SAP IDM Migration
SAP Identity Management ends mainstream maintenance on 31 December 2027.
We move SAP landscapes to open source midPoint — ABAP, S/4HANA, SuccessFactors and everything around them.
SAP Identity Management ends mainstream maintenance on 31 December 2027.
We move SAP landscapes to open source midPoint — ABAP, S/4HANA, SuccessFactors and everything around them.
SAP IDM migration is a service for organisations running SAP Identity Management 8.0 — the final release — whose mainstream maintenance ends on 31 December 2027, with extended maintenance available at a premium until the end of 2030. SAP’s recommended path, SAP Cloud Identity Services plus Microsoft Entra ID Governance, is cloud-only and SAP-and-Microsoft-centric.
We replace SAP IDM with midPoint, the open source identity governance platform by Evolveum (Slovakia), recognised by Gartner and licensed under Apache 2.0 and the EUPL. As one of seven midPoint Gold Partners worldwide, Inalogy brings the SAP connectivity, the HR-driven lifecycle and the governance layer a modern SAP landscape needs.
SAP IDM usually sits at the centre of the landscape: it provisions users and roles into ECC or S/4HANA, takes its feed from SuccessFactors or another HR system, and reaches non-SAP targets that were added over the years. Replacing it means replacing the identity backbone, so we run the new platform in parallel — reconciled read-only, every mapping simulated against production data — before provisioning switches system by system, ABAP systems last.
The result is a platform that provisions into SAP exactly as before and adds what SAP IDM lacked: business roles across SAP and non-SAP applications, segregation-of-duties enforcement, access certification and an audit trail your NIS2 and DORA auditors can read. Fourteen months remain; a typical enterprise migration takes 6–14 months plus procurement.
What an SAP IDM migration with Inalogy includes
Discovery of the SAP IDM estate
Repositories, tasks, scripts, workflows and every connected system inventoried; data quality of the identity store assessed; role catalogue reviewed. Output: a migration blueprint with scope, calendar, risks and budget.
SAP connectivity validated, not assumed
User and role provisioning into ABAP systems (ECC, S/4HANA) through the ConnId SAP connector; SuccessFactors as HR source or target through REST/SCIM; connector coverage confirmed against a sandbox system in the first weeks.
HR-driven lifecycle and role model
Joiner, mover and leaver processes driven by your HR system; business roles spanning SAP and non-SAP applications; role mining to clean up the catalogue you carry over.
Parallel run and simulation
midPoint reconciles against production read-only while SAP IDM keeps provisioning; every mapping and policy is simulated and the differences reviewed system by system.
Phased cut-over before the deadline
Provisioning switches target by target, ABAP systems last, each verified by automated reconciliation; SAP IDM goes read-only, then off — before 31 December 2027.
Governance SAP IDM never had
Segregation-of-duties policies enforced at assignment time, access certification campaigns, self-service requests and audit evidence for NIS2, DORA and ISO 27001.
Typical SAP IDM landscapes we migrate
SAP IDM provisioning into ECC or S/4HANA
The classic estate: HR feed, ABAP user and role management, Active Directory. Replaced like-for-like, with governance added.
SuccessFactors-driven lifecycle
SuccessFactors as the authoritative source with rehires, multiple contracts and long leave handled in the data model, not in scripts.
SAP plus a dozen non-SAP targets
The systems bolted on over the years — directories, databases, SaaS, bespoke applications — connected through the same ConnId framework.
Regulated and sovereignty-bound
Banks, utilities, public sector under NIS2, DORA or KRITIS that cannot move the keys to their ERP into a non-EU cloud. midPoint on-premises or hosted in the EU.
| When | Phase | What happens | Output |
|---|---|---|---|
| Oct–Nov 2026 | Discovery & assessment | Inventory of repositories, tasks, scripts and targets; data-quality check; role review; procurement in parallel | Migration blueprint |
| Dec 2026–Mar 2027 | Foundation | midPoint environment stood up; HR source and Active Directory connected read-only; SAP connector validated against sandbox; correlation rules and data model agreed | Reconciled identity store |
| Apr–Jul 2027 | Parallel build | Target connectors, business roles, SoD policies, approval workflows; simulations against production data | Provisioning validated for every target |
| Aug–Oct 2027 | Phased cut-over | Provisioning switched one target at a time, ABAP systems last; reconciliation after each switch; self-service and certification enabled | SAP IDM read-only |
| Nov–Dec 2027 | Decommission & hand-over | SAP IDM switched off before the maintenance deadline; documentation, training, operations model | Audit-ready IGA under your control |
Smaller landscapes compress this; multi-entity groups stretch it. Every month of delay comes off the parallel-build phase — the phase that removes risk. Background and the full options comparison: SAP IDM end of life: your options.
Mainstream maintenance for SAP Identity Management 8.0 ends on 31 December 2027; extended maintenance can be bought until 31 December 2030. SAP IDM 8.0 is the final release and SAP has announced no successor product.
SAP Cloud Identity Services for authentication and provisioning and Microsoft Entra ID Governance for governance. Both are cloud-only. They suit cloud-first SAP-plus-Microsoft estates; hybrid landscapes, non-SAP targets and sovereignty requirements usually need a full IGA platform such as midPoint.
Yes. midPoint manages users and roles in ABAP systems through its SAP connector and integrates SuccessFactors through its REST/SCIM APIs. We confirm the exact connector set against your systems during discovery.
Yes — the role catalogue, authoritative-source rules and approval responsibilities carry over. Workflows are redesigned as midPoint policies; custom scripts and manual reconciliation jobs are usually left behind as technical debt.
Six to fourteen months for a typical enterprise estate plus procurement. midPoint has no licence fee; the budget covers discovery, implementation, optional Evolveum subscription and operations — in-house, with us, or as a managed service in the EU.
Still on SAP IDM with no replacement scoped? We assess your landscape and give you a blueprint and calendar within weeks — reach out. Want to know more about our services?