What comes next?
In the course of the SAP IDM replacement, most companies are currently thinking about tools. Yet the answer to a far more important question is missing: what actually runs through SAP IDM?
SAP has announced the end of life of its identity management system for 2027. At most companies SAP IDM still works today and runs stably. That is not the problem. The problem is the structures that have grown over time, missing documentation, and scarce resources that hardly anyone can keep track of after years.
This only becomes apparent once the migration starts. It causes additional costs and consumes avoidable time and resources.

The four biggest risks in an SAP IDM replacement:
- HR depends on it. ERP too. Various custom solutions anyway. Dependencies only surface during the project, when it gets expensive.
- The process takes at least 12–18 months. Anyone who did not start in 2026 will not be able to meet the end of support cleanly.
- The consultants who can really do such migrations are already in demand. The number of projects is not getting smaller.
- Without updates and patches, the attack surface grows. Compliance requirements are hard to demonstrate with a system that has no support.
Our approach
Tool comes later
We never start with the tool question. Before One Identity, Entra ID, or any other platform comes into play, it must be clear what really needs to be migrated.
Analysis
Analysis of the existing SAP IDM environment, including all dependencies, customizations, and undocumented processes.
Requirements
What does the successor solution have to deliver? NIS2, DORA, GxP, SOX, all compliance requirements are mapped out early.
Platform comparison
Only once the context is clear does a platform comparison make sense. We recommend what fits your landscape, not what sounds good.
Migration
Structured migration with a clear timeline. Ongoing operation after go-live, without a handover vacuum and without loss of knowledge.





