Microsoft Identity Manager SP3: What it is and what it means for your identity strategy

Here at Performanta we like to say that we are not afraid of the C word (heh-hem, our C word is context). For some organisations leaving on-premise systems in the past is simply not an option. Whether that’s for security purposes, cost, processes, stringent regulatory requirements or something else entirely. And Microsoft have released a compatibility update for exactly those organisations.
Microsoft’s Service Pack 3 for Microsoft Identity Manager (MIM) 2016 is a compatibility update that keeps ageing on-premises identity infrastructure running on current Windows Server, SQL Server and SharePoint platforms. If you run MIM, this is welcome news. It is not, however, a reason to stop planning.
SP3 buys you some time even while Microsoft's priorities have been clear for several years: their identity innovation is happening in Microsoft Entra, not in MIM. So SP3 is best understood as a short-term bridge, one that you’ll get value from if you’re currently on MIM and can treat this time as a planning-for-tomorrow window. And we can help you navigate this.
3 dates to mark in your calendars
Milestone | Date |
SharePoint Server 2016/2019 end of support | 14 July 2026 |
MIM 2016 SP2 support extended until | May 2027 |
MIM extended support lifecycle ends | January 2029 |
January 2029 might feel like ages away, but it really isn’t. Identity transitions like untangling metaverse logic, custom workflows, connected systems and years of accumulated configuration all routinely take longer than you’d expect, and if we’re being totally honest, most start later than they should. In our view, preparing for this transition should be started from now – as two-and-a-bit years of a well leveraged runway is a shorter window than it looks on a roadmap.
What SP3 delivers
SP3 is a compatibility release that adds:
• Support for Windows Server 2022 and SQL Server 2022
• Azure SQL connectivity with Managed Identity authentication
• ADFS claims-based single sign-on for the MIM Portal
• The option to host the MIM Portal on SharePoint Server Subscription Edition (SPSE)
Moving to SPSE requires a new Portal deployment and it moves you onto subscription licensing with ongoing renewal costs.
Why this is a planning window, and what to think about
Microsoft Entra now covers a substantial share of what MIM was built to do, and covers it natively in the cloud:
• Identity lifecycle workflows
• Access packages and access reviews
• Privileged Identity Management
• SCIM and API-based provisioning
• Self-service password reset with on-premises writeback
Maybe you see that list and think that's enough to retire pieces of your MIM estate, maybe not. You know your C word better than anyone. But we must acknowledge that Entra doesn't replace every MIM deployment outright, particularly where complex metaverse logic or multiple authoritative data sources are in play. You don’t necessarily need to decide right now to “migrate everything” or “do nothing.” Instead, you should conduct a workload-by-workload assessment of what you can move, what you can redesign, and what still needs to run on MIM for now.
What we'd recommend doing with the time SP3 buys you
Assess your real MIM and SharePoint dependency — without the pressure of an imminent deadline forcing rushed decisions.
Identify the workloads that can move to Entra with the least disruption — self-service password reset and specific provisioning scenarios are likely the sensible starting point.
Align your identity roadmap to where Microsoft is investing, where it makes sense – and work with a trusted partner to do so (we can help!).
Use the breathing space deliberately. SP3 removes some of the immediate time pressure, but don’ get lax – use it to plan for tomorrow.
In practice, that assessment should look closely at:
How much of your current MIM Portal functionality is truly required (if pieces have been acquired over time with poor rationale for the right-now, chuck it in the “not needed” bucket)
Which workflows can be redesigned or decoupled from legacy patterns
Where SharePoint-based identity components create dependency you could reduce now
Which MIM use cases are transitional, and which are needed for the long-term
Where Performanta comes in
We've been managing hybrid identity environments — Microsoft Identity Manager and Microsoft Entra alike — since long before “hybrid identity” was the accepted term for it. In fact, we even trademarked “Secure Hybrid Identity” all the way back in 2020. Our Enterprise Identity Management practice runs JML automation, access governance and self-service programmes across MIM and Entra estates for organisations that can't afford to get this transition wrong, and our identity consultants and 3rd-line specialists work as an extension of your team.
If you're running MIM today, SP3 is a good moment to get a clear, honest picture of where you stand — an actual assessment of your dependencies, your risk, and your realistic path to Entra where it makes sense.
We offer:
A MIM dependency assessment — a clear-eyed view of what your MIM estate does right now, and what it would take to change that
An Entra suitability review — mapped against your specific workflows, not a generic checklist
A phased roadmap to January 2029 that fits your organisation's pace, risk appetite and budget cycle
Talk to our identity team before your roadmap is written for you by a deadline.
Book a MIM & Entra readiness conversation with Performanta → Click Here
We help you know your ground and protect it, proactively. Performanta is a global cyber safety partner, founded in 2010, with security professionals across the UK and South Africa. Our Identity Management practice helps organisations run, govern and modernise hybrid identity environments — including Microsoft Identity Manager and Microsoft Entra — without compromising security or continuity along the way.



