02
Identity Management System replacement case study at orange Slovensko

SAP IDM Migration

SAP Identity Management ends mainstream maintenance on 31 December 2027.
We move SAP landscapes to open source midPoint — ABAP, S/4HANA, SuccessFactors and everything around them.

Identity Management System replacement case study at orange Slovensko

SAP has no successor for SAP IDM.
We migrate SAP landscapes to midPoint

SAP IDM migration is a service for organisations running SAP Identity Management 8.0 — the final release — whose mainstream maintenance ends on 31 December 2027, with extended maintenance available at a premium until the end of 2030. SAP’s recommended path, SAP Cloud Identity Services plus Microsoft Entra ID Governance, is cloud-only and SAP-and-Microsoft-centric.

We replace SAP IDM with midPoint, the open source identity governance platform by Evolveum (Slovakia), recognised by Gartner and licensed under Apache 2.0 and the EUPL. As one of seven midPoint Gold Partners worldwide, Inalogy brings the SAP connectivity, the HR-driven lifecycle and the governance layer a modern SAP landscape needs.

SAP IDM usually sits at the centre of the landscape: it provisions users and roles into ECC or S/4HANA, takes its feed from SuccessFactors or another HR system, and reaches non-SAP targets that were added over the years. Replacing it means replacing the identity backbone, so we run the new platform in parallel — reconciled read-only, every mapping simulated against production data — before provisioning switches system by system, ABAP systems last.

The result is a platform that provisions into SAP exactly as before and adds what SAP IDM lacked: business roles across SAP and non-SAP applications, segregation-of-duties enforcement, access certification and an audit trail your NIS2 and DORA auditors can read. Fourteen months remain; a typical enterprise migration takes 6–14 months plus procurement.

What an SAP IDM migration with Inalogy includes

midPoint — open source identity governance platform

Discovery of the SAP IDM estate
Repositories, tasks, scripts, workflows and every connected system inventoried; data quality of the identity store assessed; role catalogue reviewed. Output: a migration blueprint with scope, calendar, risks and budget.

SAP connectivity validated, not assumed
User and role provisioning into ABAP systems (ECC, S/4HANA) through the ConnId SAP connector; SuccessFactors as HR source or target through REST/SCIM; connector coverage confirmed against a sandbox system in the first weeks.

HR-driven lifecycle and role model
Joiner, mover and leaver processes driven by your HR system; business roles spanning SAP and non-SAP applications; role mining to clean up the catalogue you carry over.

Parallel run and simulation
midPoint reconciles against production read-only while SAP IDM keeps provisioning; every mapping and policy is simulated and the differences reviewed system by system.

Phased cut-over before the deadline
Provisioning switches target by target, ABAP systems last, each verified by automated reconciliation; SAP IDM goes read-only, then off — before 31 December 2027.

Governance SAP IDM never had
Segregation-of-duties policies enforced at assignment time, access certification campaigns, self-service requests and audit evidence for NIS2, DORA and ISO 27001.

Typical SAP IDM landscapes we migrate

SAP IDM provisioning into ECC or S/4HANA

The classic estate: HR feed, ABAP user and role management, Active Directory. Replaced like-for-like, with governance added.

SuccessFactors-driven lifecycle

SuccessFactors as the authoritative source with rehires, multiple contracts and long leave handled in the data model, not in scripts.

SAP plus a dozen non-SAP targets

The systems bolted on over the years — directories, databases, SaaS, bespoke applications — connected through the same ConnId framework.

Regulated and sovereignty-bound

Banks, utilities, public sector under NIS2, DORA or KRITIS that cannot move the keys to their ERP into a non-EU cloud. midPoint on-premises or hosted in the EU.

03

A 14-month calendar: from decision to a decommissioned SAP IDM

WhenPhaseWhat happensOutput
Oct–Nov 2026Discovery & assessmentInventory of repositories, tasks, scripts and targets; data-quality check; role review; procurement in parallelMigration blueprint
Dec 2026–Mar 2027FoundationmidPoint environment stood up; HR source and Active Directory connected read-only; SAP connector validated against sandbox; correlation rules and data model agreedReconciled identity store
Apr–Jul 2027Parallel buildTarget connectors, business roles, SoD policies, approval workflows; simulations against production dataProvisioning validated for every target
Aug–Oct 2027Phased cut-overProvisioning switched one target at a time, ABAP systems last; reconciliation after each switch; self-service and certification enabledSAP IDM read-only
Nov–Dec 2027Decommission & hand-overSAP IDM switched off before the maintenance deadline; documentation, training, operations modelAudit-ready IGA under your control

Smaller landscapes compress this; multi-entity groups stretch it. Every month of delay comes off the parallel-build phase — the phase that removes risk. Background and the full options comparison: SAP IDM end of life: your options.

04

Frequently asked questions about SAP IDM migration

When is SAP IDM end of life?

Mainstream maintenance for SAP Identity Management 8.0 ends on 31 December 2027; extended maintenance can be bought until 31 December 2030. SAP IDM 8.0 is the final release and SAP has announced no successor product.

What does SAP recommend instead?

SAP Cloud Identity Services for authentication and provisioning and Microsoft Entra ID Governance for governance. Both are cloud-only. They suit cloud-first SAP-plus-Microsoft estates; hybrid landscapes, non-SAP targets and sovereignty requirements usually need a full IGA platform such as midPoint.

Can midPoint provision into S/4HANA and use SuccessFactors as the HR source?

Yes. midPoint manages users and roles in ABAP systems through its SAP connector and integrates SuccessFactors through its REST/SCIM APIs. We confirm the exact connector set against your systems during discovery.

Can we keep our SAP IDM business roles?

Yes — the role catalogue, authoritative-source rules and approval responsibilities carry over. Workflows are redesigned as midPoint policies; custom scripts and manual reconciliation jobs are usually left behind as technical debt.

How long does the migration take and what does it cost?

Six to fourteen months for a typical enterprise estate plus procurement. midPoint has no licence fee; the budget covers discovery, implementation, optional Evolveum subscription and operations — in-house, with us, or as a managed service in the EU.

Still on SAP IDM with no replacement scoped? We assess your landscape and give you a blueprint and calendar within weeks — reach out. Want to know more about our services?

2471SAP IDM Migration
Microsoft Identity Manager Migration
2473SAP IDM Migration
midPoint Implementation Partner