Semperis has launched Migrator for Active Directory 2.0. The new architecture treats AD migration as a security and control process, with validation and visibility built into the migration lifecycle.

Active Directory migrations have long been technically complex projects. In addition to transferring user accounts and directory objects, organizations must account for service accounts, authentication mechanisms, encryption dependencies and endpoints. With version 2.0 of Migrator for Active Directory, Semperis aims to address these aspects more explicitly as part of the security process.

According to the company, the new architecture is now available worldwide and is based on Kubernetes. Its underlying approach is that a migration should not be treated simply as a data-copying operation. Instead, each transfer of an object between environments is considered a transition across a trust boundary.

Semperis describes Active Directory as the central identity platform for many global enterprises. The company also cites Unit 42’s Global Incident Response Report 2026, according to which identity weaknesses play a role in almost 90 percent of the cyber incidents examined. Attacks involving Active Directory authentication tickets have also increased, the company says.

The migration window is particularly relevant from a security perspective. During a transition, two environments may operate in parallel, credentials are transferred and additional connections between systems can be established. This can temporarily change the attack surface. Semperis also argues that traditional AD migration tools have seen limited architectural change over an extended period.

Migrator for Active Directory 2.0 combines several functions. Directory Synchronization Sets (DSS) are designed to organize migrations by project and in waves. Staging reports provide a preview of planned changes before they are applied, allowing the target state to be reviewed in advance.

For endpoint transitions, the product includes a Secure Access and Control Agent. The in-place cutover is designed to take place without reimaging devices. A searchable logging interface brings information from the different components together in a single view.

The platform also includes deployment validation. Infrastructure issues can therefore be identified during setup rather than after a migration is already underway. The objective is to expose technical dependencies before the main transition phase begins.

Semperis also points to changes affecting Kerberos encryption as a reason for the new approach. Microsoft has begun the phased retirement of RC4, according to the company. Organizations that still depend on RC4 may encounter issues involving service accounts, cross-forest authentication and coexistence between environments during migration projects.

The duration of identity integration is also relevant in mergers and acquisitions. Semperis says transactions often target value realization within 12 to 18 months, while a complete identity integration has traditionally taken 18 to 24 months. Migration schedules can therefore face both technical and organizational constraints.

“The risk in migration was never the copy operation,” says Michael Masciulli, Managing Director, Migration Products & Services at Semperis. He points instead to undocumented service accounts, encryption dependencies and existing attack paths. The new Migrator is intended to make such factors visible before they result in outages.

Semperis is also positioning the product for a partner-led delivery model. The company says it provides onboarding, training and certification support. Partners can use the platform to deliver migration projects while retaining the customer relationship and responsibility for implementation.

The press release cites Sharp Healthcare as an example of the intended use case. A spokesperson for its identity team describes migration and consolidation as ways to simplify identity environments and reduce the attack surface. During acquisition integrations, the spokesperson says, Migrator can synchronize identities and contacts across environments without changing authentication or disrupting existing provisioning processes.

The product is also aimed at regulated industries. According to Semperis, Migrator for Active Directory is available through Semperis and its partner ecosystem in North America, Europe and the Asia-Pacific region, subject to regional ordering, support and deployment requirements.

With Migrator for Active Directory 2.0, Semperis is shifting the focus from object transfer alone toward controlled migration with validation, logging and security checks.

By Carolina Heyder

Carolina Heyder is a business analyst and moderator with extensive experience in the German and international IT market. She has worked for many years at renowned European trade publishers such as WEKA Fachmedien, Vogel IT Medien, Springer, and Aspencore. She creates content for both web and print media and is an expert in front of the microphone and camera. Thanks to her fluency in German, English, and Spanish, as well as her Chilean roots, she brings a global and intercultural perspective to topics such as cybersecurity, artificial intelligence, digital transformation, sustainability, and other key areas of the IT sector.

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner