AgenorIT
AgenorIT
Consumer Services & Professional PlatformsVictorian Consumer Services PlatformScale: Multi-tenant customer account base

Customer Identity Modernisation: Migrating to Microsoft Entra External ID

Phased, seamless identity migration from legacy relational stores to Microsoft Entra External ID with conditional access and risk-based MFA.

Executive Summary

Challenge, Approach & Delivery Outcomes

The Challenge

Managing customer credentials in a legacy SQL database exposed the organisation to credential stuffing risks and created friction with modern Australian data protection standards.

Our Approach

AgenorIT architected a phased migration pipeline to Microsoft Entra External ID, synchronising credentials using just-in-time migration hooks into Microsoft hyperscale identity vaults.

The Outcome

Customer accounts transitioned without mandatory password resets for active users, zero major service disruptions, unified social sign-on (Apple & Google), and automated risk-based conditional access.

Key Performance Metrics

Measured Technical & Operational Impact

JIT Flow
Identity Migration

Transitioned active users to Microsoft Entra with zero manual password resets required.

Near-Zero
Service Disruption

Phased cutover executed with seamless session continuity.

Hardened
Security Alignment

Hardened identity perimeter aligned with Australian privacy principles and modern identity baselines.

Sub-Second
Token Issuance Latency

Fast OAuth2 / OIDC token issuance latency across Australian regions.

Delivery Telemetry & MeasurementConfidential Client
Measurement Window: 6-month post-migration operational monitoring period.
Telemetry Sources: Azure Monitor Log Analytics telemetry and structured cloud architecture verification against Australian baseline identity controls.
Note: Client identity withheld under commercial non-disclosure agreement.
Background & Starting Point

Client Context & Environment

A Melbourne-based consumer services firm operating across Victoria managed tens of thousands of active customer accounts. The platform had expanded rapidly over five years, accumulating technical debt in its custom-built authentication backend.

User credentials, session states, and permission scopes were stored across relational database tables without modern adaptive rate-limiting, risk telemetry, or centralised identity lifecycle management.

Technical Constraints

The Engineering Challenge

As customer traffic and attack sophistication increased, the client's technical team faced severe operational and compliance constraints:

  • Security exposure: Elevated vulnerability to automated credential stuffing and password spraying attacks targeting custom login endpoints.
  • Compliance gap: Australian privacy regulations and institutional partners required verifiable Zero-Trust controls, immutable audit trails, and mandatory MFA capabilities.
  • User experience friction: Custom authentication lacked native social identity integration (Apple ID, Google), resulting in high friction during mobile onboarding.
  • Zero-interruption requirement: The cutover could not invalidate existing customer sessions or force a disruptive bulk password reset.
Engineering Execution

Chronological Delivery & Concrete Artefacts

AgenorIT engineered an end-to-end identity modernised architecture over a phased 8-week engagement:

01

Identity Architecture & Schema Mapping

Designed target user flows in Microsoft Entra External ID, mapping custom profile attributes and role assignments to standard OpenID Connect / OAuth2 claims.

Delivered Artefacts
  • •Architecture Decision Record (ADR-04: Entra External ID Topology)
  • •Attribute mapping matrix and claims transformation schema
02

Custom Policy & UX Implementation

Configured Entra User Flows and Custom Policies (Identity Experience Framework) branded precisely to the client design system, integrating Apple and Google social providers.

Delivered Artefacts
  • •Entra Custom Policy XML definitions in source control
  • •Branded HTML/CSS template assets hosted on Azure Blob Storage
03

Just-in-Time & Staged Data Migration

Deployed an API-driven migration harness allowing existing passwords to be verified and re-hashed into Entra upon first login, backed by scheduled bulk migration for dormant accounts.

Delivered Artefacts
  • •Migration orchestration Azure Function (TypeScript)
  • •Reconciliation script with encrypted audit logging
04

Conditional Access & Telemetry Configuration

Enforced risk-based conditional access policies to require Step-Up MFA only when anomalous geolocation or untrusted devices are detected.

Delivered Artefacts
  • •Entra Conditional Access policy definitions
  • •Azure Monitor workbook for real-time authentication telemetry
Technology Stack

Components Deployed in Production

Microsoft Entra External ID

Identity

Azure AD B2C / IEF

Custom Policy

OpenID Connect / OAuth 2.0

Protocols

Azure Functions

Migration API

Azure Monitor & Log Analytics

Telemetry

Bicep

IaC

Business & Engineering Results

Key Engineering Outcomes

The new identity architecture completely decoupled user authentication from the core application database, establishing a hardened perimeter backed by Microsoft enterprise security.

  • Active customer accounts transitioned seamlessly without forced bulk password resets.
  • Near-zero disruption during cutover window, with automated fallback safeguards.
  • Native Apple and Google sign-in streamlined onboarding to a single tap on mobile devices.
  • Hardened identity perimeter aligned with Australian privacy guidelines and risk-based MFA.
Planning Your Own Migration?

Azure AD B2C to Entra External ID Migration Guide

Explore our complete architectural guide covering support timelines, JIT password migration patterns, token authority changes, and cut-over checklists.

Read B2C to Entra Migration Guide
Direct Technical Consultation

Discuss a Similar Architecture for Your Organisation

Speak directly with Gurinder Singh about architecting your cloud migration, Entra identity system, or high-performance digital product.

Senior Azure architect & vetted specialistsStrict confidentialityDirect technical scoping