Know what migrates before you sign
Point the Identity Mesh analyzer at a Microsoft Identity Manager export. It reads every management agent and flow, tells you whether the estate can move as-is and why, and proposes the connectors, flows, and join rules that replace it. Then cut over one agent at a time.
What the analyzer produces
It observes MIM. It does not write to a database, emit deployable configuration on its own, or estimate hours. The verdict is the product.
A verdict with a reason
The analyzer reads the Sync Engine export, the metaverse schema and every management agent, and answers whether the estate can move as-is. When it cannot, the report names why: for example, that the authoritative HR feed and the largest object type both sit on custom Extensible2 agents that need connector capability before any configuration can be ported.
Counts you can defend
Naive XPath over a MIM export overstates flows by counting join-criterion mappings as flows and understates connectors because one management agent fans out into several. Every count the analyzer reports is structurally anchored and carries the corpus it was measured on.
Proposed connectors, flows, and join rules
Each mappable management agent becomes one or more proposed Identity Mesh connectors, with its join rules, projection rule, filter sets, and anchor attached as data rather than prose. Every proposal carries a verdict and the evidence behind it.
A feature census, ranked
Scripted flows are inventoried by the expression features they need, ranked by how many flows each feature unblocks. That tells you which transforms to prove first and which flows will port automatically.
From assessment to applied decisions
The Admin Portal's Migration page turns the analysis into a saved project. Sources other than MIM are marked as planned in the same page, so the workflow does not change when they arrive.
- Load a MIM export directory and see the analysis in the Admin Portal's Migration page, saved as a migration project you can return to.
- Review the proposed mesh schema, the migration plan grouped by flow, and the decisions per object type before anything is applied.
- Apply decisions to create connectors, flows, and attribute rules. When a decision set cannot be projected, the API says why instead of failing silently.
- Exclude scope you are not migrating, and keep the SQL connector's object-type fan-out collapsed so one MIM SQL agent becomes one Identity Mesh connector.
Parity where MIM customers need it
Multi-partition AD management agents
One Active Directory connector spans a forest, so a MIM agent selecting three partitions becomes one connector and cross-partition group members resolve inside it.
Self-service group management
Owner-managed groups with join policies, approvals, expiry, and audit ship as a portal module.
Password and credential handling
Identity Mesh Vault adds privileged checkout, rotation, and tamper-evident audit inside the same platform.
SQL, file, and HR feeds
Bundled SQL and File connectors are bidirectional. Workday imports today. Custom feeds are built on the Connector SDK.
Side-by-side cutover
Staging mode lets a connector run and export nothing until you confirm it, so agents are decommissioned from MIM one at a time rather than in one weekend.
What a verdict of "not feasible as-is" means
It is not a threshold. It means the estate's hardest identity decisions sit on management agents that have no Identity Mesh connector yet, usually custom Extensible2 code. The report names those agents and the object types they own, so the conversation becomes which connector capability to build, not whether the configuration can be ported.
We would rather tell you that before an engagement is sold than discover it during one.
Send us a MIM export. Get a verdict back.
We run the analyzer against your Sync Engine export and walk you through the report, the proposed connectors, and the flows that port automatically.