Migrating 50,000+ Customer Identities to Microsoft Entra External ID
Zero-downtime identity migration from legacy fragmented SQL stores to Microsoft Entra External ID with conditional access and risk-based MFA.
Challenge, Approach & Verified Outcome
Managing over 50,000 user credentials in a fragmented SQL database exposed the organisation to credential stuffing risks and failed strict Australian data protection audit requirements.
AgenorIT architected a zero-downtime, staged migration pipeline to Microsoft Entra External ID (Azure AD B2C), seamlessly synchronising hashed credentials into Microsoft hyperscale identity vaults.
50,000+ accounts migrated with zero required password resets, zero unplanned downtime, unified social sign-on (Apple & Google), and automated risk-based conditional access.
Measured Technical & Operational Impact
Migrated to Microsoft Entra with zero manual password resets required.
Phased cutover executed with seamless user session transitions.
Aligned with Australian privacy and essential security standards.
Average OAuth2 / OIDC token issuance latency across Australian regions.
Client Context & Environment
A Melbourne-based consumer services firm operating across Victoria managed over 50,000 active customer accounts. The platform had expanded rapidly over five years, accumulating technical debt in its custom-built authentication backend.
User credentials, session states, and permission scopes were stored across relational database tables without modern adaptive rate-limiting, risk telemetry, or centralised identity lifecycle management.
The Engineering Challenge
As customer traffic and attack sophistication increased, the engineering team faced severe operational and compliance constraints:
- Security exposure: Elevated vulnerability to automated credential stuffing and password spraying attacks targeting custom login endpoints.
- Compliance gap: Australian privacy regulations and institutional partners required verifiable Zero-Trust controls, immutable audit trails, and mandatory MFA capabilities.
- User experience friction: Custom authentication lacked native social identity integration (Apple ID, Google), resulting in high friction during mobile onboarding.
- Zero-interruption requirement: The cutover could not invalidate existing customer sessions or force a disruptive bulk password reset.
Chronological Delivery & Concrete Artefacts
AgenorIT engineered an end-to-end identity modernised architecture over a phased 8-week engagement:
Identity Architecture & Schema Mapping
Designed target user flows in Microsoft Entra External ID, mapping custom profile attributes and role assignments to standard OpenID Connect / OAuth2 claims.
- •Architecture Decision Record (ADR-04: Entra External ID Topology)
- •Attribute mapping matrix and claims transformation schema
Custom Policy & UX Implementation
Configured Entra User Flows and Custom Policies (Identity Experience Framework) branded precisely to the client design system, integrating Apple and Google social providers.
- •Entra Custom Policy XML definitions in source control
- •Branded HTML/CSS template assets hosted on Azure Blob Storage
Just-in-Time & Staged Data Migration
Deployed an API-driven migration harness allowing existing passwords to be verified and re-hashed into Entra upon first login, backed by scheduled bulk migration for dormant accounts.
- •Migration orchestration Azure Function (TypeScript)
- •Reconciliation script with encrypted audit logging
Conditional Access & Telemetry Configuration
Enforced risk-based conditional access policies to require Step-Up MFA only when anomalous geolocation or untrusted devices are detected.
- •Entra Conditional Access policy definitions
- •Azure Monitor workbook for real-time authentication telemetry
Components Deployed in Production
Identity
Custom Policy
Protocols
Migration API
Telemetry
IaC
Verified Outcomes
The new identity architecture completely decoupled user authentication from the core application database, establishing a hardened perimeter backed by Microsoft enterprise security.
- Over 50,000 active customer records successfully migrated without a single forced password reset.
- Zero disruption to live transactions and zero downtime during the cutover window.
- Native Apple and Google sign-in reduced onboarding clicks from 5 steps to 1 tap on mobile devices.
- Full compliance with Australian privacy standards, backed by real-time risk telemetry and automated attack mitigation.
Discuss a Similar Architecture for Your Organisation
Speak directly with our principal engineers about architecting your cloud migration, Entra identity system, or high-performance digital product.