Active Directory to Entra ID Account Migration
This document will describe the steps required to migrate Active Directory accounts to Entra ID accounts within Passwordstate.
Introduction
Typically, you would follow this process if you were planning on decommissioning your on-premise Active Directory, and had a requirement to use Entra ID as the one true source for all your domain users and security groups.
This guide will assume you already have Azure Tenant with Entra ID set up, with the appropriate users and security groups.
Passwordstate communicates to Entra ID via the Microsoft Graph API, so your Passwordstate webserver will need outbound traffic to the Microsoft Graph API at https://graph.microsoft.com
Take note of your emergency password under Administration -> Emergency Access. If you accidentally lock yourself out of the system whilst completing this process, you can also log in as the Emergency account and reverse any changes to give you access back to the system.
Please note, once this process is complete your users will be authenticating into Passwordstate using SAML. This login process may look slightly different to how they previously logged in with their Active Directory accounts. It may be beneficial to document and communicate this new login process to your end users.
If needed, you can practice this process in a test environment before attempting in production.
Preparation
This section can be performed at any stage at your own pace, as it will not impact any functionality for your existing users. They can continue to use Passwordstate as per normal, whilst you complete this section.
Go to the screen Administration -> Email Templates, and disable all templates
Next, you will need to add in your Entra ID Provider by following this guide: Security Administration Manual - Add Entra ID Providers (idP)
You will now need to add in your own Entra ID account into Passwordstate, which will give this account full control of the Administration menu. Go to Administration -> User Accounts -> User Actions (button) and select Add Entra ID Users
Search for your own Entra ID account from your Entra Provider, and click Save. If you don’t have enough free licenses when creating new accounts, you can disable any one of the existing user accounts as disabled accounts to free a license up.
With this new account, go to the screen Administration -> Security Administrators, and grant the account access to all roles
Log out of Passwordstate, and then try logging in with this new account as a test. At this point, you should be logged in with your new Entra ID account, and you should have full control of the Administrator menu.
If you have limited number of licenses, go to Administration -> System Settings -> Active Directory & Entra ID and select Yes for the setting called “Disable new user accounts when added into Passwordstate”. This will allow you to add in your new users without consuming a license for each one.
If you were using Active Directory security groups previously for applying permissions throughout the software, then you will need to add in new security groups from Entra ID. These Entra ID security groups should have the equivalent members as their corresponding Active Directory group, as you will be cloning the permissions for these groups later in this guide. Go to the screen Administration -> Security Groups -> Security Group Actions (button) and select Add Entra ID Group. Adding in new groups on this page will immediately sync the members of those groups into Passwordstate.
You can now start adding in Entra ID users individually, if they aren't already present, from the screen Administration -> User Accounts -> User Actions (button) and select Add Entra ID Users. Once this step is finished, you should have one Entra ID account in Passwordstate for each existing Active Directory account.
When cloning permissions for user accounts, there is a feature that can be unlocked which will allow you to move any Private Password Lists from the old user account to the new user account. By default, this feature is not visible, and you will need to send an unlock code to Click Studios support to gain access to this feature.
To unlock this feature, go to Administration -> Feature Access -> Restricted Features tab, and generate a code for the “When cloning user permissions, allow moving of Private Password Lists from source user to destination user” restricted feature. Send this unlock code to Click Studios’ Support, and they will reply with an unlock code.
Once unlocked, you will see an option when cloning users called “Do you wish to move any Private Password Lists from the Source User to the Destination User”.
Cloning Permissions
This section should be completed when no users are using Passwordstate, as you will be cloning user permissions and moving any Private Lists across to the appropriate Entra ID accounts
Go to Administration -> User Accounts -> User Actions (button) and select Clone User Permissions. If you have a large number of users, you can use the Clone Multiple Users button on this page. This requires you to generate and populate a .csv file with all relevant usernames, and reimport it back into Passwordstate.
When cloning permissions, select a source user as the old Active Directory account, and the destination user as the new Entra ID account.
Ensure the option to move Private Password Lists to the destination user account is set to Yes.
If you are using Security Groups, go to the screen Administration -> Security Groups -> Security Group Actions (button) and select Clone Permissions.
Select the Source and Destination Security Group and clone each security group one at a time. This process will clone the permissions for those security groups throughout the software.
You should now turn on SAML authentication as the global authentication option, if it isn’t already. This can be enabled under Administration -> System Settings -> Authentication Options.
If you have limited licenses and previously needed to disable the new Entra ID accounts to free up licenses, you can now disable the old Active Directory accounts, and enable the new Entra ID accounts. This can be done under Administration -> User Accounts.
You can enable/disable one at a time from the Action Menu on each account, or select multiple accounts and use the Toggle Status – Enabled or Disabled option under the Process Selected Items drop down list.
You can also use the Grid Layout Actions menu on this page to display up to 50 users at a time to make this process quicker.
Your system is ready for your Entra ID users to log in and begin using Passwordstate. Ask your users to test logging in and confirm all password lists and folders are visible. The user interface should look exactly the same as it did when they were logging in with their Active Directory accounts. If all looks ok, you can proceed to the next stage.
Final Considerations
If you have followed this guide because you are decommissioning On Premise Active Directory completely from your network, please consider these options below.
Screen Administration -> System Settings -> Email & Proxy servers. Possibly your email server settings may need changing on this page
Screen Administration -> Backups and Upgrades. If you are using this feature, you may need to change the account here which is used to perform the backups.
Are you using Passwordstate to manage privileged Active Directory accounts on your network? You can find this out by running the report called “Show Passwords configured for resets and their dependencies” from the page Administration -> Reporting. If you have any password records set up for this feature, you should delete these records.
Delete any Active Directory Account or Host Discovery Jobs you have set up under Jobs menu
Delete any privileged accounts set up under Administration -> Privileged Account Credentials that are referencing the old domain
Delete the domain itself from the Administration -> Active Directory & Entra ID page.
This completes the process.