Use case · Transformation and operations
SAP IDM migration: SailPoint, Saviynt or another target?
SAP Identity Management is reaching the end of mainstream maintenance in 2027, with extended maintenance available until 2030. For organisations that have used it for many years, the question is no longer really whether to prepare an exit, but where to migrate without rebuilding fifteen years of roles, workflows, connectors and exceptions elsewhere.
SailPoint and Saviynt are clearly positioning themselves in this post-SAP IDM market. Microsoft also documents a path to Entra ID Governance. Yet none of these choices should begin with a feature comparison.
The first step is to understand what SAP IDM still does usefully, what should be simplified and what can disappear.
Ariovis supports this journey in France and Belgium, from scoping to operations: current-state analysis, target architecture, technology selection, migration, integration, acceptance testing, cutover and knowledge transfer.
SailPoint and Saviynt are already pursuing SAP IDM customers
This is not simply a reading of the market. Both vendors have built an offering and narrative for organisations that need to modernise identity governance after SAP IDM.
Saviynt addresses this market most directly with an offering explicitly dedicated to replacing SAP Identity Management. One of its public references documents the migration of an international engineering group with more than 46,000 employees whose existing environment relied on SAP IDM. The project notably addressed Joiner / Mover / Leaver processes, provisioning, certifications and access requests. Saviynt reports that the new platform went live in six months, with more than 50,000 status changes automated each year and access provisioning 50% faster.
These figures describe that specific reference. They are not a promise of timeline or outcome for another SAP IDM migration.
SailPoint targets the same market with Identity Security for SAP. The vendor explicitly states that its offering is intended in particular for enterprises seeking an alternative to SAP Identity Management. It covers cloud, hybrid and on-premises SAP environments, with access governance, provisioning, certifications and segregation of duties.
SailPoint’s public references also show significant IAM transformations around SAP, including migrations from legacy IGA systems and environments using SAP SuccessFactors or custom SAP developments. However, we do not present these references as SAP IDM migrations when the public source does not say so.
SailPoint or Saviynt to replace SAP IDM?
| Criterion | SailPoint | Saviynt |
|---|---|---|
| Post-SAP IDM positioning | Identity Security for SAP explicitly targets organisations seeking an alternative to SAP IDM. | Offering and content explicitly dedicated to replacing SAP IDM. |
| Enterprise governance | Very broad IGA coverage across SAP and non-SAP environments. | Very broad IGA coverage across SAP and non-SAP environments. |
| SAP | Governance, provisioning, certification, SoD, and cloud, hybrid and on-premises SAP environments. | SAP governance, provisioning and strong positioning around Application GRC and cross-platform SoD. |
| Model | Identity Security Cloud; IdentityIQ remains available for other architectures. | Cloud is central to the platform’s positioning. |
| Public SAP IDM evidence retained here | The offering explicitly targets this transition; the references discussed here are primarily IAM/SAP transformations. | A direct public reference from SAP IDM in an environment with more than 46,000 employees. |
| Point to challenge | Programme scale, integration, delivery, operations and the real value of functional extensions against the IGA requirement. | Platform breadth, cloud transformation, operations and the ability to avoid rebuilding around IGA domains that can be addressed separately. |
Part of the US identity market is moving towards ever-broader platforms: IGA, PAM, application governance, machine identities, security posture, authorization and other functions are progressively brought under one banner. This strategy may make sense for some organisations. It must not obscure a much more practical question: is the vendor continuing to make its IGA more effective, more operable and easier to industrialise?
When exiting SAP IDM, our priority is not to buy the platform that covers the largest number of IAM categories. It is to rebuild effective identity governance, then select the best capabilities for other domains when they are genuinely needed.
We do not necessarily ask our IGA to become our PAM, authorization engine, Access Management platform and identity security tool. We first ask it to excel at governing identities and entitlements.
Netwrix Identity Manager is an IGA platform designed and historically developed in Europe, focused on governance, lifecycle, roles, requests, provisioning, recertification and compliance. Its relevance in an SAP IDM shortlist therefore does not come from an objective of reducing functionality. It comes from the opportunity to assess a different approach to IGA, developed and operated in close contact with European organisations, alongside major international platforms that are progressively extending their scope into many adjacent domains. This makes it an option to assess, not an automatic winner.
The choice must also take account of the model in which the platform was designed and will be operated. European organisations work within their own governance, regulatory, sovereignty, labour-relations and responsibility-allocation constraints. A multinational company operating in Europe still faces this reality. A solution designed and operated close to this market can therefore offer more than commercial localisation: a different way of thinking about governance, roles, operations and product evolution.
Do not replace SAP IDM with SAP IDM under another logo
SAP IDM often accumulates several generations of rules, roles, scripts, jobs and integrations. Looking for a new platform that can reproduce every object identically may feel reassuring. Above all, it risks carrying functional and technical debt into a new product.
Microsoft’s SAP IDM migration documentation is particularly useful on this point. It does not treat SAP IDM as a single block to be moved: it distinguishes, among other things, the identity store, populations, HR sources, provisioning, self-service, access lifecycle, reporting, federation, directories and extensions.
Ariovis applies this logic regardless of the target. Every component of the existing environment must be assessed against its current usefulness before it is migrated.
- KEEP
- SIMPLIFY
- STANDARDISE
- MOVE
- REMOVE
A migration driven by use cases, not by the product
- 01
Understand SAP IDM
Map sources, populations, roles, privileges, workflows, connectors, custom elements and actual operating practices.
- 02
Build the target
Decide where governance, provisioning, authentication, privileges and authorization will reside tomorrow.
- 03
Prove a real flow
Validate end to end one source, one identity, one application, the associated rules and their operability.
- 04
Migrate in waves
Organise coexistence, acceptance testing, cutovers, decommissioning, knowledge transfer and then operations.
Ariovis prioritises processes before tools, standard capabilities before custom work, data quality as the foundation and a progressive architecture rather than a big bang.
A pragmatic SAP IDM exit in France and Belgium
An SAP IDM migration is won when a historical workflow must be understood, the logic of a role rediscovered, a custom connector migrated, coexistence organised or an application switched without interrupting operations. The delivery model therefore matters as much as the product.
Ariovis works in France and Belgium with continuity across IAM consulting, architecture, integration, project delivery, knowledge transfer and operations. The teams scoping the target therefore understand the constraints of those who will carry out the migration and then operate the platform.
The real risk is not only choosing the wrong solution
An SAP IDM programme can fail with SailPoint. It can fail with Saviynt. It can fail with Entra or any other platform.
The product does not compensate for a misunderstood entitlement model, inconsistent HR sources, absent application owners, uninventoried legacy connectors or an integrator discovering the existing environment during delivery.
Ariovis has already supported an international group of approximately 14,000 identities in an IAM solution selection study. In this highly heterogeneous context, the quality of the vendor-integrator pairing strongly influenced the decision: the ability to integrate locally, industrialise development and genuinely cover the information system mattered as much as the platform itself.
In another study for an international group of approximately 10,000 identities, the conclusion was different: not to buy the new IAM platform that had initially been sought. None of the vendor-integrator proposals offered a sufficiently convincing balance between industrialisation, total cost and the commitment required.
Our role is therefore not to make a vendor win in a table. It is to help the client choose a journey it can genuinely deliver and operate.
Do you already have SailPoint and Saviynt on your shortlist?
We can choose a feature-rich platform when that breadth creates genuine value. We can also prefer a solution more focused on IGA and compose the architecture with other specialised building blocks. The right choice is the one the organisation can integrate, understand, govern and operate sustainably.
For a European organisation, including a multinational one, the ability of a vendor and its ecosystem to understand changes in the European market is part of this equation.
Ariovis can analyse the existing SAP IDM environment, rebuild the genuine selection criteria, challenge the shortlist and construct a defensible decision, an operable architecture and a journey we know how to deliver.
FAQ
Can SailPoint replace SAP IDM?
Yes. SailPoint explicitly positions Identity Security for SAP for organisations undergoing SAP transformation, including those seeking an alternative to SAP Identity Management. Migration nevertheless remains a project to migrate and transform existing roles, entitlements, workflows, connectors and processes.
Can Saviynt replace SAP IDM?
Yes. Saviynt explicitly markets this scenario and notably documents a migration from SAP IDM in an international group with more than 46,000 employees. This does not remove the need to analyse what should genuinely be retained, simplified or removed.
SailPoint or Saviynt to replace SAP IDM?
There is no universal winner. The choice depends on the SAP and non-SAP estate, cloud strategy, role models, segregation of duties, connectors, delivery model, operations and the programme’s total cost.
Should every SAP IDM role and workflow be migrated?
No. Migration is precisely an opportunity to remove roles, workflows, rules and integrations that are no longer useful before rebuilding governance in the target.