Only when the legacy vault has been shown to have no remaining active references across the estate. Completion should be based on decommission evidence, not on the percentage of accounts onboarded into the target platform.
What “complete” means in a PAM migration
A PAM migration is only complete when the old vault or legacy control plane is no longer part of the access path in practice. That means the target platform is not just populated, it is authoritative, and the retired environment has been decommissioned with evidence that no active references remain anywhere the estate can still reach.
The distinction matters because onboarding progress can look healthy while hidden dependencies keep the legacy platform alive. Teams often discover late that scripts, scheduled jobs, break-glass procedures, integrations, or admin shortcuts still point at the old vault even after most users have moved.
Why percentage onboarded is the wrong finish line
Completion is a decommissioning question, not a migration-coverage question. A high onboarded percentage can still leave a few privileged accounts, automation paths, or application secrets tied to the legacy system, which means the old platform remains a real control dependency.
That is why the finish line is not “most accounts moved”, but “no remaining active references.” If a legacy vault can still authenticate, inject secrets, or serve as a fallback path, it is still operational and still part of the risk surface.
For a practical migration path, teams should treat Privileged Access Management Guide and PAM Buyer's Guide as complements: one explains the operating model, the other helps avoid declaring victory before vault-centred and JIT-centred controls are fully separated from the legacy stack.
What evidence proves the old PAM system is really gone
Teams should look for decommission evidence, not dashboard progress. The strongest proof is a clean dependency review showing no applications, scripts, integrations, service accounts, emergency procedures, or admin workflows still reference the legacy vault or its credentials.
That evidence should be backed by operational checks such as failed lookups against the old system, removal of network reachability where appropriate, and confirmed rotation of any secrets that could have been copied out earlier. The migration is not complete until old references are removed and can stay removed.
Useful supporting controls include inventory and governance for service and machine accounts, because hidden references often live in automation rather than user workflows. NHIMG's Service Account Security Guide and Just-in-Time Access and Zero Standing Privilege Guide are especially relevant where legacy PAM is being replaced by time-bound access and better entitlement hygiene.
Risk and Threat Considerations
Leaving a legacy vault active creates a quiet but material exposure: it can preserve standing access, duplicate secrets, and undocumented fallback paths long after the formal migration appears done. That becomes especially dangerous when privileged access, break-glass use, or automation still trusts the retired platform.
Failure mechanism: A team stops at onboarding percentage, but unattended references in scripts, integrations, or emergency procedures keep the old vault reachable, so privileged access can still flow through an unowned path.
Impact: The organisation retains an unnecessary attack surface, complicates incident response, and risks secret reuse, orphaned privilege, or accidental reactivation of a control plane that should no longer exist.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Legacy PAM migration hinges on retiring and rotating credentials and authenticators. |
| AC-2 — Account Management | Completion depends on removing accounts and references tied to the old PAM path. | |
| Recommendation — Retire and rotate credentials so the legacy vault no longer authenticates anything. Revoke or disable any remaining accounts that still depend on the legacy vault. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | A PAM migration must remove obsolete access paths before closure. |
| A.8.2 — Privileged access rights | Privileged access must be fully transitioned off the retired PAM platform. | |
| Recommendation — Validate that access to privileged secrets now flows only through the target control path. Review privileged access rights until the legacy platform has no remaining active use. | ||
Practitioner Guidance
What to verify: Require a named dependency sweep before closure. The team should be able to show where the legacy vault was referenced, what was remediated, and which checks prove those references no longer exist in production and adjacent environments.
Decision rule: If any active reference remains, treat the migration as in progress, not complete. If the only evidence is onboarding percentage, keep the project open until the decommission artefacts are available and independently reviewable.
Common mistake: Declaring success after the last planned migration wave, even though break-glass paths, automation, or old documentation still point at the retired platform. That is how “completed” PAM migrations quietly become long-term dual-running estates.
Practitioner takeaway: A PAM migration ends when the old authority is no longer operational, not when the target platform looks full. Closure should be granted only after the estate proves the legacy path cannot still be used.
Related resources from NHI Mgmt Group
- How should teams reduce risk during a PAM migration?
- How do teams keep a PAM programme from drifting after migration?
- How should IAM and PAM teams decide whether password elimination is complete?
- How should security teams plan a PAM cloud migration without losing control of sensitive data and access continuity?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org