Don't miss our next webinar on migration

View the webinar
Start for free now
Blog

Watch now: understand infrastructure, control identities & ensure compliance with MAX

Three building blocks in one session: understand infrastructure, control identities, ensure compliance — and how migRaven.MAX connects all three on a shared knowledge graph.

MI

migRaven Team

Apr 22, 2026 · 4 min read

Watch now: understand infrastructure, control identities & ensure compliance with MAX

Webinar recording from 21.04.2026:

The regulatory pressure from NIS-2, GDPR and ISO 27001 presents IT departments with growing challenges. At the same time, many companies lack exactly what would be needed for security measures, audits and sound decisions: transparency.

In our webinar, Rüdiger Massih shows how companies can use migRaven.MAX to make historically grown structures visible, assign responsibilities more clearly and not only document compliance but also support it operationally.

Watch the webinar recording now:

Regulatory pressure meets legacy IT structures

Many IT infrastructures have grown organically over the years. Permissions were extended, groups nested, systems connected and responsibilities distributed – often without consistent documentation. The result is an infrastructure that still works day to day but becomes a liability in an audit.

Particularly in the context of NIS-2 the focus is shifting: away from isolated individual measures, towards robust risk management, traceable responsibilities and an overall more resilient IT.

05:50 – The regulatory tsunami11:45 – Historical sprawl and black box IT

migRaven.MAX: transparency instead of maintaining spreadsheets

To make this complexity manageable, migRaven.MAX pursues a holistic approach that extends classic IAM perspectives.

1. The knowledge graph as the technological foundation

Instead of viewing information in isolation in tables or individual systems, MAX links data from numerous sources – for example from Active Directory, Entra ID, Teams or file servers – in a logical network of relationships. This makes dependencies, responsibilities and risks visible that often remain hidden in classic representations.

2. IAM as an end-to-end management approach

MAX looks at identities, permissions and data not only in individual reviews but across their entire lifecycle: from analysis through clean-up to ongoing operations.

3. The integrated AI expert

The AI-supported assistant creates particular added value because it is based not on general internet knowledge but on the context of your own infrastructure. This makes it possible to grasp connections faster and to assess risks more precisely.

19:25 – The knowledge graph as a game changer26:15 – The AI expert: context instead of hallucination

Ownership as the key to order and security

A central principle in migRaven.MAX is Ownership. Responsibility is anchored where the relevant expertise sits – for example with data owners for directories or with those responsible for specific identities and groups.

This not only relieves IT organizationally but also improves the quality of decisions. Because anyone who has to judge whether a group is still needed or whether an access right is justified from a business perspective should know the business context.

15:50 – The owner principle for identities and data

Tidying up without risk: soft delete and „scream test“

Deleting is risky, especially in structures that have grown historically. That is why migRaven.MAX relies on controlled clean-up processes. Objects are first disabled or moved into a safe intermediate state instead of being permanently deleted straight away.

Only when the so-called Scream Test shows that there is no longer any business use does the final clean-up take place. This creates certainty, reduces risks and makes Clean-up practicable in the first place.

36:25 – Live demo: Clean-up automation and owner management

Deriving compliance reports and actions from the real infrastructure

Instead of compiling information manually from different sources, MAX can be used to derive analyses, audit reports and action lists directly from the current infrastructure context. This saves time and at the same time increases traceability.

This is a considerable advantage, especially for audits, internal reviews or security assessments: risks not only become visible, they can also be prioritized and justified.

41:00 – Live demo: AI chat and compliance reports

Conclusion: understand first, then automate

Many companies today are under pressure to make their IT faster, more secure and more compliant. But without transparency, every form of automation remains risky.

That is why migRaven.MAX starts in the right place: with understanding structures that have grown over time, with systematic clean-up and with establishing reliable responsibilities. Only on this basis does an IT environment emerge that can be managed securely and efficiently in the long term.

Q&A on the webinar Understanding infrastructure, managing identities & ensuring compliance

The underlying graph database with all infrastructure information is located on-premise at the customer's site. Only the information required for a specific query is sent to the AI. migRaven uses Azure OpenAI models (ChatGPT) with GDPR-compliant policies: The data remains within the EU, is not made public, is not stored permanently and is not used for training purposes.

migRaven.MAX is designed for rapid deployment. As a rule, 2 to 5 days of services are required to set up the system completely and connect all data sources (connectors). After that, the first clean-up jobs or AI analyses can be started immediately. For a pure analysis instance (Foundation) it can be even faster.

Yes, the system closes the „hybrid gap“. Because information from the local AD, Entra ID, Teams and SharePoint is linked in a shared graph database, paths from the local user through to their guest access in Teams can be traced and visualized without gaps.

Licensing is based on the number of active directory accounts, i.e. users who have logged in within the last 90 days.

  • Foundation: Analysis, understanding and clean-up of the infrastructure, available modularly with or without AI.
  • Evolution: Additionally with identity management (IAM), user provisioning, workflows and alerting.

The costs for the AI tool depend primarily on the tokens consumed, i.e. on the actual queries. To save tokens, AI reports that have been created once can be stored in the system as permanent database queries.

No, the Neo4j graph database used is provided by migRaven and installed as part of a setup service. At present, a guided setup service is always offered when the subscription is purchased.

Ähnliche Artikel

Weitere Beiträge des migRaven.MAX-Teams rund um Daten, Access Governance und Ihr Dateisystem.