable migration work, from source inventory and object mapping through wave execution, validation, and the record of every change, while leaving target design, exception handling, and cutover decisions with the identity team.

Seven capabilities

What the platform does

Each capability produces something the next one depends on, which is what keeps a migration from drifting.

01

Discover and inventory

Build one structured record of the source estate: applications by protocol, users, groups, assignments, policies, provisioning connections, and known dependencies.

02

Normalize and map

Give every object a treatment against a Microsoft Entra ID target, and flag anything with no direct equivalent so it becomes a decision rather than a surprise.

03

Plan controlled waves

Group work into waves by owner, risk, protocol, and business calendar, with entry and exit criteria attached to each wave.

04

Execute repeatable work

Run the prepared changes for an approved wave consistently, instead of re-deriving the same steps by hand for every application.

05

Validate access and configuration

Turn the wave into validation tasks covering sign-in, assignments, claims, policy behaviour, and provisioning, then capture the results.

06

Prepare cutover and fallback

Keep the source active until cutover is approved, and hold the fallback position for each wave alongside the steps to use it.

07

Record migration evidence

Keep the record of what was discovered, prepared, moved, and validated so the change can be reviewed and evidenced afterwards.

Delivery model

What PhaseArc does, what identity teams decide

Being explicit about this boundary is what makes the plan credible to a security review.

Responsibility split. Exact support and scope are confirmed during the migration assessment.
AreaPhaseArcYour identity team
InventoryCollects and structures the source record.Confirms what is in scope.
MappingProposes treatment per object and flags gaps.Approves the target design.
Naming and structureApplies the agreed convention consistently.Defines the convention.
ExceptionsSurfaces objects that cannot follow the standard treatment.Decides how each is handled.
WavesBuilds the wave plan and tracks entry and exit criteria.Approves each wave before it runs.
ExecutionRuns prepared changes and records the outcome.Authorizes the change window.
ValidationGenerates validation tasks and captures results.Accepts results and signs off.
CutoverPrepares cutover and fallback steps.Makes the cutover or fallback call.
DecommissionReports on remaining dependencies.Approves retirement of the source.

Principles

How the platform behaves

  • Nothing moves without a treatment recorded against it first.
  • The source platform stays active until cutover is approved for that wave.
  • Every wave has a fallback position defined before it runs.
  • Validation results are captured as evidence, not as a verbal confirmation.
  • Objects with no clean target equivalent are escalated as decisions, not silently skipped.

For the access model behind this, see migration security and controls.

Platform questions

What is an identity migration platform?
It is software that structures the repeatable work of moving an identity estate between platforms: inventory, mapping, wave planning, execution of prepared changes, validation, and the record of what happened. It does not replace the design decisions an identity team owns.
Does PhaseArc replace the identity team?
No. PhaseArc removes repetitive execution and record keeping. Target design, exception handling, wave approval, validation sign-off, and the cutover decision remain with your identity team.
How is the scope of automation confirmed?
During the migration assessment. Automation depends on the source architecture, the protocols in use, and the permissions available, so scope is agreed for your environment rather than assumed.

See the platform against your own estate

An assessment turns your source inventory into a mapped, sequenced migration plan with the exceptions named up front.