Best Practices for Migrating Users from Active Directory Profile to Entra ID Profile

Hello Netwrix Team & Community,

we are currently evaluating a migration from an Active Directory profile to a Microsoft Entra ID profile in Netwrix Password Secure and would like to ask whether there are any recommended best practices or migration procedures for this scenario.

  • We currently authenticate and synchronize users via an Active Directory profile
  • Our on-premises Active Directory users are synchronized to Microsoft Entra ID via Microsoft Entra Connect
  • Therefore, the AD user and the Entra ID user represent the same identity from a business perspective.
  • Password Secure Application Server: Windows Server 2025
  • Password Secure Client & Web Version: 26.6.100.34161

Following the Netwrix documentation for Microsoft Entra ID integration, we have:

  • Created the Entra ID profile in Password Secure
  • Configured SCIM provisioning via App Registration
  • Successfully provisioned a test group and a test user from Entra ID

After provisioning the test user, we now see two user objects in Password Secure:

  1. User associated with the Active Directory profile
  2. User associated with the Entra ID profile

Although both objects represent the same person, they appear as separate users in Password Secure.

In addition, the user’s personal (test) passwords are only visible under the existing AD-based user object and are not available under the newly provisioned Entra ID user object.

Questions

  1. Licensing

    • Does this situation consume two licenses, since two user objects exist in Password Secure Or does Password Secure recognize that both accounts belong to the same underlying identity?
  2. User Migration

    • Is there a supported way to merge or link the AD-based user with the Entra ID-based user?
    • Can existing permissions, ownerships and personal passwords be transferred from the AD user object to the Entra ID user object?
  3. Best Practice

    • What is the recommended migration path when moving from an Active Directory profile to an Entra ID profile?
    • Are there any documented best practices to avoid duplicate users and preserve existing user data?

Thank you!

Kind regards,

Sarah Dreiucker

  1. Two licenses, the users are complety seperated from each other. There is no mapping or connection between both users (same person).
  2. there is no automated way…
  3. there is no documentation for this… Every user has to handover his passwords to his alter ego…

Hi Sarah, thanks for the detailed write-up!!! This is a known scenario, and the right migration approach can vary depending on your setup, so we’d rather get you sorted properly than give a partial answer here in the community.

Please open a support ticket: our team can walk you through the technical details (authentication, ownership, permissions, user rights, tasks, seals, membership, …); we have a migration tool for specific scenarios; and Professional Services is available if you’d like hands-on help.

On licensing, worth including in the ticket too: support can provide a temporary license, if necessary, to cover the transition.

Cheers,
-sascha

Hi Martin,

thank you! Since no one has responded here for a while, I contacted support in the meantime and came to similar conclusions. It’s all a bit unfortunate.

Hi Sascha,

I’ve already contacted support and received answers to my questions. Still, I find the whole situation a bit unfortunate. On the one hand, every user has to migrate their passwords on their own without a backup (or using the Netwrix migration tool, which can only be used in conjunction with support). On the other hand, it’s unfortunate that we’re unable to integrate the new Entra groups into the old roles. I have to assign each user to the roles individually, instead of being able to grant permissions to the new Entra groups (which are added as new roles). In my opinion, that’s a lot of unnecessary work.

Hi Sarah. I agree with you on this. If it takes a lot of manual effort for me and the users, if I have to set up almost everything from scratch, and if there’s only a subscription model in the future, then the barriers to switching to a different password management solution are very low. In fact, running both systems in parallel is probably even easier for migration :slight_smile:

@SaschaMartens: this is something to think about.

Hello @bhn3ucker ! Please review How to do Hard match in Dirsync? | Microsoft Learn for proper way of matching on-prem and cloud user thus making them a single entity :slight_smile: :classical_building: