Skip to main content

Security and controls

A migration your security team can review

Identity migration touches the systems that guard everything else. This page describes how PhaseArc migrations are run and where responsibility sits. It is maintained by PhaseArc and is not an independent certification.

How is a PhaseArc migration kept safe?

Access is scoped to the work in scope and time-limited. Changes run in waves your identity team approves. The source platform keeps serving sign-ins until cutover is accepted, and every wave has a fallback position defined before it runs. Validation results and change records are captured so the migration can be reviewed afterwards.

Operating controls

How migration work is run

Controls that apply to every engagement.

Scoped access

Discovery uses read access. Change work uses the narrowest administrative scope that covers the object types in scope, agreed in writing before it is granted.

Time-limited credentials

Access exists for the duration of the work it supports and is removed when the migration or stage completes.

Approved waves

No wave runs without your identity team approving the scope and the change window.

Source stays live

Okta or Ping keeps serving authentication for anything not yet cut over, so nothing is all or nothing.

Fallback before execution

Each wave has a defined fallback position, prepared before the wave starts rather than improvised afterwards.

Recorded evidence

What was discovered, prepared, moved, and validated is recorded so the change can be reviewed and evidenced.

Data

Data handled during a migration

What migration work involves handling, and what it does not.

Typical data categories in a migration. Exact handling is agreed during the assessment.
CategoryWhy it is involvedHandling principle
Directory attributesUsers and groups must be matched and mapped in the target.Used for migration purposes only, scoped to the objects in scope.
Application configurationConnections, claims, and assignments must be recreated.Treated as configuration data, recorded in the migration record.
Policy configurationPolicy intent must be translated into Conditional Access.Reviewed and approved by your identity team before it is applied.
Passwords and secretsNot migrated between platforms.Authentication in the target uses Entra ID methods.
Migration recordsEvidence of what changed and what was validated.Retained to support review of the change.

Shared responsibility

Who is responsible for what

Responsibility split for a PhaseArc migration.
AreaPhaseArcYour organization
Access grantsRequests the narrowest scope needed.Approves, grants, and revokes access.
Target designProposes treatment and flags gaps.Approves the design and the exceptions.
Change windowsPrepares and executes the approved wave.Authorizes the window and communicates it.
ValidationProduces validation tasks and captures results.Accepts results and signs off.
CutoverPrepares cutover and fallback steps.Makes the cutover or fallback decision.
Tenant configurationApplies agreed changes in scope.Owns the tenant and its wider security posture.

Being clear

What this page does not claim

  • This page is maintained by PhaseArc to answer common security questions. It is not independent verification or certification.
  • No regulatory compliance, audit outcome, or breach guarantee is claimed here.
  • Certifications, partner status, and contractual terms are shared and confirmed directly during your assessment.
  • Rollback behaviour depends on your source platform, scope, and cutover plan, and is agreed before any migration stage runs.

For how the details you submit through this site are handled, see the privacy notice.

Security questions

What access does a migration need?
Read access to the source platform for discovery, and scoped administrative access in the Microsoft Entra ID tenant for the object types in scope. Access is agreed in writing during the assessment, granted for the work in scope, and removed when the migration completes.
Can a migration be paused or reversed?
Work moves in approved waves. A wave can be held before cutover is accepted, and each wave has a fallback position defined before it runs. Reversibility depends on your source platform, scope, and cutover plan, and is agreed during the assessment.
Does PhaseArc hold credentials or passwords?
Passwords are not migrated between platforms. Authentication in the target uses Microsoft Entra ID methods. The credentials used to run migration work are scoped for that purpose and their handling is agreed during the assessment.
Is PhaseArc certified?
Certifications and partner status are shared and confirmed directly during your assessment. This page describes how migrations are run, and is not a certification claim.

Bring your security team to the assessment

Access scope, change control, validation evidence, and fallback planning are all agreed before the first wave runs.