azure-hdinsight-migration-esp-to-non-esp
Migrating HDInsight ESP → Non-ESP (with Compensating Security Controls)
A field guide for migrating production HDInsight Enterprise Security Package (ESP) clusters — Kerberos via Azure AD Domain Services (AAD DS) + Apache Ranger — to non-ESP HDInsight clusters before ESP retirement on 31 July 2026, while preserving (or improving) the security posture using Azure-native controls instead of the Hadoop-ecosystem ones.
Why this migration is mandatory. Microsoft has announced the retirement of HDInsight ESP at end of July 2026. After that date, ESP-enabled clusters will not be supported and AAD DS integration plus Ranger will not be available on HDI. All ESP clusters must be either migrated to Microsoft Fabric, or re-deployed as non-ESP HDInsight clusters with compensating Azure-native controls — before the deadline.
This skill focuses on path B (stay on HDI, drop ESP). For full re-platforms, see:
azure-hdinsight-migration-spark-to-fabricazure-hdinsight-migration-interactive-query-to-fabricazure-hdinsight-migration-kafka-to-fabric-rtiazure-hdinsight-migration-hbase-to-fabric-cosmosdb