01
Identity Management System replacement case study at orange Slovensko

Microsoft Identity Manager Migration

Replace MIM before January 2029 with open source midPoint.
On your infrastructure, with your data, without a big-bang cut-over.

Identity Management System replacement case study at orange Slovensko

MIM support ends 9 January 2029.
Phased migration to open source midPoint

Microsoft Identity Manager migration is a service for organisations running MIM 2016 that need a supported identity platform before extended support ends on 9 January 2029. Microsoft’s successor, Entra ID Governance, is cloud-only and does not reproduce MIM’s on-premises synchronisation rules, custom workflows or non-Microsoft connectors.

We replace MIM with midPoint, the open source identity governance and administration platform by Evolveum, recognised by Gartner and licensed under Apache 2.0 and the EUPL. Inalogy is one of seven midPoint Gold Partners worldwide and has migrated MIM, SAP IDM and DirX estates across Central and Western Europe.

A MIM migration with us is not a product swap. Each Management Agent becomes a midPoint resource with declarative mappings; years of synchronisation-rule workarounds are replaced by a role model and policies; and the new platform runs in parallel against production data in simulation mode until every difference is understood. Only then do we switch provisioning, one target system at a time.

You keep control of where the platform runs — your data centre, your private cloud, or our managed IAM Factory on German infrastructure — which is what NIS2, DORA and KRITIS auditors increasingly expect from the system that decides who can access what. Typical duration: 3 to 14 months depending on the size of the estate.

What a MIM migration with Inalogy includes

midPoint — open source identity governance platform

Discovery and migration blueprint
Inventory of every Management Agent, synchronisation rule, workflow and connected system; data-quality assessment of the identity store; a blueprint with scope, timeline, risks and budget in 2–4 weeks.

Connector mapping — ECMA2 to ConnId
Each MIM Management Agent is mapped to a midPoint connector: Active Directory, LDAP, databases, flat files, REST and SCIM out of the box; bespoke systems through AI-assisted connector development.

Role model and policies instead of sync rules
Business, application and organisational roles with inheritance; segregation-of-duties and assignment policies enforced at assignment time; HR-driven joiner, mover and leaver processes.

Parallel run with simulation
midPoint reconciles against your production sources read-only while MIM keeps running; simulations show the exact effect of every mapping before cut-over.

Phased cut-over and decommission
Provisioning switches from MIM to midPoint system by system, each verified by automated reconciliation; Management Agents are retired one at a time.

Governance uplift
Access certification campaigns, self-service requests, SoD reporting and audit evidence — capabilities MIM never had and NIS2 and DORA now expect.

Typical MIM estates we migrate

MIM as the AD provisioning engine

HR feed to Active Directory and a handful of targets. Like-for-like replacement in 3–4 months, with governance added on top.

MIM with custom workflows

Years of approval processes and business rules in the MIM portal. Re-expressed as midPoint policies and workflows, usually simpler than the original.

Hybrid and sovereignty-bound

Multiple forests, on-premises applications, regulators asking where the identity platform runs. midPoint on your infrastructure or in the EU.

MIM feeding SAP and legacy systems

Management Agents to SAP, mainframes and bespoke applications. ConnId connectors and AI-assisted connector development cover the long tail.

02

How we migrate MIM to midPoint

PhaseDurationWhat happensOutput
1 — Discovery & assessment2–4 weeksInventory Management Agents, sync rules, workflows, targets; assess data quality; separate what is used from what nobody remembers buildingMigration blueprint
2 — Parallel implementation2–6 monthsStand up midPoint (on-premises, private cloud or IAM Factory); configure connectors; build role model, policies and workflows; connect HR and AD read-only; reconcile and simulatemidPoint validated against production data
3 — Cut-over & decommission2–4 weeksSwitch provisioning per target system; retire Management Agents one by one; verify with automated reconciliation; documentation and knowledge transferMIM switched off
4 — OptimisationongoingCertification campaigns, SoD policies, self-service requests, compliance reporting, administrator trainingModern IGA in operation

Timelines from our engagements: mid-market (1,000–5,000 users, AD plus 3–5 targets) 3–4 months · enterprise (5,000–20,000 users, 10–15 systems, custom workflows) 5–8 months · large enterprise (20,000+ users, multiple forests, 20+ systems) 8–14 months. The biggest variable is organisational readiness, not technology. For the full reasoning, read our guide to replacing Microsoft Identity Manager.

03

Frequently asked questions about MIM migration

When does Microsoft Identity Manager support end?

Extended support for MIM 2016 ends on 9 January 2029 for customers with Entra ID P1/P2 licences. Mainstream support ended in January 2021; since then MIM receives security fixes only. There is no successor release of MIM.

Why not migrate to Entra ID Governance?

Entra ID Governance is cloud-only and built around Entra ID. It does not run on-premises, does not reproduce MIM’s synchronisation rules or custom workflows, and reaches non-Microsoft systems through a narrower set of integrations. It is a good fit for Microsoft-centric estates with simple needs; hybrid landscapes, custom processes and sovereignty requirements usually need a full IGA platform.

Can MIM configuration be imported into midPoint?

Not automatically. Management Agents, sync rules and workflows are re-expressed as midPoint resources, mappings and policies — which removes years of workarounds. midPoint’s simulation mode runs the new configuration against production data read-only, so every difference is reviewed before cut-over.

How long does a MIM to midPoint migration take?

Three to fourteen months depending on the estate: 3–4 months for AD plus a few targets, 5–8 months for an enterprise with custom workflows, 8–14 months for multi-forest estates with 20 or more systems — plus 2–4 weeks of discovery and your procurement cycle.

What does the migration cost?

midPoint has no licence fee. The budget covers discovery, implementation, optional Evolveum subscription and operations (in-house, with us, or as a managed service). Costs do not scale with headcount, which is where the comparison with per-user cloud IGA is decided.

Running MIM and no replacement scoped yet? Ask for a no-obligation Migration Readiness Assessment — let’s talk. Want to know more about our services?

2472Microsoft Identity Manager Migration
SAP IDM Migration
2473Microsoft Identity Manager Migration
midPoint Implementation Partner