Semperis, the identity-driven cyber resilience and crisis response company, today announced the worldwide availability of Semperis Migrator for Active Directory 2.0, a ground-up architectural rebuild that makes Active Directory migration observable, controlled and security-centric at every stage.
Migrator for Active Directory treats AD migration as a security event — not a data-copy operation — with staged validation, agent-based endpoint cutover, and real-time visibility across the migration lifecycle.
Active Directory remains the primary identity platform for most global enterprises. Yet identity weaknesses now play a material role in nearly 90 percent of cyber incidents, according to the 2026 Unit 42 Global Incident Response Report, with attacks targeting AD authentication tickets doubling year over year.
That makes the AD migration window—when systems are extended, credentials are in transit, and two environments share a single attack surface—one of the highest-risk phases in the identity lifecycle. Despite this, most migration tooling has not meaningfully changed in over a decade.
This new version of Semperis Migrator for AD is built on Kubernetes and is designed around a central premise: that every object you migrate is a trust boundary crossed.
"Migration and consolidation are a major step that companies can take to reduce their attack surface, simplify identity systems and reduce the overall cost of managing multiple IDPs," said a Sharp Healthcare identity team spokesperson. "Migrator for AD exists so organizations can consolidate and reduce their attack surface with the control, visibility and security rigor that such a consequential project demands."
For regulated industries, Migrator addresses complex identity environments without disrupting critical operations. "Migrator synchronizes identities and contacts across environments during an acquisition integration without changing authentication or disrupting existing provisioning workflows," added the Sharp Healthcare spokesperson.
The release introduces Directory Synchronization Sets (DSS) for project-scoped, wave-based execution, staging reports that preview every change before it commits, a Secure Access and Control Agent for in-place endpoint cutover without reimaging, a unified searchable log surface across all components, and deployment validation that surfaces infrastructure blockers during setup instead of mid-migration.
Identity-system attacks are on the rise and with Microsoft's phased deprecation enforcement of RC4 encryption in Kerberos in effect since July, many organizations are facing a unique exposure risk during migration projects. Those that are still RC4-dependent could face mid-migration service-account failures, cross-forest authentication breakdowns, and coexistence disruptions—issues that most legacy migration tools were never designed to surface. At the same time, M&A-driven identity-integration timelines continue to shrink. Deals typically require value realization within 12–18 months, while full identity integration can traditionally take 18–24 months.
"The risk in migration was never the copy operation. It's everything the copy operation touches — the service accounts nobody documented, the encryption dependencies nobody audited, the attack paths nobody closed," said Michael Masciulli, Semperis Managing Director, Migration Products & Services. "Migrator for AD makes those risks visible before they become outages. That's how you come out of a migration stronger, not just moved."
Migrator for Active Directory is designed for a partner-first delivery model. Semperis provides guided deployment, enablement, and certification so delivery partners can execute migration engagements at scale while retaining the customer relationship and delivery ownership. The platform is available worldwide — including regulated industries across North America, Europe, and Asia-Pacific — through Semperis and its partner ecosystem.
Migrator for Active Directory is available through Semperis and its delivery-partner ecosystem, subject to regional ordering, support, and deployment requirements.
About Semperis
Semperis is the identity-driven cyber resilience and crisis management company trusted by the world's largest enterprises and government agencies to protect critical identity systems. Purpose-built for multi-cloud and hybrid identity environments—including Active Directory, Entra ID, Okta, and Ping Identity—Semperis helps organizations prevent, detect, respond to, and recover from identity-based cyberattacks.