AgenorIT
AgenorIT
Consumer Services & Professional PlatformsVictorian Consumer Services PlatformScale: 50,000+ active user identities

Migrating 50,000+ Customer Identities to Microsoft Entra External ID

Zero-downtime identity migration from legacy fragmented SQL stores to Microsoft Entra External ID with conditional access and risk-based MFA.

Executive Summary

Challenge, Approach & Verified Outcome

The Challenge

Managing over 50,000 user credentials in a fragmented SQL database exposed the organisation to credential stuffing risks and failed strict Australian data protection audit requirements.

Our Approach

AgenorIT architected a zero-downtime, staged migration pipeline to Microsoft Entra External ID (Azure AD B2C), seamlessly synchronising hashed credentials into Microsoft hyperscale identity vaults.

The Outcome

50,000+ accounts migrated with zero required password resets, zero unplanned downtime, unified social sign-on (Apple & Google), and automated risk-based conditional access.

Key Performance Metrics

Measured Technical & Operational Impact

50K+
Identities Migrated

Migrated to Microsoft Entra with zero manual password resets required.

Zero
Unplanned Downtime

Phased cutover executed with seamless user session transitions.

100%
Audit Compliance

Aligned with Australian privacy and essential security standards.

< 150ms
Token Issuance Latency

Average OAuth2 / OIDC token issuance latency across Australian regions.

Measurement Provenance & VerificationConfidential Client
Measurement Window: 6-month post-migration production monitoring period (Q4 2025 – Q2 2026).
Telemetry Sources: Azure Monitor Log Analytics (latency & uptime telemetry) and formal ISO 27001 / Essential Eight third-party compliance audit.
Note: Client identity withheld under commercial confidentiality agreement.
Background & Starting Point

Client Context & Environment

A Melbourne-based consumer services firm operating across Victoria managed over 50,000 active customer accounts. The platform had expanded rapidly over five years, accumulating technical debt in its custom-built authentication backend.

User credentials, session states, and permission scopes were stored across relational database tables without modern adaptive rate-limiting, risk telemetry, or centralised identity lifecycle management.

Technical Constraints

The Engineering Challenge

As customer traffic and attack sophistication increased, the engineering team faced severe operational and compliance constraints:

  • Security exposure: Elevated vulnerability to automated credential stuffing and password spraying attacks targeting custom login endpoints.
  • Compliance gap: Australian privacy regulations and institutional partners required verifiable Zero-Trust controls, immutable audit trails, and mandatory MFA capabilities.
  • User experience friction: Custom authentication lacked native social identity integration (Apple ID, Google), resulting in high friction during mobile onboarding.
  • Zero-interruption requirement: The cutover could not invalidate existing customer sessions or force a disruptive bulk password reset.
Engineering Execution

Chronological Delivery & Concrete Artefacts

AgenorIT engineered an end-to-end identity modernised architecture over a phased 8-week engagement:

01

Identity Architecture & Schema Mapping

Designed target user flows in Microsoft Entra External ID, mapping custom profile attributes and role assignments to standard OpenID Connect / OAuth2 claims.

Delivered Artefacts
  • Architecture Decision Record (ADR-04: Entra External ID Topology)
  • Attribute mapping matrix and claims transformation schema
02

Custom Policy & UX Implementation

Configured Entra User Flows and Custom Policies (Identity Experience Framework) branded precisely to the client design system, integrating Apple and Google social providers.

Delivered Artefacts
  • Entra Custom Policy XML definitions in source control
  • Branded HTML/CSS template assets hosted on Azure Blob Storage
03

Just-in-Time & Staged Data Migration

Deployed an API-driven migration harness allowing existing passwords to be verified and re-hashed into Entra upon first login, backed by scheduled bulk migration for dormant accounts.

Delivered Artefacts
  • Migration orchestration Azure Function (TypeScript)
  • Reconciliation script with encrypted audit logging
04

Conditional Access & Telemetry Configuration

Enforced risk-based conditional access policies to require Step-Up MFA only when anomalous geolocation or untrusted devices are detected.

Delivered Artefacts
  • Entra Conditional Access policy definitions
  • Azure Monitor workbook for real-time authentication telemetry
Technology Stack

Components Deployed in Production

Microsoft Entra External ID

Identity

Azure AD B2C / IEF

Custom Policy

OpenID Connect / OAuth 2.0

Protocols

Azure Functions

Migration API

Azure Monitor & Log Analytics

Telemetry

Bicep

IaC

Business & Engineering Results

Verified Outcomes

The new identity architecture completely decoupled user authentication from the core application database, establishing a hardened perimeter backed by Microsoft enterprise security.

  • Over 50,000 active customer records successfully migrated without a single forced password reset.
  • Zero disruption to live transactions and zero downtime during the cutover window.
  • Native Apple and Google sign-in reduced onboarding clicks from 5 steps to 1 tap on mobile devices.
  • Full compliance with Australian privacy standards, backed by real-time risk telemetry and automated attack mitigation.
Direct Senior Engineering Access

Discuss a Similar Architecture for Your Organisation

Speak directly with our principal engineers about architecting your cloud migration, Entra identity system, or high-performance digital product.

Melbourne-based senior engineersStrict confidentialityDirect technical scoping