Migration Overview
Everything you need to know before starting your migration to ManageEngine Endpoint Central, including what UEM migration is, why organizations migrate, what data transfers, and key numbers at a glance.
What is UEM Migration?
UEM Migration is the process of transitioning your endpoint management infrastructure including device configurations, policies, groups, users, apps, and patch settings from one UEM solution to Endpoint Central. Whether you're switching from a third-party competitor, upgrading from a ManageEngine point product, or moving between deployment models (on-premises ↔ cloud), the migration process ensures your IT operations continue without disruption.
The UEM Migration Tool is ManageEngine's purpose-built, free utility that automates data transmission between UEM products. It collects device data, policies, and settings from the source solution, maps and transforms them to match the structure of the target, and migrates everything with automated backup ensuring continuity throughout the transition.
How the UEM Migration Tool Works
The tool runs through three sequential internal stages from the moment you initiate a migration:
- Collect: Reads all device data, policies, groups, and settings from the source server via secure API.
- Map & Transform: Converts source data structures to the equivalent format on the destination product.
- Transfer & Verify: Pushes all data to the destination server with module-level status tracking and retry support.
Why Use the UEM Migration Tool?
Organizations leverage ManageEngine's purpose-built migration utility to eliminate the heavy lifting of manual data entry and configuration mapping. Here are the core benefits:
| What You Get | Description |
|---|---|
| No Additional Cost | The tool is available as a free 64-bit Windows executable. No license purchase or subscription is required to download or use it. |
| Zero Operational Downtime | Both the source and destination servers remain fully operational throughout the migration. Administrators can continue managing endpoints on either server without interruption. |
| Automated Data Transfer | The tool handles the entire migration lifecycle across three structured phases — collecting data from the source via secure API, mapping and transforming it to match Endpoint Central's structure, and transferring it to the destination with built-in verification. No manual re-entry or policy reconstruction is required. |
| Enterprise-Scale Data Migration | The tool is designed to handle large volumes of endpoint data without performance limitations, making it suitable for organizations managing hundreds to tens of thousands of endpoints. |
| Granular Status Tracking and Retry Support | Migration progress is tracked at the module level. If a specific module fails, it can be retried independently without restarting the full migration — reducing the risk of incomplete transfers. |
| Secure Data Collection | All data is read from the source server through a secure API. There is no direct database access or manual data export involved, ensuring the process is controlled and auditable. |
What Gets Migrated?
The UEM Migration Tool handles the transfer of configurations, policies, and settings between source and destination servers. The scope of migration is categorized into three tiers based on the level of automation involved:
Fully Automated Transfer
These items transfer completely without any manual intervention:
| Module | Feature |
|---|---|
| Mobile Device Management | MDM Device Metadata |
| MDM Managed Google Play (non-Gsuite) | |
| MDM App | |
| MDM Apps to Groups mapping | |
| MDM Profiles | |
| MDM Profiles to Groups Mapping | |
| MDM Enrollment Token | |
| MDM Agent Migration Profile | |
| Scope of Management | SOM Replication policy |
| Patch Management | System Health Policy |
| Patch Database Settings | |
| Clean Up Settings | |
| Download Settings | |
| Deployment Policy | |
| Office Click To Run | |
| Automated Patch Deployment (APD) | |
| Configuration | Configuration Settings |
| USB Settings | |
| Software Deployment | Manual Packages |
| AutoUpdate Policies | |
| Auto-update Templates | |
| BitLocker | BLM Policies |
| Device Control Plus | DCP Policies |
| DCP Trusted Device | |
| DCP Settings | |
| Endpoint DLP | EDLP Data Classification |
| EDLP Policy | |
| EDLP Override Justification Message | |
| Application Control | ACP Remove Admin Rights |
| ACP Policy Deployment |
Follow-up Required
These items transfer automatically with a simple follow-up step on the destination:
| Module | Feature | Follow-up Required |
|---|---|---|
| Mobile Device Management | MDM Users | AD users needs to be configured manually on destination |
| MDM Groups | AD Groups needs to be configured manually on destination | |
| Repository | Script Repository | Files Exceeding 250 MB needs to be configured manually on destination |
| Scope of Management | SOM Remote office | Metadata transfers; distribution server is set up fresh on destination |
| SOM Managed Computer | Metadata transfer but agent needs to be migrated & Auto-populates after agent re-installation | |
| SOM Custom Group | AD groups & default groups needs to be configured manually on destination | |
| Patch | Test Group | Test groups with AD groups & default groups needs to be configured manually on destination |
| Decline Patch | Decline patch with AD groups & default groups needs to be configured manually on destination | |
| Install/Uninstall Patch Configurations | Configurations linked to non-live patches needs to be configured manually on destination | |
| Configuration | Configuration Deploy & Configuration templates | All configurations and configuration templates will be migrated, except the following: Mac configurations Configurations linked to non-live or modified template packages Configurations with file uploads larger than 250 MB Certain configurations (e.g., file folder operations, folder backup) may require credentials to execute successfully. These configurations need to be redeployed to the targets with the necessary credentials. |
| Software Deployment | Template Packages | Non-live or modified template packages needs to be configured manually on destination |
| Install/Uninstall Software Configurations | Configurations linked to non-live or modified template packages needs to be configured manually on destination | |
| BitLocker | BLM Deployment | BLM deployment with AD groups & default groups needs to be configured manually on destination |
| Device Control Plus | DCP Deployment | DCP deployment with AD groups & default groups needs to be configured manually on destination |
| Application Control | ACP Application Group | ACP Application Group with AD groups & default groups needs to be configured manually on destination |
Administrator-Configured Items
These items are intentionally set up fresh on the destination server by the administrator:
| Feature | Reason |
|---|---|
| Apple ABM/ASM Tokens | Standard Apple requirement for any server change |
| Domain Credentials | Domain metadata transfers; credentials are re-entered on destination |
| AD-based Users & Custom Groups | Recreated on destination; non-AD custom groups transfer fully |
| Device-specific MDM Profiles | Group profiles transfer; device-specific profiles are redeployed |
| Files Exceeding 250 MB | Configurations with large uploads are re-uploaded on the destination |
- Security Best Practice: Credential Manager entries are intentionally configured fresh on the destination server to maintain security integrity. Ensure credentials are re-entered with exact precision before initiating migration matching case, spacing, and characters exactly.
- Manual Creation: Data in features other than the ones mentioned above must be created manually on the destination server.
- Active Directory Exclusions: Active Directory-based Custom Groups, default Custom Groups, and AD users (along with their associated groups and tasks) will not be migrated.
Migration at a Glance
ManageEngine's migration ecosystem is designed for scale, flexibility, and continuity. Here are the key numbers:
| Metric | Value |
|---|---|
| Migration Paths Supported | 40+ |
| Migration Tool Cost | No licensing fee |
| Data Loss | Supported migration data is preserved. |
| Global Reach | Trusted by customers in 190+ countries |
| Migration Workflow | 3 (Prepare → Execute → Verify) |
Three-Phase Migration Process
The migration strategy is systematically structured into three distinct and independent phases:
- Phase 1: Data Migration
Automated transfer of core configurations, policies, custom groups, and settings. - Phase 2: Agent Deployment
Secure installation of Endpoint Central agents across all targeted OS platforms. - Phase 3: Device Enrollment
Complete transition and enrollment of endpoints into the destination console.
All three phases are designed to run without interrupting your existing endpoint management. The source server, Destination server and Migration Tool remain fully operational during data migration. Devices continue to be managed until you explicitly deploy the new agent to each endpoint eliminating any gap in endpoint management coverage.
Ready to Make the Move?
Download the free UEM Migration Tool and start your migration today.
Have a specific question? Reach out to the migration support team: endpointcentral-support@manageengine.com