Back to Blog // deployment

Migrating from Active Directory and LDAP Without Downtime

Replacing a directory is daunting because identity is load-bearing. Here is how Veripass lets you migrate from Active Directory and LDAP through federation and provisioning, without a hard cutover.

June 16, 2025 · Veripass
Migrating from Active Directory and LDAP Without Downtime

Migrating off Active Directory or LDAP feels risky for a simple reason: identity is load-bearing. Every application, every login, and every access decision runs through it, so a clumsy cutover does not just inconvenience users — it locks them out. The way to migrate without downtime is to avoid the cutover entirely and move through federation and provisioning instead.

Why the big-bang cutover fails

The instinct is to pick a date, move everyone to the new system, and switch off the old one. In practice that approach concentrates all the risk into a single moment. If anything is wrong — a missed group, a mismapped attribute, an application no one remembered was wired to the old directory — the failure is total and immediate, and the rollback is just as disruptive as the migration.

A no-downtime migration does the opposite. It lets the old directory keep working while the new model is stood up alongside it, so the two coexist during the transition and access never depends on a single switch.

Federate first, migrate gradually

The first move with Veripass is not to replace the directory — it is to federate with it. Veripass federates over OIDC with Microsoft Entra ID and Google Workspace and supports SAML and OIDC for authentication. For an organization whose identity already lives in Entra ID, that means users keep authenticating against their existing directory while Veripass takes over cross-application federation, authorization, and audit.

This decouples two things that a big-bang migration forces together: changing where users authenticate, and changing how access is governed. With Veripass you can adopt the new governance model first, with the existing directory still authoritative, and move the source of truth later — or leave it where it is.

Let SCIM carry the lifecycle

The part of a directory migration that goes wrong most often is account lifecycle: users who were never created in the new system, or who were left enabled in the old one. SCIM is the answer. Veripass provisions accounts over SCIM, so creation, updates, and deprovisioning flow automatically rather than being reconciled by hand.

During a migration this matters twice over. It keeps account state consistent as you transition, and it ensures that when you do retire the old directory, deprovisioning is handled cleanly instead of leaving orphaned accounts behind.

A staged path

A no-downtime migration with Veripass tends to follow the same shape:

  • Federate. Connect Veripass to the existing Active Directory or LDAP estate over OIDC/SAML so users authenticate as they always have.
  • Adopt governance. Move authorization onto the composable model — claims, capabilities, roles, access profiles — and turn on context-aware policy and step-up where it matters.
  • Provision over SCIM. Bring account lifecycle under SCIM so creation and deprovisioning are automated.
  • Shift the source of truth when ready. Move the authoritative directory on your own timeline, knowing federation and provisioning are already carrying the load.
  • Retire the legacy directory only once nothing depends on it, with SCIM ensuring clean deprovisioning.

At no point in this sequence is there a single moment where access depends on a switch being thrown correctly. Each stage is reversible, each is observable through the immutable audit trail, and the old directory keeps working until you genuinely no longer need it. That is what “without downtime” means in practice — not a flawless cutover, but a migration that never required one.

Keep reading

Hybrid and On-Premise Identity Without Lock-In

Hybrid and On-Premise Identity Without Lock-In

Not every workload belongs in the cloud. Here is how Veripass runs the same federation, policy, and audit model across cloud, on-premise, and hybrid deployments.

Architecture Overview: Federating Identities at Scale

Architecture Overview: Federating Identities at Scale

How Veripass federates identities across many applications and organizations from a single multi-tenant control plane, without forcing every team onto one directory.

Audit Trails That Survive an Audit

Audit Trails That Survive an Audit

An audit trail is only useful if it holds up when someone actually audits it. Here is what makes Veripass audit records immutable, attributable, and reconstructable.