SAML2 Integration Migration Guide

SAML2 Integration Migration Guide 

As part of an ongoing platform modernization effort, Frame is migrating SAML2 authentication services to a new domain structure. 

This change is required because Frame is discontinuing the use of legacy nutanix.com-based domains for authentication services. As a result, existing SAML2 integrations must be migrated to new domains to ensure continued and supported operation. 

   - In the US region, this change affects authentication endpoints under the img.frame.nutanix.com domain.
   - In the DEU region, the authentication service is being moved to a subdomain that already hosts the Frame backend.
     This simplifies the overall domain structure used for user authentication. 

The updated domain structure simplifies network configuration, particularly for customers with on‑premises desktop deployments that rely on strict network allow‑listing. 

To minimize disruption, the migration process allows you to: 


Migration Overview 

The migration is performed by creating a new SAML2 integration alongside the existing one, validating it, and then migrating data from the old (source) integration to the new (target) integration. 

At a high level, the process consists of the following phases: 

  1. Create and configure a new SAML2 integration 
  2. Verify that the new integration works as expected 
  3. Migrate users and permissions from the old integration 
  4. Validate end-user access 
  5. Decommission the old integration 

Each phase is described in detail below. 

1. Create a New SAML2 Integration 

Start by creating a new SAML2 integration in Frame. 

Configure the integration according to the SAML2 documentation. 

At this stage, the existing SAML2 integration should remain active and unchanged. 

 

2. Verify the New Integration 

Once the new SAML2 integration is configured: 

Only proceed to migration after you are satisfied that the new integration works correctly. 


3. Migrate Data from the Existing Integration 

After validating the new integration, you can migrate data from the existing (source) integration. 

3.1 Start the Migration 

image.png

image.png 

3.2 Migration Execution 


image.png 

3.3 Migration Results 

Explanation: 


4. Validate End-User Access 

Once the migration has completed: 

confirm that they receive the same resources as before.
At this stage, both integrations may coexist, but users should primarily authenticate using the new integration. 

 

5. Remove the Old Integration 

After you have confirmed that: 

we recommend removing the old SAML2 integration.
This completes the migration process. 

  Optional
  Running an Additional Migration Pass
  If you need additional time to verify the new integration, you may keep the old integration active for a limited period.
  During this time, it is possible that new users authenticate through the old integration. These users do not yet exist in the        new integration
To address this, before deleting the old integration, you can run the migration again.

Additional Migration Pass 

This second migration will: 

As a result: 

This behavior is expected and indicates that only the differences were applied. 

If no new users were added since the previous migration, all users may be skipped. 

 


Revision #4
Created 3 March 2026 08:23:41 by Dominik Conrad
Updated 10 March 2026 08:27:48 by Dominik Conrad