Frequently Asked Questions
What is Evolveum midPoint?
Evolveum midPoint is an open-source Identity Governance and Administration (IGA) platform. It handles identity lifecycle management, access provisioning, role-based access control, and compliance reporting for organizations of any size. Unlike commercial IAM platforms, midPoint has no per-user licensing fees and no vendor lock-in.
Is midPoint really free? What are the costs?
midPoint itself is open-source and free to download and use. The costs come from implementation, customization, and ongoing support. You pay for consulting services to deploy and configure midPoint, build custom connectors, and train your team. There are no per-user or per-identity licensing fees, making midPoint significantly cheaper than commercial alternatives at scale.
How does midPoint compare to SailPoint, One Identity, or Saviynt?
midPoint offers comparable functionality including full lifecycle management, access certification, role mining, and compliance reporting. Key differences: midPoint is open-source with no per-user licensing, supports Kubernetes-native deployment, and provides full source code access. Commercial platforms offer more out-of-the-box connectors but at significantly higher total cost of ownership.
What size organization is midPoint suitable for?
midPoint scales from small organizations with a few hundred identities to large enterprises managing over 1,000,000 identities. WeKnowIdentity has delivered implementations across this full range, from mid-size companies with 400 identities to major telecom operators with hundreds of thousands of users.
Can midPoint run in the cloud or only on-premises?
midPoint supports both cloud and on-premises deployment. It runs natively on Kubernetes (AWS, Azure, GCP) with Helm charts and GitOps configuration. It also runs on traditional infrastructure with Docker or bare-metal installation.
Why should I hire a midPoint consultant instead of doing it in-house?
midPoint is powerful but complex. A certified consultant brings proven deployment patterns, avoids common pitfalls, and delivers production-ready implementations in weeks rather than months. WeKnowIdentity holds 4 Evolveum midPoint certifications and has completed 10+ enterprise deployments.
What certifications does WeKnowIdentity hold?
Founder Jan Minarciny holds 4 Evolveum midPoint certifications: Professional, Advanced, Deployment Specialist, and Group Synchronization Specialist. Plus Identity Management (IDPro BoK), GitOps (CGOA from The Linux Foundation), and Kubernetes certifications.
How long does a typical midPoint implementation take?
Basic deployment: 4 to 8 weeks. Complex implementations with multiple systems and compliance workflows: 3 to 6 months. Migration projects from legacy IAM platforms: 6 to 12 months depending on complexity.
Do you offer a free initial consultation?
Yes. Contact us for a free initial consultation where we assess your current IAM landscape and recommend the right midPoint approach for your organization.
What industries have you delivered midPoint projects in?
Telecom, government, finance, healthcare, education, media, and technology sectors across Slovakia, Switzerland, Germany, Austria, and Poland.
Why should I migrate from SAP IDM or Microsoft MIM to midPoint?
SAP IDM end of maintenance: December 2027. Microsoft MIM extended support end: January 2029. midPoint offers a modern alternative with full lifecycle management, ConnId connector framework, Kubernetes-native deployment, and no per-user licensing.
What systems can midPoint connect to?
Active Directory, LDAP, REST APIs, SOAP services, SCIM, SQL/NoSQL databases, CSV feeds, HR systems, and proprietary platforms. We build custom connectors for any target system.
Can you migrate from SailPoint or One Identity to midPoint?
Yes. We help organizations migrate from SailPoint IdentityIQ, One Identity Manager, and other commercial IAM platforms, including data migration, connector mapping, and phased cutover.
Is there downtime during migration to midPoint?
No. We deliver zero-downtime migrations using parallel operation. Your existing platform continues running while midPoint is deployed alongside it, with controlled cutover only after full verification.
How many identities can midPoint handle?
From hundreds to over 1,000,000 identities. Performance depends on infrastructure sizing, which we optimize during the architecture phase.
Does midPoint support Kubernetes deployment?
Yes, midPoint runs natively on Kubernetes. We specialize in Kubernetes-native deployments with Helm charts, GitOps configuration, and CI/CD pipelines for reproducible, scalable environments.
What compliance frameworks does midPoint support?
GDPR, NIS2, ISO 27001, SOX, and industry-specific frameworks. Built-in features include access certification, segregation of duties (SoD), role mining, audit logging, and automated compliance reporting.
Does WeKnowIdentity provide midPoint training?
Yes. Hands-on training covering administration, configuration, connector development, and troubleshooting. From half-day executive overviews to multi-day workshops. Knowledge transfer is included in every implementation project.
Is midPoint really free? Do I need a subscription from Evolveum?
midPoint is open source and free to download and use. However, we recommend purchasing a subscription from Evolveum for two reasons: it funds the continued development of the platform, and it gives you access to Level 4 (L4) support, which includes bug fixes in the midPoint core and the ability to request new features. WeKnowIdentity covers the first three levels of support (L1, L2, L3): configuration, deployment, troubleshooting, and optimization of your midPoint environment. Together, you get complete coverage from operational support all the way to platform development.
What is the business case and ROI for implementing midPoint?
Organizations typically achieve ROI on their midPoint investment within 12 to 18 months. Key benefits: elimination of per-user license fees (60 to 80% savings over commercial platforms on a 5-year horizon), 70 to 90% reduction in manual identity administration through automation, onboarding shortened from days to hours, minimized security risk from excessive access, and regulatory compliance (GDPR, NIS2) achieved without additional tools.
What happens if we stay on our current legacy IAM system?
If your IAM system (SAP IDM, Microsoft MIM) is reaching end of life, you will lose security patches, bug fixes, and vendor support. This means growing security vulnerabilities, compliance problems during audits (GDPR, NIS2), and increasing maintenance costs for aging infrastructure. The longer you delay migration, the more expensive and risky it becomes. Organizations that plan early can execute phased migrations with zero downtime.
What is the total cost of ownership (TCO) of midPoint compared to commercial platforms?
For an organization with 50,000 identities: commercial platforms (SailPoint, One Identity, Saviynt) typically cost EUR 300,000 to 600,000 per year in licensing alone, plus implementation costs. midPoint has zero license fees. Total costs include implementation (one-time), optional annual Evolveum subscription for L4 support, and internal operational costs. Over a 5-year horizon, organizations commonly save 50 to 75% in total costs compared to commercial alternatives.
What are the ongoing annual costs after midPoint implementation?
After implementation, annual costs consist of: Evolveum subscription for L4 support and platform updates (optional but recommended), internal team operational time for midPoint administration (typically 0.5 to 1 FTE for mid-size deployments), and optional L1 to L3 support from WeKnowIdentity. There are no per-user license fees, no mandatory upgrades, and no overage charges for exceeding identity limits.
How does midPoint integrate with Active Directory, Azure AD, and LDAP?
midPoint has native connectors for Active Directory and LDAP directories, which are the most commonly used target systems. For Microsoft Entra ID (Azure AD), midPoint integrates via the Microsoft Graph API. These connectors support full synchronization: account creation, updates, deletion, group management, password synchronization, and change detection via delta imports. Most organizations keep their existing AD/LDAP infrastructure and add midPoint as the governance layer on top.
How does midPoint handle high availability and disaster recovery?
midPoint supports high-availability deployment through multiple application replicas behind a load balancer, PostgreSQL database with replication and automatic failover, shared storage for the midPoint home directory, and Kubernetes-native features like self-healing pods and rolling updates. For disaster recovery: regular database backups, GitOps configuration (entire config in Git enables rapid restoration), and multi-region deployment for mission-critical environments.
How much internal staff do we need to operate midPoint day-to-day?
For a mid-size deployment (5,000 to 50,000 identities): typically 0.5 to 1 FTE midPoint administrator for daily operations, monitoring, and minor configuration changes. For larger deployments or environments with frequent changes: 1 to 2 FTE. WeKnowIdentity provides training to make your team self-sufficient, and we offer ongoing L1 to L3 support for organizations that prefer an external operational model.
How are midPoint upgrades and patches handled?
Evolveum releases regular midPoint versions (major releases annually, minor updates and patches on an ongoing basis). Upgrades typically involve: database backup, deploying the new version (on Kubernetes, a simple image tag change), running database migrations (automatic), and verification. With GitOps deployment, upgrading is as simple as changing the version number in your Helm values and committing to Git. WeKnowIdentity assists clients with upgrade planning and execution.
Does midPoint support zero trust architecture principles?
Yes. midPoint supports key zero trust principles: least privilege (automatic access assignment and revocation based on roles), continuous verification (periodic access certification campaigns), micro-segmentation of access (granular roles and policies), automatic anomaly detection (SoD violations, non-standard access patterns), and complete audit trail of all access changes. midPoint does not replace your authentication solutions (SSO, MFA) but complements them with a governance layer that ensures the right people have the right access at the right time.
How does midPoint integrate with MFA and SSO solutions?
midPoint integrates with MFA and SSO solutions through provisioning: it manages user accounts and group memberships in identity providers such as Keycloak, Okta, Microsoft Entra ID, or ForgeRock. midPoint ensures users are automatically enrolled for MFA, assigned to the correct SSO groups, and de-provisioned upon departure. The midPoint admin interface itself supports delegated authentication via SAML or OIDC.
How does midPoint handle complex organizational structures and multi-tenancy?
midPoint excels at modeling complex organizational structures: multi-level hierarchies (divisions, departments, teams, projects), matrix organizations with multiple reporting lines, multi-tenant environments with data isolation between tenants, delegated administration (each tenant or division manages their own identities), and organizational units as the source for automatic role assignment. This is an area where midPoint significantly outperforms many commercial platforms.

