Greenfield means rebuilding the ERP environment and processes with a cleaner design, while Brownfield means converting the existing system and preserving more of the current structure. Greenfield usually creates more opportunity to reset access models and controls. Brownfield is faster for continuity, but it can carry forward older role and governance issues.
Why This Matters for Security Teams
Migration choice is not just an ERP delivery decision. It changes how identity, access, and control debt are either reset or carried forward. Greenfield creates a chance to redesign privileged access, secrets handling, and approval paths around current risk, while Brownfield preserves continuity but often preserves legacy entitlements too. That matters because non-human identities are frequently over-permissioned, and old access models tend to survive long after the original business rationale has disappeared.
For security teams, the real issue is whether the migration creates a clean governance baseline or simply repackages existing exposure. NHI Mgmt Group’s Ultimate Guide to NHIs — What are Non-Human Identities notes that 97% of NHIs carry excessive privileges, which is exactly the kind of debt a Brownfield approach can preserve if access is copied forward without redesign. Current guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls supports treating access and configuration as controlled assets, not assumptions.
In practice, many security teams encounter migration risk only after the new environment has already inherited the old one’s weakest controls.
How It Works in Practice
Greenfield migration usually means rebuilding the ERP environment, redesigning integrations, and re-validating who and what should have access. That gives security teams a practical moment to re-establish least privilege, reset service account ownership, replace hard-coded secrets, and map every machine identity to a clear business function. Brownfield migration, by contrast, converts the existing platform in place. It is faster and less disruptive, but it often requires the security team to untangle decades of accumulated roles, technical accounts, and exception-based access.
For NHI governance, the difference is operational. A Greenfield program can apply current standards from day one: separate human and machine access paths, short-lived credentials, rotation policies, and explicit offboarding for service accounts. Brownfield programs need a discovery and containment phase first, because inherited accounts may have broad access that is undocumented or shared across systems. The Ultimate Guide to NHIs — What are Non-Human Identities is useful here because it frames visibility, rotation, and governance as lifecycle controls, not one-time cleanup tasks.
Best practice is to validate the migration path against NIST SP 800-53 Rev 5 Security and Privacy Controls and then translate that into concrete steps:
- Inventory every human and non-human identity before cutover.
- Classify which privileges are required now, not historically.
- Reissue secrets and tokens instead of copying them forward.
- Separate emergency access from day-to-day operational access.
- Test revocation, rotation, and ownership handoff before go-live.
These controls tend to break down when Brownfield migrations span many connected systems because shared accounts, undocumented dependencies, and custom integrations make it hard to remove privilege without causing outages.
Common Variations and Edge Cases
Tighter control during migration often increases delivery effort, requiring organisations to balance speed against the risk of inheriting insecure access paths. That tradeoff is especially visible when the ERP platform supports manufacturing, finance, or third-party integrations that cannot tolerate long outages.
There is no universal standard for whether Greenfield is always “safer” or Brownfield is always “faster.” A Greenfield build can still fail if old processes are simply recreated in a new system. A Brownfield conversion can be acceptable if the team performs full entitlement review, secrets rotation, and post-cutover access validation. The deciding factor is not the label, but whether the migration forces a governance reset.
This is where security and program teams should align on exit criteria. For Greenfield, the question is whether the new environment starts with clean identity design. For Brownfield, the question is whether legacy controls are being actively retired rather than imported. NHI Mgmt Group’s research shows how often organisations leave secrets and service accounts exposed in vulnerable locations, which is why migration is a governance event as much as a technical one.
When the ERP estate includes third parties, old middleware, or manual exception handling, Brownfield migrations often preserve the very access patterns that security leaders were hoping to eliminate.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Migration can duplicate overprivileged service accounts and secrets. |
| NIST CSF 2.0 | PR.AC-4 | Access control must be revalidated during ERP migration. |
| NIST AI RMF | GOVERN | Migration decisions need governance for inherited identity risk. |
| NIST Zero Trust (SP 800-207) | SA-4 | Brownfield migrations often preserve trust assumptions that Zero Trust rejects. |
| CSA MAESTRO | Programmatic governance helps control identity sprawl during transformation. |
Apply lifecycle controls to machine identities and service integrations throughout migration.
Related resources from NHI Mgmt Group
- What is the difference between greenfield, brownfield, and bluefield ERP migration approaches for security and governance teams?
- What is the difference between greenfield, brownfield, and hybrid SAP S/4HANA migration approaches?
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?