Migrator for Active Directory treats AD migration as a security event — not a data-copy operation — with staged validation, agent-based endpoint cutover, and real-time visibility across the migration lifecycle.
Hoboken, September 23, 2026 — Semperis, the identity-driven cyber resilience and crisis response company, today announced the worldwide availability of Semperis Migrator for Active Directory 2.0, a ground-up architectural rebuild that makes Active Directory (AD)migration observable, controlled and security-centric at every stage.
Active Directory remains the primary identity platform for most global enterprises. Yet identity weaknesses now play a material role in nearly 90 percent of cyber incidents, according to the 2026 Unit 42 Global Incident Response Report, with attacks targeting AD authentication tickets doubling year over year.
That makes the AD migration window—when systems are extended, credentials are in transit, and two environments share a single attack surface—one of the highest-risk phases in the identity lifecycle. Despite this, most migration tooling has not meaningfully changed in over a decade.
This new version of Semperis Migrator for AD is built on Kubernetes and is designed around a central premise: that every object you migrate is a trust boundary crossed.
The release introduces:
- Directory Synchronization Sets (DSS) for project-scoped, wave-based execution
- Staging reports that preview every change before it commits
- A Secure Access and Control Agent for in-place endpoint cutover without reimaging
- A unified searchable log surface across all components
- Deployment validation that surfaces infrastructure blockers during setup instead of mid-migration
“Migration and consolidation are a major step that companies can take to reduce their attack surface, simplify identity systems and reduce the overall cost of managing multiple IDPs,” said a Sharp Healthcare identity team spokesperson. “Migrator for AD exists so organizations can consolidate and reduce their attack surface with the control, visibility and security rigor that such a consequential project demands.”
For regulated industries, Migrator addresses complex identity environments without disrupting critical operations. “Migrator synchronizes identities and contacts across environments during an acquisition integration without changing authentication or disrupting existing provisioning workflows,” added the Sharp Healthcare spokesperson.
Why now
Identity-system attacks are on the rise and with Microsoft’s phased deprecation enforcement of RC4 encryption in Kerberos in effect since July, many organizations are facing a unique exposure risk during migration projects. Those that are still RC4-dependent could face mid-migration service-account failures, cross-forest authentication breakdowns, and coexistence disruptions—issues that most legacy migration tools were never designed to surface. At the same time, M&A-driven identity-integration timelines continue to shrink. Deals typically require value realization within 12–18 months, while full identity integration can traditionally take 18–24 months.
“The risk in migration was never the copy operation. It’s everything the copy operation touches — the service accounts nobody documented, the encryption dependencies nobody audited, the attack paths nobody closed,” said Michael Masciulli, Semperis Managing Director, Migration Products & Services. “Migrator for AD makes those risks visible before they become outages. That’s how you come out of a migration stronger, not just moved.”
Built for global, partner-led delivery
Migrator for Active Directory is designed for a partner-first delivery model. Semperis provides guided deployment, enablement, and certification so delivery partners can execute migration engagements at scale while retaining the customer relationship and deliveryownership. The platform is available worldwide — including regulated industries across North America, Europe, and Asia-Pacific — through Semperis and its partner ecosystem.
Availability
Migrator for Active Directory is available through Semperis and its delivery-partner ecosystem, subject to regional ordering, support, and deployment requirements.
For more information, visit Migrator for Active Directory or contact: Migration@Semperis.com
About Semperis
Semperis is the identity-driven cyber resilience and crisis management company trusted by the world’s largest enterprises and government agencies to protect critical identity systems. Purpose-built for multi-cloud and hybrid identity environments — including Active Directory, Entra ID, Okta, and Ping Identity — Semperis helps organizations prevent, detect, respond to, and recover from identity-based cyberattacks.
Modern cyberattacks are won or lost at the identity layer, where failures now escalate into full-scale business crises. Semperis’ AI-powered platform unifies identity lifecycle defense and crisis management — hardening identity infrastructure, detecting and containing active threats, enabling rapid, trusted recovery, and supporting secure, out-of-band coordination when core systems are disrupted — all reinforced by a world-class identity forensics and incident response team.
As part of its mission to help organizations achieve true cyber resilience, Semperis supports the broader cyber community through the award-winning Hybrid Identity Protection (HIP) Conference and Podcast and free identity security tools including Purple Knight and Forest Druid. More than 1,200 organizations—including over 25% of the 100 largest U.S. companies—rely on Semperis. The company is privately held, headquartered in Hoboken, New Jersey, and serves customers in more than 40 countries.
Learn more: semperis.com
Follow us: Blog / LinkedIn / X / Facebook / YouTube
Media Contact:
Bill Keeler
Semperis
Senior Director, PR & Comms
billk@semperis.com
