×
×
×
×

Migration Process

Step-by-step guidance on how to migrate to ManageEngine Endpoint Central — including architecture, pre-migration checklist, step-by-step tool execution, agent migration, post-migration verification, and FAQs.

Migration Architecture & Workflow

The migration process runs through three phases with distinct checkpoints at each stage. The following workflow covers the complete end-to-end journey from preparation to a verified, stable destination in Endpoint Central.

Migration Architecture and Workflow
Tip
Uninterrupted management by design: The source server, destination server, and migration tool remain fully operational throughout data migration. Devices continue to be managed until you explicitly deploy the new agent to each endpoint — there is no forced cutover and no gap in endpoint management coverage.

UEM Migration Tool — Key Capabilities

The UEM Migration Tool is ManageEngine's dedicated utility for automating UEM product transitions. It is available as a free download and provides a web console-based interface for managing the entire migration lifecycle.

  • Free download — No additional licensing or subscription fees.
  • 64-bit Windows executable — Runs on Windows Server or Windows desktop machine.
  • Web console interface — Browser-based management dashboard for migration operations.
  • Multi-module selection — Choose exactly which of the 11 migration modules to migrate. Modules not selected initially can be added later using Add New.
  • Module-level retry — Retry failed modules individually without rerunning the full migration.
  • Proxy support — Configure server connection type for restricted network environments (Settings → Proxy).
  • NAT settings — Configure NAT rules for Apple device management scenarios (Settings → NAT).
  • API key authentication — Secure API authentication for on-premises sources (Admin → API Explorer → API Key).
  • Zoho OAuth — Sign in securely via Zoho accounts with consent-based authorization for cloud instances.

Pre-Migration Checklist & Network Port Requirements

Completing each item in this checklist before running the UEM Migration Tool ensures a smooth, uninterrupted transition. This preparation phase is the foundation for a successful migration.

a. General Prerequisites

  1. Both source and destination server licenses must be active before starting migration.
  2. Both the source and destination servers must be reachable from the machine running the migration tool.
  3. For on-premises source or destination servers, the server URL entered in the migration tool must be in FQDN format — IP addresses are not accepted.
  4. For on-premises servers, verify that the NAT settings configured on both the source and destination servers match the domain in each server's SSL certificate.

Prerequisites for Data Migration

Source server

1. Source server must be upgraded to the latest build before starting.

2. Agent Protection Settings disabled on source (required for agent migration).

Destination server

1. APNs certificate must be configured on destination, required for iOS device management.

2. Knox enrollment must be configured on destination, required for Android device management.

3. Create the credentials in Credential Manager on the destination server exactly as they exist on the source server, ensuring there are no case sensitivity errors, spaces, or extra characters (only if credentials are used in configurations).

4. Add and integrate Active Directory in the MDM module on the destination server before initiating migration.

Prerequisites for Agent Migration

Source server

1. Agent Protection Settings disabled on source (required for agent migration).

Note
No prerequisites are required on the destination server for agent migration. Ensure data migration is completed successfully before deploying agents to endpoints.

Prerequisites for Device Migration

Destination server

1. APNs certificate must be configured on destination, required for iOS device management.

2. Knox enrollment must be configured on destination, required for Android device management.

Note
No prerequisites are required on the source server for device migration. Ensure data migration and agent migration are completed successfully before proceeding.

b. Network & Connections

Outbound

  • For on-premises source or destination servers, allow outbound access from the machine running the migration tool to the source or destination server's domain and port. This step is not required if the source server and the migration tool are on the same network.
  • For cloud source or destination products, allow outbound access to *.manageengine.com and *.zoho.com on port 443 from the machine running the migration tool. The exact domains may vary based on your data center region — refer to the regional whitelisting table above.

Inbound (iOS Devices)

If you are migrating iOS devices, enrollment can be completed using either of the following methods:

  • Using the ManageEngine MDM App — no additional port configuration required.
  • Using Webclip — ensure port 7383 is open for inbound connections on the source server before distributing the iOS migration profile.

Required Domains Whitelisting

If you need specific domains to be whitelisted, allow the following:

Domain URLPurpose
https://patchdb.manageengine.comPatch database updates sync
https://mdm.manageengine.comMobile Device Management profiles & settings
https://mdmdatabase.manageengine.comMDM database sync
https://www.zoho.comZoho authentication APIs
https://manageengine.comManageEngine portal resources
https://creator.zoho.comZoho Creator integration services

Regional Data Center Whitelisting

Based on your data center location, whitelist the following regional domains:

Data CenterMDM DomainEndpoint Central DomainDownload DomainAccounts DomainUpload Domain
US (.com)mdm.manageengine.comendpointcentral.manageengine.comdownload-accl.zoho.comaccounts.zoho.comupload-accl.zoho.com
EU (.eu)mdm.manageengine.euendpointcentral.manageengine.eudownload-accl.zoho.euaccounts.zoho.euupload-accl.zoho.eu
IN (.in)mdm.manageengine.inendpointcentral.manageengine.indownload-accl.zoho.inaccounts.zoho.inupload-accl.zoho.in
AU (.com.au)mdm.manageengine.com.auendpointcentral.manageengine.com.audownload.zoho.com.auaccounts.zoho.com.auupload-accl.zoho.com.au
JP (.jp)mdm.manageengine.jpendpointcentral.manageengine.jpdownload.zoho.jpaccounts.zoho.jpupload-accl.zoho.jp
CN (.com.cn)mdm.manageengine.cnendpointcentral.manageengine.cndownload.zoho.com.cnaccounts.zoho.com.cnupload-accl.zoho.com.cn
CA (.ca)mdm.manageengine.caendpointcentral.manageengine.cadownload.zohocloud.caaccounts.zohocloud.caupload-accl.zohocloud.ca
UK (.co.uk)mdm.manageengine.co.ukendpointcentral.manageengine.co.ukdownload-accl.zoho.co.ukaccounts.zoho.co.ukupload-accl.zoho.co.uk
SA (.sa)mdm.manageengine.saendpointcentral.manageengine.safiles.zoho.saaccounts.zoho.saupload-accl.zoho.sa
AE (.ae)mdm.manageengine.aeendpointcentral.manageengine.aefiles.zoho.aeaccounts.zoho.aeupload-accl.zoho.ae

Step-by-Step Migration Execution

The migration execution is divided into two sequential phases: Data Migration (configurations, policies, settings) followed by Agent/Device Migration (deploying new agents to endpoints per OS).

Important
Complete data migration first. Deploy agents only after all modules are successfully migrated to the destination server.

1. Setup and Prerequisites

  1. Download the UEM Migration Tool on the machine running the central server.

  2. Install the downloaded EXE file and set up credentials to access the migration tool. Once you sign in, you will be able to view the migration tool console.

  3. Configure Proxy Settings. Supported options:

    1. No Connection to Internet
    2. Direct Connection to Internet
    3. HTTP Proxy configuration
    4. Automatic configuration using script

    To set up proxy settings, click Settings → Proxy → Choose the connection type from the dropdown → Save.

    Migration Tool - Proxy Settings
  4. For Apple devices, configure NAT settings by clicking Settings → NAT and adding the required IP address or FQDN, then click Save.

    Migration Tool - NAT Settings
  5. Navigate to the Migration tab and click Migrate Now to proceed.

    Migration Tool - Migrate Now

2. Source Authentication (On-Premises as Example)

Note

1. If you are migrating from a cloud product, select the product name and proceed to the cloud authentication steps.

2. If you are migrating from or to MSP products, contact support for further assistance.

  1. Select the required product for migration (e.g., Endpoint Central On-premises).
  2. Enter the complete URL (FQDN) and port number of your source server.
  3. Select the domain associated with your administrator account.
  4. Enter the credentials of an administrator account with the required privileges on the source server and click Proceed to authenticate. Once validated, the tool connects to the source server and transitions to the Destination Server Details section.
Migration Tool - Source Server Authentication

3. Destination Authentication(Cloud as Example)

  1. Select the destination product (e.g., Endpoint Central Cloud).
  2. Select the Data Center (US, EU, CN, IN, AU, UK, CA, SA, AE, JP) in which your cloud account is hosted.
    Migration Tool - Destination Server Authentication
  3. Click Authenticate. You will be redirected to the Zoho Accounts page to sign in with your credentials.
    Migration Tool - Zoho Sign-in
  4. On the Consents page, read the terms and agreements and click Accept.
    Migration Tool - UEM Migration Services

4. Module Selection & Execution

  1. After completing authentication, select the modules to migrate. The tool presents 11 migration modules — select the ones relevant to your migration path:
    Migration Tool - Module Selection
    • Mobile Device Management
    • Scope of Management
    • Patch
    • Software Deployment
    • Configuration
    • Repository
    • Vulnerability Manager (VMP)
    • BitLocker
    • Device Control Plus
    • Application Control
    • Endpoint DLP
  2. Pay attention to dependencies: Some sub-groups within a module depend on others. For example, within the Mobile Device Management module, MDM Groups depends on MDM Users — if MDM Users is not selected, MDM Groups cannot be migrated.
  3. Select the prerequisites checkbox to view the list of prerequisites in a pop-up, verify them, and click Agree and Proceed.
    Migration Tool - Module Prerequisites
  4. Click Migrate to initiate data migration.
    Migration Tool - Module Migration
  5. Monitor progress on the Migration Status page.
  6. Retry option for migration failure

  7. Failure Recovery: If a module fails, click Retry. If a dependent module fails, it will be marked as Skipped. You cannot edit details while migration is in progress.
    Migration Tool - Migration Status
  8. Use the Add New button to migrate additional modules that were not selected in the initial run.

1. Agent Deployment

  1. Open the destinationEndpoint Central console → Agent → Computers → select remote office → Download Agent (.exe).
    Remote Office Agent
  2. Download the Agent Migration Tool (.exe) to the same folder.
  3. Right-click AgentMigrationTool.exe → Run as administrator.
  4. Click Choose Agent Installer → select the downloaded agent .exe.
    AgentMigrationTool - Choose Agent Installer
  5. Confirm Version and Server info match the destination server → click Create Agent.exe.
    Create Agent.exe
  6. The Agent.exe file will be created in the same directory as the tool.
    Generated Agent.exe
  7. Copy Agent.exe to the client machine and run it in CMD as administrator with the /silent argument: Agent.exe /silent.
    Run Agent.exe in CMD
  8. Verify that the migration is working correctly on the test devices before proceeding to batch deployment.
  9. In the sourceEndpoint Central server console, navigate to Configuration → Windows → Custom Script → Computer.
    Custom Script - Computer
  10. Enter the name of the configuration, click Create/Modify Script, and add the script to the repository. Download the script here.
    Add script to repository
  11. Select the script in the custom script configuration.
    Select script in configuration
  12. In dependency files, upload the previously generated Agent.exe file. Select the target devices and deploy the configuration.
    Deploy configuration
  13. Once the changes are applied, the agent will be moved to the destination server console.

2. Windows Endpoints MDM Re-enrollment

MDM Re-enrollment

This step is required only after deploying the Endpoint Central agent and confirming the connection is established between the server and the agents.

To re-enroll Windows machines under MDM, refer to the agent installation document.

Warning
Critical: Do not use this method for machines enrolled via Azure AD enrollment. Running this batch script on Azure AD enrolled machines will brick the device.

1. Mac Agent Migration

Note
For ABM-enrolled devices running macOS 26 or later, use Apple's native MDM migration solution and follow these steps to complete the agent migration from Source to Destination. Learn more →
  1. Disable Agent Protection Settings: In the Endpoint Central on-premises web console, navigate to Agent → Agent Settings → Agent Protection Settings and disable Restrict users from uninstalling the Agent and Distribution server, if enabled.
    Disable Agent Protection Settings
  2. Download the agent package:
    • Open the destination web console.
    • Navigate to Agent → Computers.
    • Select the required remote office.
    • Click Download Agent.
      Remote Office Agent
    • Rename the file to UEMS_MacAgent.pkg and place it in a folder.
  3. Download Migration.sh to the same directory.
    Mac Migration files
  4. Zip the package with serverinfo.plist and Migration.sh.
    Zip package
  5. Navigate to Endpoint Central → Software Deployment → Add Package → Mac.
    Create Mac package
  6. Create a Mac package by uploading the generatedArchive.zip. In Advanced Options, entersh ./Migration.sh

    Create Mac package
  7. Create a Mac Software Deployment configuration and deploy the package to the required machines on-premises. Apply to a few test machines first before full deployment.

2. Mac MDM Migration Steps (OP to Cloud / Non-ABM & ABM)

For assistance with the MDM part of Mac migration, reach out to the ManageEngine migration support team at endpointcentral-support@manageengine.com

Linux Agent Migration

  1. In the destination Endpoint Central Cloud console: Agent → Agent Settings → Agent Protection Settings → disable "Restrict users from uninstalling the Agent and Distribution Server, if enabled."
    Disable Agent Protection Settings
  2. Open the destination Endpoint Central Cloud console → Agent → Computers → select remote office → Download Agent → rename the downloaded file to UEMS_LinuxAgent.bin.
    Remote Office Agent
  3. Create a Linux custom script configuration in the sourceEndpoint Central console.
    Linux custom script
  4. Add copyAgentFiles.bash to the script repository.
  5. Upload the following dependency files:
    • UEMS_LinuxAgent.bin — from the zip file downloaded from the destination Endpoint Central Cloud console
    • serverinfo.json — from the same zip file
    • LinuxAgentInstaller.bash
  6. Define targets and apply the configuration.
Note
After the configuration is applied, allow up to 10 minutes for the new Linux agent to install. Always test on a few machines first before batch deployment.

Migrate Android Devices

Android devices are migrated by applying a migration profile to the device or through re-enrollment after data migration is complete.

Android Device Migration

Steps to Migrate Android Devices

  1. A profile named Android Migration Profile will be available in the Mobile Device Management module on the destination server once data migration is complete.
  2. Distribute the Android Migration Profile to your test devices first. Once the profile is applied, those devices migrate to the destination server automatically.
  3. Verify that migration is working correctly on the test devices before proceeding. Once confirmed, distribute the profile to the rest of your Android devices.
Note
Always validate the Android Migration Profile on a test device before distributing it to your full Android device inventory.

Migrate iOS Devices

iOS Device Migration

Steps to Migrate iOS Devices

  1. Configure APNs on the destination server before distributing the migration profile. This is required for iOS device management to function on the destination.
  2. A profile named iOS Migration Profile will be available on the source server once data migration is complete.
  3. Distribute the iOS Migration Profile to your devices. Users must open the Webclip on their device, tap Begin, and enter their device passcode to initiate enrollment.
  4. Once the profile is applied, the device migrates to the destination server automatically.
Note
Always validate the iOS Migration Profile on a test device before distributing it to your full iOS device inventory.

Post-Migration Verification

Note
After completing data migration, agent deployment, and device enrollment, perform the following verification steps to confirm a clean and stable transition.
  • Migrated agents land in the default remote office by default. Manually move them to their respective remote offices after migration is complete. Refer to Remote Office Management for steps.
  • Distribution servers for each remote office must be manually installed on the destination server after migration.
  • Inventory scan details will populate automatically after agent migration completes.
  • Configurations and Automated Patch Deployment (APD) tasks are saved as drafts and remain suspended after migration. Redeploy them to the target devices after moving agents to their respective remote offices.
  • Only manually created software packages and template packages that are live and unmodified are migrated. All other packages must be recreated on the destination server.
  • Domain metadata transfers automatically. Enter domain credentials on the destination server to sync the domains.
  • After migration, mobile devices are moved to their respective groups. Device-specific MDM profiles are not migrated and must be manually redeployed to the respective devices on the destination server.
  • Only Android Enterprise apps and enterprise apps are migrated. Apple ABM/ASM tokens must be manually added on the destination server after migration.

Real-World Migration Scenarios

Common migration scenarios that organizations encounter, along with the recommended approach for each.

Scenario 1: Consolidating ManageEngine Point Products

Situation
Your organization uses Patch Manager Plus for patching and Mobile Device Manager Plus for mobile management as separate standalone products.

Goal
Consolidate into Endpoint Central for a single-console experience.

Approach
Migrate Patch Manager Plus first — patches, policies, and groups transfer via the UEM Migration Tool. Then migrate Mobile Device Manager Plus — profiles, devices, and apps. After data migration completes, deploy Endpoint Central agents to all desktop endpoints and re-enroll mobile devices through the migration profile.

Scenario 2: Mixed Environment Consolidation

Situation
Your organization uses Patch Manager Plus for Windows patch management alongside a separate third-party UEM platform for Mac and mobile device management — resulting in two consoles and two toolsets.

Goal
Migrate both platforms into a single Endpoint Central instance.

Approach
Use the UEM Migration Tool to migrate Patch Manager Plus data first — patches, policies, and groups transfer fully. For the third-party platform, use a combination of the migration tool for supported data items such as device metadata and groups, and a guided migration session to map existing configurations to their Endpoint Central equivalents. Deploy agents to all endpoints after data migration completed and re-enroll mobile devices through the migration profile.

Scenario 3: On-Premises to Cloud Migration

Situation
You want to migrate your existing on-premises Endpoint Central infrastructure to the cloud to eliminate the administrative overhead of managing server hardware, OS updates, and daily upkeep.

Goal
Move to Endpoint Central Cloud without losing existing configurations.

Approach
Use the UEM Migration Tool for a direct Endpoint Central On-premises → Endpoint Central Cloud data migration. Then deploy cloud agents per OS. The source server stays operational throughout the transition — no gap in endpoint management coverage.

Scenario 4: MSP to Enterprise Transition

Situation
Your managed service provider was using Endpoint Central MSP to manage your endpoints. You are bringing IT management in-house.

Goal
Migrate from the MSP instance to your own Endpoint Central setup.

Approach
Use the EC MSP → Endpoint Central migration path. All configurations, policies, and device data transfer via the UEM Migration Tool. Coordinate with your MSP for the agent switchover window and redeploy configurations after migration completes.

Scenario 5: Migrating from Another UEM Platform

Situation
Your organization is using another UEM platform but requires broader endpoint management coverage — including stronger patch management, OS deployment, and cross-platform support across Windows, macOS, Linux, and mobile devices.

Goal
Replace the current UEM platform with Endpoint Central.

Approach
Begin with an audit of your current platform's policies, groups, and configurations to identify what can be migrated and what needs to be recreated. Use the UEM Migration Tool to transfer supported data items — device metadata, groups, and users — and work with ManageEngine's guided migration session for platform-specific configuration mapping. Deploy Endpoint Central agents to endpoints and validate coverage before decommissioning the existing platform. Reach out to endpointcentral-support@manageengine.com to begin a guided migration assessment.

Frequently Asked Questions

What is the difference between data migration and device migration?
Data migration transfers your configurations, policies, groups, users, apps, profiles, and settings from the source server to the destination server using the UEM Migration Tool. Device migration is a separate step where you push a new agent installer to each endpoint so it re-registers with the destination server. Both steps are required for a complete migration — data migration alone does not move devices to the destination server.
What do I need to prepare before migrating iOS devices?
Configure APNs on the destination server before starting iOS device migration — this is required for iOS device management to function on the destination. Ask end users to disable Stolen Device Protection at least 2 hours before migration begins, and temporarily remove iPadOS devices from kiosk mode before migrating — kiosk mode can be re-enforced after enrollment completes. During migration, users open the Webclip on their device, tap Begin, and enter their device passcode to complete enrollment into Endpoint Central.
Authentication fails when connecting to the source or destination server — what should I check?
Confirm the server URL is in FQDN format — IP addresses are not accepted, and the URL must be reachable from the machine running the migration tool. Verify that NAT settings are configured on the source server with a FQDN that matches the SSL certificate, and restart the server after making any changes.
The migration tool shows a certificate or FQDN mismatch error — how do I resolve it?
This error occurs when the FQDN entered does not match the domain pattern in the server's SSL certificate — wildcard certificates (*.example.com) cover only one subdomain level and will not match deeper paths. To resolve this, verify that the FQDN configured in the server's NAT settings matches the domain present in the SSL certificate, then re-enter that FQDN in the migration tool and retry authentication.
What if a module fails during migration?
The Migration Status page tracks the status of each module individually. For any module that fails, select it and use the Retry option to re-attempt migration for that specific module without rerunning the full migration. If a dependent module fails, modules that rely on it will be marked as Skipped — resolve the failed module first, then retry the dependent ones.
How do I run a module when its dependency module has failed?
The tool holds dependent modules until their dependency migrates successfully — for example, MDM Apps to Groups mapping waits for MDM Groups to complete first. The recommended approach is to resolve the failed dependency module using the Retry option, then retry the dependent module. If the dependency module continues to fail, contact ManageEngine support at endpointcentral-support@manageengine.com with the migration logs for further assistance.
APD migration is failing — what are the common causes?
APD migration fails when the deployment policy used in the task has not migrated successfully — resolve the deployment policy failure first using Retry, then retry the APD module. If the APD task name contains special characters, rename the task on the source server to remove them and retry. APD tasks will also not migrate if the target computer, custom group, domain, or remote office has not migrated — check the Scope of Management module status and resolve any failures there first.
Configuration deployment migration failed — what should I check?
Configuration migration skips items linked to non-live or modified template packages — verify that all template packages used in your configurations are active and unmodified on the source server before retrying. Configurations with file uploads exceeding 250 MB need to be re-uploaded directly on the destination server after migration completes. Mac configurations are handled through a separate deployment workflow and should be set up fresh on Endpoint Central after migration.
Software package migration failed — how do I resolve this?
Only manually created packages, live template packages and unmodified template packages migrate automatically — if a template package has been modified or is inactive, recreate it on the destination server. Script migration failure also causes manual package migration to be skipped — resolve the Repository module first using Retry, then retry the Software Deployment module. Archived packages and software repository items should be set up fresh on the destination after migration completes.
How do I migrate Mac endpoints from another UEM platform?
For non-ABM Mac devices, deploy the Endpoint Central agent through your current platform's deployment console using UEMS_MacAgent.pkg alongside the com.manageengine.ems.plist configuration file — once installed, the device onboards automatically. After the agent is live, deploy the MDM migration script from the Endpoint Central console to remove the existing MDM profile and trigger Endpoint Central MDM enrollment. For ABM-enrolled devices on macOS Sonoma, the administrator runs the migration script locally on the device and enters admin credentials directly.View the complete steps for Mac agent migration →
How do I migrate Android devices from another UEM platform?
For Work Profile (Profile Owner) devices, remove the existing work profile on the device from Settings → Accounts, then re-enroll the device in Endpoint Central using invite or self-enrollment. For fully managed (Device Owner) devices, change the MDM server to ManageEngine in your Knox Mobile Enrollment or Zero Touch Enrollment portal and trigger a factory reset from the source MDM console — the device enrolls in Endpoint Central automatically after the reset completes. View the complete steps for Android device migration →
How do I collect UEM migration tool logs for a support case?
Wait for all modules to reach a final status on the Migration Status page, then stop the UEM Migration Tool service from Windows Services (search for "ManageEngine UEM Migration Tool" → Stop). Navigate to the logs folder at C:\Program Files\ManageEngine\UEM Migration Tool\logs, compress the entire folder, and share it with ManageEngine support at endpointcentral-support@manageengine.com. Always stop the service before compressing — this ensures no log files are partially written at the time of collection.
How do I collect the required information when reporting a migration failure?
Collect the complete logs folder from C:\Program Files\ManageEngine\UEM Migration Tool\logs along with the report from the UEM Migration Tool (Navigate to Migration > Migration Status > Export). Note the source and destination product names, build versions, and the specific module and sub-group that failed — these details allow the support team to identify the failure point without needing direct access to your environment. Share this with ManageEngine support at endpointcentral-support@manageengine.com along with any error messages visible in the tool console.