Azure IAM Maps MIM Action And Authorization Workflows To SailPoint IdentityIQ

via Press Release Distribution Service
ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.

Azure IAM, LLC explains whether Microsoft Identity Manager action and authorization workflows can be rebuilt as SailPoint IdentityIQ workflows, which parts translate automatically, which need a human decision, and why the timing model changes between the two products.

-- Organizations retiring Microsoft Identity Manager (MIM) for SailPoint IdentityIQ eventually open the MIM Portal, count the management policy rules, and ask the same question: can MIM's action workflows and authorization workflows be rebuilt as SailPoint workflows, or does the business logic behind them have to be rediscovered from scratch? Azure IAM, LLC, an independent identity consulting firm, says most of it can be carried across, but not one for one, because the two products disagree about what a workflow is. The firm documents its MIM to SailPoint method at https://azureiam.com/mim-to-sailpoint.

MIM attaches workflows to management policy rules (MPRs). A request MPR can bind three kinds: authentication workflows, which challenge the requester, authorization workflows, which run before a request commits and can block it, and action workflows, which run after the change is committed. A set transition MPR fires an action workflow when an object enters or leaves a set, which is how most MIM estates implement joiner, mover, and leaver processing. IdentityIQ has no MPR. Its workflows are XML objects made of steps, transitions, approvals, and BeanShell, launched by a lifecycle request, a lifecycle event detected during identity refresh, or a task.

That structural difference drives the first finding. According to Azure IAM, MIM typically spreads one lifecycle event across several MPR and workflow pairs, while IdentityIQ expects one workflow per event. The firm's approach classifies each pair as joiner, mover, leaver, or unclassified, records the evidence behind each classification, and puts every pair in front of a human to confirm or correct. Confirmed pairs for one event are merged into a single consolidated workflow, with the already translated BeanShell spliced in rather than regenerated, and nothing silently dropped.

Action workflow activities translate better than most teams expect. MIM's Function Evaluator activities carry real function expressions, and Azure IAM translates those expressions deterministically into BeanShell rather than summarizing them. Email notification activities become IdentityIQ email templates. The leaver workflow gets the most attention: the trigger has to match a transition rather than a state, so that a move from inactive to terminated does not rerun the workflow against an account that is already disabled.

Authorization workflows are a design decision rather than a conversion. A MIM approval activity holds a request until approvers respond, and IdentityIQ models the same intent with approval schemes and work items inside its lifecycle request workflow, routed to a manager, an application owner, a security officer, or a named identity. Azure IAM inventories each authorization workflow, the requests it gates, and who approves, then maps it to the IdentityIQ approval that preserves the control. Filter validation activities that reject bad input usually become form field validation or policy checks rather than a workflow step.

Authentication workflows and custom activities need the most care. Authentication workflows, used for self-service password reset gates, generally do not belong in IdentityIQ at all; in most current estates that function moves to Microsoft Entra ID self-service password reset. Activities from the Microsoft Identity Manager Workflow Activity Library (MIMWAL), common in mature estates, carry function expressions that translate into BeanShell backed by a shared helper library. Custom activities compiled as .NET workflow assemblies, and scripts embedded in PowerShell activities, carry logic no documenter report can see. Azure IAM lists each one in the migration caveats so the logic is reviewed and rebuilt as BeanShell deliberately rather than lost.

Timing also changes. A MIM set transition fires when the request that changes membership is processed. An IdentityIQ lifecycle event fires when an identity refresh task notices the change. Azure IAM states that any process that depends on near real time behavior, such as same day disablement at termination, should be identified during scoping so the refresh schedule is designed around it.

The firm validates converted workflows by running MIM and IdentityIQ in parallel. During that run MIM remains the only system provisioning to downstream systems, while IdentityIQ aggregates, evaluates, and produces the provisioning it would send, so differences in workflow behavior surface before cutover.

Microsoft's extended support for MIM 2016 SP2 runs through January 10, 2029. Estates whose MIM Portal is hosted on SharePoint Server 2019 already face an earlier deadline, because SharePoint Server 2019 reached end of support on July 14, 2026.

Organizations still running MIM workflows can book a scoping call with Azure IAM at https://azureiam.com/contact to see which workflows convert, which merge, and which need a decision before a fixed fee migration quote.

Contact Info:
Name: Robin Lilly
Email: Send Email
Organization: Azure IAM, LLC
Address: 2521 North Main Unit 1-276, Las Cruces, New Mexico 88001, United States
Website: https://azureiam.com

Source: NewsNetwork

Release ID: 89205326

In case of identifying any problems, concerns, or inaccuracies in the content shared in this press release, or if a press release needs to be taken down, we urge you to notify us immediately by contacting error@releasecontact.com (it is important to note that this email is the authorized channel for such matters, sending multiple emails to multiple addresses does not necessarily help expedite your request). Our dedicated team will be readily accessible to address your concerns and take swift action within 8 hours to rectify any issues identified or assist with the removal process. We are committed to delivering high-quality content and ensuring accuracy for our valued readers.

Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article