Get off
MIM.

A complete migration to SailPoint IdentityIQ, proven against your live MIM before you switch it off.

Book a scoping call
  • Independent consultancy
  • Principals: former Microsoft consultants
  • Top Secret cleared, SCI Poly
  • Government and defense contracting

MIM 2016 support ends January 9, 2029

Mainstream support ended January 12, 2021. Since then it has been security updates only, and Microsoft does not accept design changes or new features for products in extended support. If you are still on FIM 2010 or FIM 2010 R2, you have been unsupported since October 11, 2022.

The question is not whether you move. It is whether you move on a plan or on a deadline.

Already broken
  • November 2025The MIM hybrid reporting cloud endpoints went dark.
  • September 30, 2024Entra MFA Server stopped servicing MFA requests, which breaks MIM SSPR and PAM approvals.
  • Silverlight end of lifeThe BHOLD modules go with it.

What you get

A working IdentityIQ site that does what your MIM does, so you can retire MIM.

Not a pile of documentation about your MIM. Not a greenfield rebuild that happens to sit near it. We build the package and we do the creation into the new site. You are not handed a zip and wished well.

Migrating MIM is a discovery problem before it is an engineering problem. The configuration is spread across a synchronization service, a policy service, a portal, and compiled .NET assemblies nobody has opened in years. Most of the cost, and nearly all of the risk, is in finding out what the current system actually does before anyone can rebuild or replace it. That is the part we automated.

Is it perfect? No. What it is: you are off a product with a support end date, running a system that does what MIM was doing.

Watch it work

The role conversion, running end to end. MIM security groups, distribution groups, and criteria based sets becoming SailPoint business roles and IT roles.

Automated group migration from MIM to SailPoint IdentityIQ, a 29 minute demonstration Watch the demonstration, 29 min

What the demonstration covers:

A full migration walkthrough is in production.

What this takes from you

Less than you would expect, and we would rather you know before the call than after.

Your people, for a working session. A few hours with whoever actually knows your joiner, mover and leaver process. This is the only part nobody can do for you, and it is the part that decides whether the result behaves correctly.

Answers to a guided wizard. It scales with your environment. Microsoft's own Contoso Pilot estate produces ten screens and 46 questions, covering scope, correlation and join, joiner, mover, leaver and workflows. Each question arrives prepopulated from your own reports, with the evidence behind it and a confidence score, because MIM spreads one lifecycle event across several policy rules and workflows and consolidating them is a design decision, not a lookup.

Your MIM configuration, exported by your team. The MIM Configuration Documenter sync and service reports, your portal sets and groups, and your connector configuration. Microsoft's own tool, run by your people, on your network.

Your rules-extension source, if you still have it. Most estates do not. The developers left and the project files went with them. We decompile your assemblies, recover the logic, and translate it like any other input. Your own code, from your own binaries, recovered at your direction.

Nothing leaves your network before there is an agreement. When it does, reports are processed in memory and never stored, nothing is written to disk, and nothing is logged.

That is the whole demand on your team, and it is measured in days.

What comes across

MIM conceptBecomes in IdentityIQ
Management agentApplication with schema and connection map
Join rulesCorrelationConfig and correlation rules
Import attribute flowsIdentity attribute sources, in MIM's precedence order
Export attribute flowsProvisioning policies and transformation rules
Sync-rule expressionsFinished, readable BeanShell
Rules extensions in .NETFinished BeanShell
WAL workflows and MPRsWorkflow XML plus IdentityTrigger
Criteria sets over peopleGroupDefinition populations
Run profilesAggregation and refresh tasks
GroupsBusiness and IT roles
Email templatesEmailTemplate XML, HTML preserved

Email templates and the workflows attached to them move together, which matters more than it sounds. Notifications are usually where a migration quietly loses behavior.

The part that refuses to guess

Every piece of MIM logic is either translated faithfully or left as a clearly marked scaffold with the reason recorded. Nothing is approximated.

A subtly wrong attribute rule produces a wrong username or a wrong distinguished name that looks entirely correct in the output and surfaces weeks later in production. So the expression translator supports 70 of the 87 MIM Workflow Activity Library functions and refuses the other 17 on purpose, each with a message explaining why. The .NET translator parses C# with a real grammar specifically so it can detect and decline what it cannot honor.

A scaffold is an honest deliverable. Confidently wrong identity logic is not.

Parsers where it matters, AI where it helps

The translation is done by parsers, not by pattern matching and not by a language model, so the same input always produces the same output. That covers expressions, .NET rules extensions, the groups to roles conversion, and the system documentation.

AI is used in one place, the lifecycle design wizard, where the work is a design conversation rather than a translation.

Parsers where a wrong answer is a wrong distinguished name in production. AI where the work is a design conversation. Never the other way around.

We prove it matches before you switch off MIM

The worry is never really whether the configuration moves. It is whether the new system produces the same answers as the old one.

We run MIM and IdentityIQ side by side. During the parallel run MIM is the only system provisioning to downstream systems. IdentityIQ aggregates, evaluates, and produces the provisioning it would send, but nothing it generates reaches a connected system until you cut over. Parallel running is how you get off MIM, not a period where two systems write to the same targets.

While both are live, Active Directory group membership is verified as unchanged: the groups a user ends up in through IdentityIQ roles are checked against the groups MIM put them in. Connector output is compared too, so what IdentityIQ would send to each connected system is measured against what MIM actually sends, and a difference surfaces in parallel running rather than in production.

MIM stays up, still provisioning, until that comparison satisfies you. You decommission it because you have evidence, not because a project plan says the cutover date arrived.

Fixed fee

We quote a fixed fee, because the scope is not a matter of opinion. It is whatever your MIM does today, moved. That boundary is what makes a fixed price honest.

This is a migration, not a redesign. If you want IdentityIQ to do something MIM never did, that is a different project. It is billed hourly, it extends the schedule, and we will tell you plainly which one you are asking for before you sign anything.

Get off MIM first. Improve second. Trying to do both at once is how these projects turn into years.

What this does not do

Stated plainly, because the honest list is what makes the rest credible.

Who we are

Azure IAM, LLC is an independent identity consulting firm. Identity architecture for corporate, defense, intelligence and education.

Our company puts decades of experience implementing small to large scale identity management systems at the disposal of our customers. We architect, design, and implement secured identity systems for the public and private sectors, the states, and the federal government. Our solutions span on-premises data centers to the cloud.

Why the focus on users? The user identity is the new perimeter. It is the asset to secure and protect against password spray, social engineering, phishing, impersonation, and other sophisticated attacks.

Top Secret cleared, SCI Poly. Former Microsoft consultants. SailPoint IdentityIQ, MIM and FIM, Entra ID, and Okta certified.

The MIM deployments we replace took years to build. We are the consultants who built systems like them.

More about us

Beyond the migration

Migration is not only MIM. We have moved organizations off Okta to Entra ID, and the same discipline applies: know what the current system actually does, prove the new one matches, then switch off the old one.

The rest of what we do:

See all services

Still running MIM?

Book a scoping call. We will tell you what your migration actually involves, before you commit to anything.

Book a scoping call