Semperis launches Active Directory migration security tool
Thu, 24th Sep 2026 (Today)
Semperis has launched Migrator for Active Directory 2.0 for organisations moving or consolidating Microsoft Active Directory environments.
The new version frames Active Directory migration as a security issue rather than a routine data transfer project. Migration periods can expose organisations to risks tied to legacy systems, undocumented dependencies, and the temporary overlap of old and new environments.
Active Directory remains a core identity platform for many large organisations, making any change sensitive from both operational and security standpoints. Semperis cited incident response data showing that identity weaknesses contribute to a large share of cyber incidents, while attacks targeting Active Directory authentication tickets have been increasing.
The release has been rebuilt on Kubernetes and introduces several changes to migration management. These include Directory Synchronization Sets for project-scoped, wave-based execution; staging reports that preview changes before they are committed; a Secure Access and Control Agent for endpoint cutover without reimaging; a unified, searchable log across components; and deployment validation to identify infrastructure blockers during setup.
Its focus on staged execution and pre-change visibility reflects broader concern that migration tools have not kept pace with the complexity of modern identity estates. Many organisations now operate mixed environments shaped by acquisitions, legacy applications, and older authentication methods, all of which can complicate consolidation.
Migration risks
One pressure point is the continued presence of older encryption dependencies and service accounts that may not be fully documented. Semperis pointed to the phased deprecation of RC4 encryption in Kerberos as a factor that could expose weaknesses during migration, particularly where organisations still rely on older configurations.
According to the company, these conditions can lead to service account failures, cross-forest authentication breakdowns, and disruption during coexistence between environments. Such issues can be hard to detect in advance if migration tools are designed mainly to move directory objects rather than examine the security and operational assumptions around them.
The issue also has a business dimension. Identity integration often sits at the centre of merger and acquisition activity, where companies are expected to combine systems quickly while keeping core operations running. Semperis said deal timetables often require value to be realised within 12 to 18 months, while full identity integration has traditionally taken 18 to 24 months.
That gap has increased pressure on technology teams to shorten migration timelines without increasing the risk of outages. In regulated sectors, where identity systems can be tied to clinical, financial, or public services, disruption can have broader operational consequences.
Sharp Healthcare, quoted by Semperis, described migration and consolidation as an opportunity to reduce exposure and simplify identity systems. “Migration and consolidation are a major step that companies can take to reduce their attack surface, simplify identity systems and reduce the overall cost of managing multiple IDPs,” said a Sharp Healthcare identity team spokesperson.
The spokesperson added that the software is intended to support that process with greater oversight. “Migrator for AD exists so organizations can consolidate and reduce their attack surface with the control, visibility and security rigor that such a consequential project demands,” the spokesperson said.
Operational focus
Semperis also highlighted the software's role in acquisition-led integrations, where organisations need to synchronise identities across environments without interrupting existing authentication and provisioning processes. That use case reflects a common post-deal challenge: connecting systems before they can be fully standardised.
Sharp Healthcare addressed that point directly. “Migrator synchronizes identities and contacts across environments during an acquisition integration without changing authentication or disrupting existing provisioning workflows,” the spokesperson said.
Michael Masciulli, Managing Director, Migration Products & Services, Semperis, said the main risks in Active Directory migration often sit outside the copy process itself. “The risk in migration was never the copy operation. It's everything the copy operation touches - the service accounts nobody documented, the encryption dependencies nobody audited, the attack paths nobody closed,” Masciulli said.
He said the aim is to identify those issues before they interrupt operations. “Migrator for AD makes those risks visible before they become outages. That's how you come out of a migration stronger, not just moved,” Masciulli said.