FI Finnish
SE Swedish
FR French
PL Polish
DE German
US English (US)

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

English (US)
FI Finnish
SE Swedish
FR French
PL Polish
DE German
US English (US)
  • Log in
  • Home
  • Identity Governance and Administration (IGA)
  • IGA solution library
  • Instructions & guidelines
  • Customer instructions

Customer Instructions for New Cloud Component Migration

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Service Management
    Matrix42 Professional Solution Matrix42 Core Solution Enterprise Service Management Matrix42 Intelligence
  • Identity Governance and Administration (IGA)
    IGA overview IGA solution library
  • Platform
    ESM ESS2 ESS Efecte Chat for Service Management Integrations Add-ons
  • Release Notes for M42 Professional, IGA, Conversational AI
    2026.1 2025.3 2025.2 2025.1 2024.2 2024.1 2023.4 2023.3 2023.2 2023.1 2022.4 2022.3 Release Information and Policies
  • Other Material
    Terms & Documentation Guidelines Accessibility Statements
  • Services
+ More
    • Service Management

    • Identity Governance and Administration (IGA)

    • Platform

    • Release Notes for M42 Professional, IGA, Conversational AI

    • Other Material

    • Services

Customer Instructions for New Cloud Component Migration

In this article is described changes to Customer's Efecte environment if new cloud components (Efecte Secure Access & Efecte Provisioning Engine) are migrated to be used, instead of Efecte Identity Management (EIM). 

Also in this article is described requirements for Customer's Efecte environment, which needs to be fulfilled before migration is possible to implement. 

Efecte has made two ready-made migration packages and if requirements for Productized Migration are not fulfilled, migration impacts to Customer's Efecte environment needs to be evaluated more detailed level in pre-study. 

Efecte Secure Access & Efecte Provisioning Engine has their own component descriptions, which fulfills this documentation and there are several references to those documents. 


Productized Migration Project


Productized Migration Project is ready-made package for migrating new Efecte components to Customers existing Efecte Cloud environment and it contains all needed documentation for the project, definitions, implementation and technical Go-Live. 

Productized Migration project has also pre-requirements for Customers existing Efecte Cloud environment and it contains limited capabilities for authentication, but if some other features are needed, Migration Pre-Study will be better choice to start. 

It is also good to notice, that Productized Migration project needs Customer resources and there are several Customer tasks, which needs to be implemented during the project.  


Technical Requirements for Productized Migration


There are five (5) main categories for requirements that needs to be answered with "Yes". 

1. Requirements for Customers existing Efecte Cloud environment

  • Customers Efecte Cloud environment is in dedicated cloud
  • Either Efecte Provisioning Engine or Efecte Secure Access component are not installed
  • Efecte Identity Management (EIM) component is installed
  • Customer has production and test environment (or only production)
  • Efecte Identity Management (EIM) is used for providing personal and organizational data to Efecte Self-Service Portal
  • Customer's Efecte Service Management Platform is using Python 2.2 (or older version).


2. Requirements for Directory's

  • Customer is only reading user information from AD or Azure AD 
  • There is only one directory instance in use


3. Requirements for Authentication

  • Customer is using AD or Azure AD as Identity Provider
  • Customer is using User Federation, ADFS or Azure AD SSO for authentication


4. Requirements for Customers Efecte solution 

  • Baseline needs to be version xxx.xxx or newer
  • User information from AD or Azure AD is read to Person and AD Group datacards
  • Efecte Service Management roles (ESM Roles) are not managed in Customers AD or Azure AD

5. Customer is NOT using

  • HAKA authentication
  • Local Users
  • Several Efecte Self-Service Portals or Efecte Service Management platforms
  • Some other directory than AD or Azure AD
  • Several AD or Azure AD directory's
  • Password self reset in Efecte Identity Management (EIM)
  • Authentication against another IdP's than AD/AzureAD/ADFS 
  • Users are imported from CSV

Needed Customer Resources


For the Productized Migration project, Customer needs to allocate Project Coordinator, AD or Azure AD Specialist, Authentication Specialist and current Efecte Admins to be participating in the project.

It is also very important to allocate enough time for the participants, so that they are able to perform all needed tasks. Productized Migration project contain detailed level schedule, which helps Customer with resourcing.  


Customer tasks

During Productized Migration project, Customer needs to participate in the project by implementing tasks listed below.

1. AD or Azure AD configuration
Customer needs to update / change AD or Azure AD configuration, according to Customer Instructions provided by Efecte, so that new Efecte Secure Access component will be used in the future time. 

2. Test environment for AD or Azure AD
Productized migration is implemented in Efecte test environment and it is highly recommended to Customer have test environment for AD or Azure AD.

3. Data cleaning
It is very important when migration is implemented, that data content is valid, up to date and cleaned before the project. Especially AD or Azure AD data related to users and groups (and which is used for authentication) and Customer Efecte ITSM solution data needs to be cleaned.  

4. Connections
Needed connections, technical users, VPN-tunnel etc. needs to be created before Productized Migration project start or during it. 

5. List of configuration
Productized Migration contains also needed test environment and if Customer already has existing Efecte test environment, it is updated to same level as Customer production environment. If there is some configuration in Customers Efecte test environment, which Customer wants to be imported back to test environment after environments are updated to same level, Customer needs to provide a list of all configuration that needs to be stored back. 


Customer Responsibilities


1. Data content
Customer is responsible for all data content handled in the migration project. This means that all AD or Azure AD data which is used for authenticating users to Efecte solutions and as a source for personal and organizational information, needs to be up to date and accurate, so that only valid data is imported.


2. Resources
Customers responsible is to allocate enough time for needed Customer resources, according to agreed schedule. 

3. User Approval Testing (UAT)
UAT needs to be performed with high quality and Customer is responsible to organize testing group, test cases, test data etc. 

4. Functional Go-Live
If there are any change requests made to migration scope, Customer is responsible to organize functional Go-Live actions, like for example end-user training or instructions, piloting groups, communication etc. if changes have effect on Customers end-users or admins. 

5. Efecte configuration made by other vendors
If there is any configuration made by other vendors or Customers Efecte admins, it is Customers responsibility to make sure that Efecte is aware of these configurations, before migration project starts. 

Delete

Migration Pre-Study


In the pre-study Efecte consultants evaluates Customers existing environment, where Efecte Identity Management & Efecte Service Management configuration related to users and authentication is investigated, possible changes are listed and work estimated. 

Customer can expect that at least tasks, resources and responsibilities are similar in both Productized and Enterprise migration projects, but they are separately agreed with Customer before the migration project start. 


Migration Pre-Study is needed when, 

1. Customer is using some other functionality or authentication method, which is not mentioned in Productized Migration project. 

2. Productized Migration requirements are not fulfilled

3. Customer (or other vendor) has done complex configuration relating users and authenticating to Efecte solution, which Efecte is not aware


4. Customer wants to have new functionalities or directory services during the migration

5. Customer is using local user login for users to authenticate to Efecte solutions

6. Customer is using Finish HAKA-authentication or similar one in other countries

7. Customer is using local users 

8. Customer is using password self reset in Efecte Identity Management (EIM)

9. Customer is using AD or Azure AD groups for allocating Efecte Service Management roles (ESM roles)


Outcomes for Migration Pre-study:

1. Efecte Consultants agree that new cloud components can be migrated according to Productized Migration

2. Efecte Consultants agree that migration is possible, but it will need extra configuration or installations. Consultants will calculate needed work estimations, Efecte Project Management office will create schedule for the migration project and responsibilities are agreed with Customer. 

3. Efecte Consultants agree that migration will need development to new cloud components and discusses with Efecte's Products unit, about roadmap and schedule for new features and Customer will have estimation when migration would be possible to implement. 

Delete


What changes?

All of these changes listed below are part of Productized Migration project and they apply also in many of the Migration Pre-study cases. 


New Login Window


New login window for Customers Efecte Self-Service Portal & Efecte Service Management users. 

When Efecte Identity Management (EIM) is removed from the Customers existing Efecte environment, new Efecte Secure Access component is used instead for authenticating users to Efecte solutions, build on top of Efecte Service Management platform. More details about Efecte Secure Access components can be read from 
the component description. 

Customer can choose background picture & logo for the login page. 

Delete

Data Flows


With new Efecte Cloud components data is read to new templates (please check also chapter "Two New Templates") IGA Account and IGA Entitlement and only mandatory information is shown on Person template. 


Previously, when Efecte Identity Management (EIM) was used, data was read to AD-group template and straight to Person template. 




Delete

Notice!

Also data flow inside Customers Efecte Cloud has changed within new cloud components. It is described more detailed in the components descriptions. 

Delete

Two New Templates 


When new cloud components are migrated to Customer's Efecte environment, they also bring changes to existing configuration and new capabilities to configure authentication and data reads from directory's (like for example AD or Azure AD).  

New Templates: IGA Account & IGA Entitlement

Currently Customers data from directory's are imported to Person and AD Group datacards, but with new components data is imported to IGA Account and IGA Entitlement datacards. Person datacard is still used after Productized Migration, but there will be changes in attribute level and some of the information that was shown previously on Person datacard, is shown in IGA Account datacard. IGA Entitlement datacard will replace AD-group datacard, which will not be used, after migration and it will be removed or inactivated. 


1. Example of Person datacard, after changes


2. Example of AD-Group datacard, to be removed / inactivated



3. Example of New IGA Entitlement datacard



4. Example of New IGA Account datacard




Delete

Benefits


There are several benefits for using new templates, because they are designed especially for the new Efecte Cloud components. They also allow new better secured user management for Efecte solutions. 


1. With new templates it is possible to manage situations where users may have several accounts to same and / or different directory's, but they all need to relate to only one person in Efecte. If user has several accounts, it is possible to define which account information is used generally in Efecte solutions (like in Person datacard) and which is used for authentication. 


2. The templates also provide better possibility for Customer to configure automation for their Efecte solution user management according to continuously increasing security demands (like for example pseudonymous, which means that user related information can be stored for auditing reason, without user being recognized by personal information). 


3. Possibility to configure better reports and views for data read from the Customer's directory. For example by reading all groups related to O365 licensing, report views can be used for evaluating if there are unused licenses allocated to accounts, which last login data was for example one (1) month ago.  


Delete

Easy Configuration for New Components


Efecte Provisioning Engine is configured entirely from Efecte Service Management platform. Productized Migration project contains same attributes to be configured, as was used with Efecte Identity Management (EIM) component. 

Customer is allowed to use only scheduled-based provisioning, which is described in detailed level in component description. Event-based provisioning needs IGA licenses. 



Attribute mappings for users and group are configured in the same schedulable task.



Efecte Secure Access


Delete

Changes to Customers Efecte Architecture


Efecte cloud architecture stays the same with other components, expect Efecte Identity Management (EIM) is replaced with new Efecte cloud components (Efecte Secure Access & Efecte Provisioning Engine). 

Connection between Efecte Self-Service Portal and Efecte Service Management platform is also renewed and in after migration connection is made via REST API interface. 

Customers Current Efecte Architecture

Customers current Efecte cloud architecture contains several components, which Efecte Identity Management (EIM) is used for authenticating users to Efecte solutions and providing Customers directory (like for example AD) data to Efecte Self-Service Portal and solutions build on top of Efecte Service Management platform (like for example ITSM, HR etc.). 



Customers Efecte Cloud Architecture, after Productized Migration

New Efecte Cloud components (Efecte Secure Access & Efecte Provisioning Engine) and new connector between Efecte Self-Service Portal and Efecte Self-Service Management platform, are used to replace all functions provided by Efecte Identity Management (EIM). 

All current functions related to user authentication and reading Customers user data from directory's are configured to work as they were, but please notice changes which will be shown to Customer's end-users and Efecte admin users.


 


Efecte Cloud Components, after Productized Migration



Delete



Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Efecte Secure Access - Customer instructions for ADFS configuration
  • Secure Access - Customer instructions for Entra ID configuration SAML
  • Efecte Secure Access - Customer instructions for User Federation (AD)
  • Customer Instructions for IGA Project

Copyright 2026 – Matrix42 Professional.

Matrix42 homepage


Knowledge Base Software powered by Helpjuice

0
0
Expand