×
×
×
×

Migration Overview

Everything you need to know before starting your migration to ManageEngine Endpoint Central, including what UEM migration is, why organizations migrate, what data transfers, and key numbers at a glance.

What is UEM Migration?

UEM Migration is the process of transitioning your endpoint management infrastructure including device configurations, policies, groups, users, apps, and patch settings from one UEM solution to Endpoint Central. Whether you're switching from a third-party competitor, upgrading from a ManageEngine point product, or moving between deployment models (on-premises ↔ cloud), the migration process ensures your IT operations continue without disruption.

The UEM Migration Tool is ManageEngine's purpose-built, free utility that automates data transmission between UEM products. It collects device data, policies, and settings from the source solution, maps and transforms them to match the structure of the target, and migrates everything with automated backup ensuring continuity throughout the transition.

How the UEM Migration Tool Works

The tool runs through three sequential internal stages from the moment you initiate a migration:

  1. Collect: Reads all device data, policies, groups, and settings from the source server via secure API.
  2. Map & Transform: Converts source data structures to the equivalent format on the destination product.
  3. Transfer & Verify: Pushes all data to the destination server with module-level status tracking and retry support.
Tip
For detailed instructions on tool installation, configuration, and execution, refer to the Migration Process Guide →

Why Use the UEM Migration Tool?

Organizations leverage ManageEngine's purpose-built migration utility to eliminate the heavy lifting of manual data entry and configuration mapping. Here are the core benefits:

What You GetDescription
No Additional CostThe tool is available as a free 64-bit Windows executable. No license purchase or subscription is required to download or use it.
Zero Operational DowntimeBoth the source and destination servers remain fully operational throughout the migration. Administrators can continue managing endpoints on either server without interruption.
Automated Data TransferThe tool handles the entire migration lifecycle across three structured phases — collecting data from the source via secure API, mapping and transforming it to match Endpoint Central's structure, and transferring it to the destination with built-in verification. No manual re-entry or policy reconstruction is required.
Enterprise-Scale Data MigrationThe tool is designed to handle large volumes of endpoint data without performance limitations, making it suitable for organizations managing hundreds to tens of thousands of endpoints.
Granular Status Tracking and Retry SupportMigration progress is tracked at the module level. If a specific module fails, it can be retried independently without restarting the full migration — reducing the risk of incomplete transfers.
Secure Data CollectionAll data is read from the source server through a secure API. There is no direct database access or manual data export involved, ensuring the process is controlled and auditable.

What Gets Migrated?

The UEM Migration Tool handles the transfer of configurations, policies, and settings between source and destination servers. The scope of migration is categorized into three tiers based on the level of automation involved:

Fully Automated Transfer

These items transfer completely without any manual intervention:

ModuleFeature
Mobile Device ManagementMDM Device Metadata
MDM Managed Google Play (non-Gsuite)
MDM App
MDM Apps to Groups mapping
MDM Profiles
MDM Profiles to Groups Mapping
MDM Enrollment Token
MDM Agent Migration Profile
Scope of ManagementSOM Replication policy
Patch ManagementSystem Health Policy
Patch Database Settings
Clean Up Settings
Download Settings
Deployment Policy
Office Click To Run
Automated Patch Deployment (APD)
ConfigurationConfiguration Settings
USB Settings
Software DeploymentManual Packages
AutoUpdate Policies
Auto-update Templates
BitLockerBLM Policies
Device Control PlusDCP Policies
DCP Trusted Device
DCP Settings
Endpoint DLPEDLP Data Classification
EDLP Policy
EDLP Override Justification Message
Application ControlACP Remove Admin Rights
ACP Policy Deployment

Follow-up Required

These items transfer automatically with a simple follow-up step on the destination:

ModuleFeatureFollow-up Required
Mobile Device ManagementMDM UsersAD users needs to be configured manually on destination
MDM GroupsAD Groups needs to be configured manually on destination
RepositoryScript RepositoryFiles Exceeding 250 MB needs to be configured manually on destination
Scope of ManagementSOM Remote officeMetadata transfers; distribution server is set up fresh on destination
SOM Managed ComputerMetadata transfer but agent needs to be migrated & Auto-populates after agent re-installation
SOM Custom GroupAD groups & default groups needs to be configured manually on destination
PatchTest GroupTest groups with AD groups & default groups needs to be configured manually on destination
Decline PatchDecline patch with AD groups & default groups needs to be configured manually on destination
Install/Uninstall Patch ConfigurationsConfigurations linked to non-live patches needs to be configured manually on destination
ConfigurationConfiguration Deploy & Configuration templates All configurations and configuration templates will be migrated, except the following:

Mac configurations
Configurations linked to non-live or modified template packages
Configurations with file uploads larger than 250 MB

Certain configurations (e.g., file folder operations, folder backup) may require credentials to execute successfully. These configurations need to be redeployed to the targets with the necessary credentials.
Software DeploymentTemplate PackagesNon-live or modified template packages needs to be configured manually on destination
Install/Uninstall Software ConfigurationsConfigurations linked to non-live or modified template packages needs to be configured manually on destination
BitLockerBLM DeploymentBLM deployment with AD groups & default groups needs to be configured manually on destination
Device Control PlusDCP DeploymentDCP deployment with AD groups & default groups needs to be configured manually on destination
Application ControlACP Application GroupACP Application Group with AD groups & default groups needs to be configured manually on destination

Administrator-Configured Items

These items are intentionally set up fresh on the destination server by the administrator:

FeatureReason
Apple ABM/ASM TokensStandard Apple requirement for any server change
Domain CredentialsDomain metadata transfers; credentials are re-entered on destination
AD-based Users & Custom GroupsRecreated on destination; non-AD custom groups transfer fully
Device-specific MDM ProfilesGroup profiles transfer; device-specific profiles are redeployed
Files Exceeding 250 MBConfigurations with large uploads are re-uploaded on the destination
Warning
  • Security Best Practice: Credential Manager entries are intentionally configured fresh on the destination server to maintain security integrity. Ensure credentials are re-entered with exact precision before initiating migration matching case, spacing, and characters exactly.
  • Manual Creation: Data in features other than the ones mentioned above must be created manually on the destination server.
  • Active Directory Exclusions: Active Directory-based Custom Groups, default Custom Groups, and AD users (along with their associated groups and tasks) will not be migrated.

Migration at a Glance

ManageEngine's migration ecosystem is designed for scale, flexibility, and continuity. Here are the key numbers:

MetricValue
Migration Paths Supported40+
Migration Tool CostNo licensing fee
Data LossSupported migration data is preserved.
Global ReachTrusted by customers in 190+ countries
Migration Workflow3 (Prepare → Execute → Verify)

Three-Phase Migration Process

The migration strategy is systematically structured into three distinct and independent phases:

  • Phase 1: Data Migration
    Automated transfer of core configurations, policies, custom groups, and settings.
  • Phase 2: Agent Deployment
    Secure installation of Endpoint Central agents across all targeted OS platforms.
  • Phase 3: Device Enrollment
    Complete transition and enrollment of endpoints into the destination console.

All three phases are designed to run without interrupting your existing endpoint management. The source server, Destination server and Migration Tool remain fully operational during data migration. Devices continue to be managed until you explicitly deploy the new agent to each endpoint eliminating any gap in endpoint management coverage.

Ready to Make the Move?

Download the free UEM Migration Tool and start your migration today.

Have a specific question? Reach out to the migration support team: endpointcentral-support@manageengine.com