# Migration Overview Last Updated On: 04 Sep 2026 Everything you need to know before starting your migration to ManageEngine Endpoint Central, including what UEM migration is, why organizations migrate, what data transfers, and key numbers at a glance. ## What is UEM Migration? **UEM Migration** is the process of transitioning your endpoint management infrastructure including device configurations, policies, groups, users, apps, and patch settings from one UEM solution to Endpoint Central. Whether you're switching from a third-party competitor, upgrading from a ManageEngine point product, or moving between deployment models (on-premises ↔ cloud), the migration process ensures your IT operations continue without disruption. The **UEM Migration Tool** is ManageEngine's purpose-built, free utility that automates data transmission between UEM products. It collects device data, policies, and settings from the source solution, maps and transforms them to match the structure of the target, and migrates everything with automated backup ensuring continuity throughout the transition. ## How the UEM Migration Tool Works The tool runs through three sequential internal stages from the moment you initiate a migration: 1. **Collect:** Reads all device data, policies, groups, and settings from the source server via secure API. 2. **Map & Transform:** Converts source data structures to the equivalent format on the destination product. 3. **Transfer & Verify:** Pushes all data to the destination server with module-level status tracking and retry support. **Tip:** For detailed instructions on tool installation, configuration, and execution, refer to the [Migration Process Guide →](https://www.manageengine.com/products/desktop-central/help/general/migration-process.html). ## Why Use the UEM Migration Tool? Organizations leverage ManageEngine's purpose-built migration utility to eliminate the heavy lifting of manual data entry and configuration mapping. Here are the core benefits: | What You Get | Description | |---|---| | **No Additional Cost** | The tool is available as a free 64-bit Windows executable. No license purchase or subscription is required to download or use it. | | **Zero Operational Downtime** | Both the source and destination servers remain fully operational throughout the migration. Administrators can continue managing endpoints on either server without interruption. | | **Automated Data Transfer** | The tool handles the entire migration lifecycle across three structured phases — collecting data from the source via secure API, mapping and transforming it to match Endpoint Central's structure, and transferring it to the destination with built-in verification. No manual re-entry or policy reconstruction is required. | | **Enterprise-Scale Data Migration** | The tool is designed to handle large volumes of endpoint data without performance limitations, making it suitable for organizations managing hundreds to tens of thousands of endpoints. | | **Granular Status Tracking and Retry Support** | Migration progress is tracked at the module level. If a specific module fails, it can be retried independently without restarting the full migration — reducing the risk of incomplete transfers. | | **Secure Data Collection** | All data is read from the source server through a secure API. There is no direct database access or manual data export involved, ensuring the process is controlled and auditable. | ## What Gets Migrated? The UEM Migration Tool handles the transfer of configurations, policies, and settings between source and destination servers. The scope of migration is categorized into three tiers based on the level of automation involved: ### Fully Automated Transfer These items transfer completely without any manual intervention: | Module | Feature | |---|---| | Mobile Device Management | MDM Device Metadata | | Mobile Device Management | MDM Managed Google Play (non-Gsuite) | | Mobile Device Management | MDM App | | Mobile Device Management | MDM Apps to Groups mapping | | Mobile Device Management | MDM Profiles | | Mobile Device Management | MDM Profiles to Groups Mapping | | Mobile Device Management | MDM Enrollment Token | | Mobile Device Management | MDM Agent Migration Profile | | Scope of Management | SOM Replication policy | | Patch Management | System Health Policy | | Patch Management | Patch Database Settings | | Patch Management | Clean Up Settings | | Patch Management | Download Settings | | Patch Management | Deployment Policy | | Patch Management | Office Click To Run | | Patch Management | Automated Patch Deployment (APD) | | Configuration | Configuration Settings | | Configuration | USB Settings | | Software Deployment | Manual Packages | | Software Deployment | AutoUpdate Policies | | Software Deployment | Auto-update Templates | | BitLocker | BLM Policies | | Device Control Plus | DCP Policies | | Device Control Plus | DCP Trusted Device | | Device Control Plus | DCP Settings | | Endpoint DLP | EDLP Data Classification | | Endpoint DLP | EDLP Policy | | Endpoint DLP | EDLP Override Justification Message | | Application Control | ACP Remove Admin Rights | | Application Control | ACP Policy Deployment | ### Follow-up Required These items transfer automatically with a simple follow-up step on the destination: | Module | Feature | Follow-up Required | |---|---|---| | Mobile Device Management | MDM Users | AD users needs to be configured manually on destination | | Mobile Device Management | MDM Groups | AD Groups needs to be configured manually on destination | | Repository | Script Repository | Files Exceeding 250 MB needs to be configured manually on destination | | Scope of Management | SOM Remote office | Metadata transfers; distribution server is set up fresh on destination | | Scope of Management | SOM Managed Computer | Metadata transfer but agent needs to be migrated & Auto-populates after agent re-installation | | Scope of Management | SOM Custom Group | AD groups & default groups needs to be configured manually on destination | | Patch | Test Group | Test groups with AD groups & default groups needs to be configured manually on destination | | Patch | Decline Patch | Decline patch with AD groups & default groups needs to be configured manually on destination | | Patch | Install/Uninstall Patch Configurations | Configurations linked to non-live patches needs to be configured manually on destination | | Configuration | Configuration Deploy & Configuration templates | All configurations and configuration templates will be migrated, except the following: Mac configurations; Configurations linked to non-live or modified template packages; Configurations with file uploads larger than 250 MB. Certain configurations (e.g., file folder operations, folder backup) may require credentials to execute successfully. These configurations need to be redeployed to the targets with the necessary credentials. | | Software Deployment | Template Packages | Non-live or modified template packages needs to be configured manually on destination | | Software Deployment | Install/Uninstall Software Configurations | Configurations linked to non-live or modified template packages needs to be configured manually on destination | | BitLocker | BLM Deployment | BLM deployment with AD groups & default groups needs to be configured manually on destination | | Device Control Plus | DCP Deployment | DCP deployment with AD groups & default groups needs to be configured manually on destination | | Application Control | ACP Application Group | ACP Application Group with AD groups & default groups needs to be configured manually on destination | ### Administrator-Configured Items These items are intentionally set up fresh on the destination server by the administrator: | Feature | Reason | |---|---| | Apple ABM/ASM Tokens | Standard Apple requirement for any server change | | Domain Credentials | Domain metadata transfers; credentials are re-entered on destination | | AD-based Users & Custom Groups | Recreated on destination; non-AD custom groups transfer fully | | Device-specific MDM Profiles | Group profiles transfer; device-specific profiles are redeployed | | Files Exceeding 250 MB | Configurations with large uploads are re-uploaded on the destination | **Warning:** - **Security Best Practice:** Credential Manager entries are intentionally configured fresh on the destination server to maintain security integrity. Ensure credentials are re-entered with exact precision before initiating migration matching case, spacing, and characters exactly. - **Manual Creation:** Data in features other than the ones mentioned above must be created manually on the destination server. - **Active Directory Exclusions:** Active Directory-based Custom Groups, default Custom Groups, and AD users (along with their associated groups and tasks) will not be migrated. ## Migration at a Glance ManageEngine's migration ecosystem is designed for scale, flexibility, and continuity. Here are the key numbers: | Metric | Value | |---|---| | Migration Paths Supported | 40+ | | Migration Tool Cost | No licensing fee | | Data Loss | Supported migration data is preserved. | | Global Reach | Trusted by customers in 190+ countries | | Migration Workflow | 3 (Prepare → Execute → Verify) | ## Three-Phase Migration Process The migration strategy is systematically structured into three distinct and independent phases: - **Phase 1: Data Migration** Automated transfer of core configurations, policies, custom groups, and settings. - **Phase 2: Agent Deployment** Secure installation of Endpoint Central agents across all targeted OS platforms. - **Phase 3: Device Enrollment** Complete transition and enrollment of endpoints into the destination console. All three phases are designed to run without interrupting your existing endpoint management. The source server, Destination server and Migration Tool remain **fully operational during data migration**. Devices continue to be managed until you explicitly deploy the new agent to each endpoint eliminating any gap in endpoint management coverage.