Customer Identity Modernisation: Migrating to Microsoft Entra External ID
Phased, seamless identity migration from legacy relational stores to Microsoft Entra External ID with conditional access and risk-based MFA.
Challenge, Approach & Delivery Outcomes
Managing customer credentials in a legacy SQL database exposed the organisation to credential stuffing risks and created friction with modern Australian data protection standards.
AgenorIT architected a phased migration pipeline to Microsoft Entra External ID, synchronising credentials using just-in-time migration hooks into Microsoft hyperscale identity vaults.
Customer accounts transitioned without mandatory password resets for active users, zero major service disruptions, unified social sign-on (Apple & Google), and automated risk-based conditional access.
Measured Technical & Operational Impact
Transitioned active users to Microsoft Entra with zero manual password resets required.
Phased cutover executed with seamless session continuity.
Hardened identity perimeter aligned with Australian privacy principles and modern identity baselines.
Fast OAuth2 / OIDC token issuance latency across Australian regions.
Client Context & Environment
A Melbourne-based consumer services firm operating across Victoria managed tens of thousands of active customer accounts. The platform had expanded rapidly over five years, accumulating technical debt in its custom-built authentication backend.
User credentials, session states, and permission scopes were stored across relational database tables without modern adaptive rate-limiting, risk telemetry, or centralised identity lifecycle management.
The Engineering Challenge
As customer traffic and attack sophistication increased, the client's technical team faced severe operational and compliance constraints:
- Security exposure: Elevated vulnerability to automated credential stuffing and password spraying attacks targeting custom login endpoints.
- Compliance gap: Australian privacy regulations and institutional partners required verifiable Zero-Trust controls, immutable audit trails, and mandatory MFA capabilities.
- User experience friction: Custom authentication lacked native social identity integration (Apple ID, Google), resulting in high friction during mobile onboarding.
- Zero-interruption requirement: The cutover could not invalidate existing customer sessions or force a disruptive bulk password reset.
Chronological Delivery & Concrete Artefacts
AgenorIT engineered an end-to-end identity modernised architecture over a phased 8-week engagement:
Identity Architecture & Schema Mapping
Designed target user flows in Microsoft Entra External ID, mapping custom profile attributes and role assignments to standard OpenID Connect / OAuth2 claims.
- •Architecture Decision Record (ADR-04: Entra External ID Topology)
- •Attribute mapping matrix and claims transformation schema
Custom Policy & UX Implementation
Configured Entra User Flows and Custom Policies (Identity Experience Framework) branded precisely to the client design system, integrating Apple and Google social providers.
- •Entra Custom Policy XML definitions in source control
- •Branded HTML/CSS template assets hosted on Azure Blob Storage
Just-in-Time & Staged Data Migration
Deployed an API-driven migration harness allowing existing passwords to be verified and re-hashed into Entra upon first login, backed by scheduled bulk migration for dormant accounts.
- •Migration orchestration Azure Function (TypeScript)
- •Reconciliation script with encrypted audit logging
Conditional Access & Telemetry Configuration
Enforced risk-based conditional access policies to require Step-Up MFA only when anomalous geolocation or untrusted devices are detected.
- •Entra Conditional Access policy definitions
- •Azure Monitor workbook for real-time authentication telemetry
Components Deployed in Production
Identity
Custom Policy
Protocols
Migration API
Telemetry
IaC
Key Engineering Outcomes
The new identity architecture completely decoupled user authentication from the core application database, establishing a hardened perimeter backed by Microsoft enterprise security.
- Active customer accounts transitioned seamlessly without forced bulk password resets.
- Near-zero disruption during cutover window, with automated fallback safeguards.
- Native Apple and Google sign-in streamlined onboarding to a single tap on mobile devices.
- Hardened identity perimeter aligned with Australian privacy guidelines and risk-based MFA.
Azure AD B2C to Entra External ID Migration Guide
Explore our complete architectural guide covering support timelines, JIT password migration patterns, token authority changes, and cut-over checklists.
Discuss a Similar Architecture for Your Organisation
Speak directly with Gurinder Singh about architecting your cloud migration, Entra identity system, or high-performance digital product.