we are currently evaluating a migration from an Active Directory profile to a Microsoft Entra ID profile in Netwrix Password Secure and would like to ask whether there are any recommended best practices or migration procedures for this scenario.
We currently authenticate and synchronize users via an Active Directory profile
Our on-premises Active Directory users are synchronized to Microsoft Entra ID via Microsoft Entra Connect
Therefore, the AD user and the Entra ID user represent the same identity from a business perspective.
Password Secure Application Server: Windows Server 2025
Password Secure Client & Web Version: 26.6.100.34161
Successfully provisioned a test group and a test user from Entra ID
After provisioning the test user, we now see two user objects in Password Secure:
User associated with the Active Directory profile
User associated with the Entra ID profile
Although both objects represent the same person, they appear as separate users in Password Secure.
In addition, the user’s personal (test) passwords are only visible under the existing AD-based user object and are not available under the newly provisioned Entra ID user object.
Questions
Licensing
Does this situation consume two licenses, since two user objects exist in Password Secure Or does Password Secure recognize that both accounts belong to the same underlying identity?
User Migration
Is there a supported way to merge or link the AD-based user with the Entra ID-based user?
Can existing permissions, ownerships and personal passwords be transferred from the AD user object to the Entra ID user object?
Best Practice
What is the recommended migration path when moving from an Active Directory profile to an Entra ID profile?
Are there any documented best practices to avoid duplicate users and preserve existing user data?
Hi Sarah, thanks for the detailed write-up!!! This is a known scenario, and the right migration approach can vary depending on your setup, so we’d rather get you sorted properly than give a partial answer here in the community.
Please open a support ticket: our team can walk you through the technical details (authentication, ownership, permissions, user rights, tasks, seals, membership, …); we have a migration tool for specific scenarios; and Professional Services is available if you’d like hands-on help.
On licensing, worth including in the ticket too: support can provide a temporary license, if necessary, to cover the transition.
thank you! Since no one has responded here for a while, I contacted support in the meantime and came to similar conclusions. It’s all a bit unfortunate.
I’ve already contacted support and received answers to my questions. Still, I find the whole situation a bit unfortunate. On the one hand, every user has to migrate their passwords on their own without a backup (or using the Netwrix migration tool, which can only be used in conjunction with support). On the other hand, it’s unfortunate that we’re unable to integrate the new Entra groups into the old roles. I have to assign each user to the roles individually, instead of being able to grant permissions to the new Entra groups (which are added as new roles). In my opinion, that’s a lot of unnecessary work.
Hi Sarah. I agree with you on this. If it takes a lot of manual effort for me and the users, if I have to set up almost everything from scratch, and if there’s only a subscription model in the future, then the barriers to switching to a different password management solution are very low. In fact, running both systems in parallel is probably even easier for migration