Local Logins to Entra ID Account Migration
This document will describe the steps required to migrate Local Passwordstate accounts to Entra ID accounts within Passwordstate.
Introduction
This guide will assume you already have Azure Tenant with Entra ID set up, with the equivalent users and security groups.
Passwordstate communicates to Entra ID via the Microsoft Graph API, so your Passwordstate webserver will need outbound traffic to the Microsoft Graph API at https://graph.microsoft.com
Take note of your emergency password under Administration -> Emergency Access. If you accidentally lock yourself out of the system whilst completing this process, you can also log in as the Emergency account and reverse any changes to give you access back to the system.
Please note, once this process is complete your users will be authenticating into Passwordstate using SAML. This login process may look slightly different to how they previously logged in with their local accounts. It may be beneficial to document and communicate this new login process to your end users.
If needed, you can practice this process in a test environment before attempting in production.
Preparation
This section can be performed at any stage at your own pace, as it will not impact any functionality for your existing users. They can continue to use Passwordstate as per normal, whilst you complete this section.
Go to the screen Administration -> Email Templates, and disable all templates
Next, you will need to add in your Entra ID Provider by following this guide: Security Administration Manual - Add Entra ID Providers (idP)
You will now need to add in your own Entra ID account into Passwordstate, which will give this account full control of the Administration menu. Go to Administration -> User Accounts -> User Actions (button) and select Add Entra ID Users
Search for your own Entra ID account from your Entra Domain, and click Save. If you don’t have enough free licenses when creating new accounts, you can disable any one of the existing user accounts as disabled accounts to free a license up.
With this new account, go to the screen Administration -> Security Administrators, and grant the account access to all roles
Log out of Passwordstate, and then try logging in with this new account as a test. At this point, you should be logged in with your new Entra ID account, and you should have full control of the Administrator menu.
If you have limited number of licenses, go to Administration -> System Settings -> Active Directory & Entra ID and select Yes for the setting called “Disable new user accounts when added into Passwordstate”. This will allow you to add in your new users without consuming a license for each one.
If you were using Local Passwordstate security groups previously for applying permissions throughout the software, then you will need to add in new security groups from Entra ID. These Entra ID security groups should have the equivalent members as their corresponding Local Passwordstate group, as you will be cloning the permissions for these groups later in this guide. Go to the screen Administration -> Security Groups -> Security Group Actions (button) and select Add Entra ID Group. Adding in new groups on this page will immediately sync the members of those groups into Passwordstate.
You can now start adding in Entra ID users individually, if they aren't already present, from the screen Administration -> User Accounts -> User Actions (button) and select Add Entra ID Users. Once this step is finished, you should have one Entra ID account in Passwordstate for each existing Local account.
When cloning permissions for user accounts, there is a feature that can be unlocked which will allow you to move any Private Password Lists from the old user account to the new user account. By default, this feature is not visible, and you will need to send an unlock code to Click Studios support to gain access to this feature.
To unlock this feature, go to Administration -> Feature Access -> Restricted Features tab, and generate a code for the “When cloning user permissions, allow moving of Private Password Lists from source user to destination user” restricted feature. Send this unlock code to Click Studios’ Support, and they will reply with an unlock code.
Once unlocked, you will see an option when cloning users called “Do you wish to move any Private Password Lists from the Source User to the Destination User”.
Cloning Permissions
This section should be completed when no users are using Passwordstate, as you will be cloning user permissions and moving any Private Lists across to the Entra ID accounts
Go to Administration -> User Accounts -> User Actions (button) and select Clone User Permissions. If you have a large number of users, you can use the Clone Multiple Users button on this page. This requires you to generate and populate a .csv file with all relevant usernames, and reimport it back into Passwordstate.
When cloning permissions, select a source user as the old Local account, and the destination user as the new Entra ID account.
Ensure the option to move Private Password List to the destination user account is set to Yes.
If you are using Security Groups, go to the screen Administration -> Security Groups -> Security Group Actions (button) and select Clone Permissions.
Select the Source and Destination Security Group and clone each security group one at a time. This process will clone the permissions for those security groups throughout the software.
You should now turn on SAML authentication as the global authentication option, if it isn’t already. This can be enabled under Administration -> System Settings -> Authentication Options.
If you have limited licenses and previously needed to disable the new Entra ID accounts to free up licenses, you can now disable the old Local accounts, and enable the new Entra ID accounts. This can be done under Administration -> User Accounts.
You can enable/disable one at a time from the Action Menu on each account, or select multiple accounts and use the Toggle Status – Enabled or Disabled option under the Process Selected Items drop down list.
You can also use the Grid Layout Actions menu on this page to display up to 50 users at a time to make this process quicker.
Your system is ready for your Entra ID users to log in and begin using Passwordstate. Ask your users to test logging in and confirm all password lists and folders are visible. The user interface should look exactly the same as it did when they were logging in with their Local Passwordstate accounts.
Once your users have tested and confirmed all is working well, you can now delete the old Local user accounts and Local Security groups, if applicable.