Security and controls
A migration your security team can review
Identity migration touches the systems that guard everything else. This page describes how PhaseArc migrations are run and where responsibility sits. It is maintained by PhaseArc and is not an independent certification.
How is a PhaseArc migration kept safe?
Access is scoped to the work in scope and time-limited. Changes run in waves your identity team approves. The source platform keeps serving sign-ins until cutover is accepted, and every wave has a fallback position defined before it runs. Validation results and change records are captured so the migration can be reviewed afterwards.
Operating controls
How migration work is run
Controls that apply to every engagement.
Scoped access
Time-limited credentials
Approved waves
Source stays live
Fallback before execution
Recorded evidence
Data
Data handled during a migration
What migration work involves handling, and what it does not.
| Category | Why it is involved | Handling principle |
|---|---|---|
| Directory attributes | Users and groups must be matched and mapped in the target. | Used for migration purposes only, scoped to the objects in scope. |
| Application configuration | Connections, claims, and assignments must be recreated. | Treated as configuration data, recorded in the migration record. |
| Policy configuration | Policy intent must be translated into Conditional Access. | Reviewed and approved by your identity team before it is applied. |
| Passwords and secrets | Not migrated between platforms. | Authentication in the target uses Entra ID methods. |
| Migration records | Evidence of what changed and what was validated. | Retained to support review of the change. |
Shared responsibility
Who is responsible for what
| Area | PhaseArc | Your organization |
|---|---|---|
| Access grants | Requests the narrowest scope needed. | Approves, grants, and revokes access. |
| Target design | Proposes treatment and flags gaps. | Approves the design and the exceptions. |
| Change windows | Prepares and executes the approved wave. | Authorizes the window and communicates it. |
| Validation | Produces validation tasks and captures results. | Accepts results and signs off. |
| Cutover | Prepares cutover and fallback steps. | Makes the cutover or fallback decision. |
| Tenant configuration | Applies agreed changes in scope. | Owns the tenant and its wider security posture. |
Being clear
What this page does not claim
- This page is maintained by PhaseArc to answer common security questions. It is not independent verification or certification.
- No regulatory compliance, audit outcome, or breach guarantee is claimed here.
- Certifications, partner status, and contractual terms are shared and confirmed directly during your assessment.
- Rollback behaviour depends on your source platform, scope, and cutover plan, and is agreed before any migration stage runs.
For how the details you submit through this site are handled, see the privacy notice.
Security questions
What access does a migration need?
Can a migration be paused or reversed?
Does PhaseArc hold credentials or passwords?
Is PhaseArc certified?
Bring your security team to the assessment
Access scope, change control, validation evidence, and fallback planning are all agreed before the first wave runs.