# Migration Process Step-by-step guidance on how to migrate to ManageEngine Endpoint Central — including architecture, pre-migration checklist, step-by-step tool execution, agent migration, post-migration verification, and FAQs. ## Migration Architecture & Workflow The migration process runs through three phases with distinct checkpoints at each stage. The following workflow covers the complete end-to-end journey from preparation to a verified, stable destination in Endpoint Central. ![Migration Architecture and Workflow](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/general/migration-arch.webp) > **Tip** > > **Uninterrupted management by design:** The source server, destination server, and migration tool remain fully operational throughout data migration. Devices continue to be managed until you explicitly deploy the new agent to each endpoint — there is no forced cutover and no gap in endpoint management coverage. ## UEM Migration Tool — Key Capabilities The UEM Migration Tool is ManageEngine's dedicated utility for automating UEM product transitions. It is available as a free download and provides a web console-based interface for managing the entire migration lifecycle. - **Free download** — No additional licensing or subscription fees. - **64-bit Windows executable** — Runs on Windows Server or Windows desktop machine. - **Web console interface** — Browser-based management dashboard for migration operations. - **Multi-module selection** — Choose exactly which of the 11 migration modules to migrate. Modules not selected initially can be added later using Add New. - **Module-level retry** — Retry failed modules individually without rerunning the full migration. - **Proxy support** — Configure server connection type for restricted network environments (Settings → Proxy). - **NAT settings** — Configure NAT rules for Apple device management scenarios (Settings → NAT). - **API key authentication** — Secure API authentication for on-premises sources (Admin → API Explorer → API Key). - **Zoho OAuth** — Sign in securely via Zoho accounts with consent-based authorization for cloud instances. ## Pre-Migration Checklist & Network Port Requirements Completing each item in this checklist before running the UEM Migration Tool ensures a smooth, uninterrupted transition. This preparation phase is the foundation for a successful migration. ### a. General Prerequisites 1. Both source and destination server licenses must be active before starting migration. 2. Both the source and destination servers must be reachable from the machine running the migration tool. 3. For on-premises source or destination servers, the server URL entered in the migration tool must be in FQDN format — IP addresses are not accepted. 4. For on-premises servers, verify that the NAT settings configured on both the source and destination servers match the domain in each server's SSL certificate. ### Prerequisites for Data Migration #### Source server 1. Source server must be upgraded to the [latest build](https://www.manageengine.com/products/desktop-central/service-packs.html) before starting. 2. Agent Protection Settings disabled on source (required for agent migration). #### Destination server 1. APNs certificate must be configured on destination, required for iOS device management. 2. Knox enrollment must be configured on destination, required for Android device management. 3. Create the credentials in Credential Manager on the destination server exactly as they exist on the source server, ensuring there are no case sensitivity errors, spaces, or extra characters (only if credentials are used in configurations). 4. Add and integrate Active Directory in the MDM module on the destination server before initiating migration. ### Prerequisites for Agent Migration #### Source server 1. Agent Protection Settings disabled on source (required for agent migration). > **Note** > > No prerequisites are required on the destination server for agent migration. Ensure data migration is completed successfully before deploying agents to endpoints. ### Prerequisites for Device Migration #### Destination server 1. APNs certificate must be configured on destination, required for iOS device management. 2. Knox enrollment must be configured on destination, required for Android device management. > **Note** > > No prerequisites are required on the source server for device migration. Ensure data migration and agent migration are completed successfully before proceeding. ### b. Network & Connections **Outbound** - For on-premises source or destination servers, allow outbound access from the machine running the migration tool to the source or destination server's domain and port. This step is not required if the source server and the migration tool are on the same network. - For cloud source or destination products, allow outbound access to `*.manageengine.com` and `*.zoho.com` on port 443 from the machine running the migration tool. The exact domains may vary based on your data center region — refer to the regional whitelisting table above. **Inbound (iOS Devices)** If you are migrating iOS devices, enrollment can be completed using either of the following methods: - Using the ManageEngine MDM App — no additional port configuration required. - Using Webclip — ensure port 7383 is open for inbound connections on the source server before distributing the iOS migration profile. #### Required Domains Whitelisting If you need specific domains to be whitelisted, allow the following: | Domain URL | Purpose | |---|---| | https://patchdb.manageengine.com | Patch database updates sync | | https://mdm.manageengine.com | Mobile Device Management profiles & settings | | https://mdmdatabase.manageengine.com | MDM database sync | | https://www.zoho.com | Zoho authentication APIs | | https://manageengine.com | ManageEngine portal resources | | https://creator.zoho.com | Zoho Creator integration services | #### Regional Data Center Whitelisting Based on your data center location, whitelist the following regional domains: | Data Center | MDM Domain | Endpoint Central Domain | Download Domain | Accounts Domain | Upload Domain | |---|---|---|---|---|---| | US (.com) | mdm.manageengine.com | endpointcentral.manageengine.com | download-accl.zoho.com | accounts.zoho.com | upload-accl.zoho.com | | EU (.eu) | mdm.manageengine.eu | endpointcentral.manageengine.eu | download-accl.zoho.eu | accounts.zoho.eu | upload-accl.zoho.eu | | IN (.in) | mdm.manageengine.in | endpointcentral.manageengine.in | download-accl.zoho.in | accounts.zoho.in | upload-accl.zoho.in | | AU (.com.au) | mdm.manageengine.com.au | endpointcentral.manageengine.com.au | download.zoho.com.au | accounts.zoho.com.au | upload-accl.zoho.com.au | | JP (.jp) | mdm.manageengine.jp | endpointcentral.manageengine.jp | download.zoho.jp | accounts.zoho.jp | upload-accl.zoho.jp | | CN (.com.cn) | mdm.manageengine.cn | endpointcentral.manageengine.cn | download.zoho.com.cn | accounts.zoho.com.cn | upload-accl.zoho.com.cn | | CA (.ca) | mdm.manageengine.ca | endpointcentral.manageengine.ca | download.zohocloud.ca | accounts.zohocloud.ca | upload-accl.zohocloud.ca | | UK (.co.uk) | mdm.manageengine.co.uk | endpointcentral.manageengine.co.uk | download-accl.zoho.co.uk | accounts.zoho.co.uk | upload-accl.zoho.co.uk | | SA (.sa) | mdm.manageengine.sa | endpointcentral.manageengine.sa | files.zoho.sa | accounts.zoho.sa | upload-accl.zoho.sa | | AE (.ae) | mdm.manageengine.ae | endpointcentral.manageengine.ae | files.zoho.ae | accounts.zoho.ae | upload-accl.zoho.ae | ## Step-by-Step Migration Execution The migration execution is divided into two sequential phases: **Data Migration** (configurations, policies, settings) followed by **Agent/Device Migration** (deploying new agents to endpoints per OS). > **Important** > > Complete data migration first. Deploy agents only after all modules are successfully migrated to the destination server. ### 1. Setup and Prerequisites 1. Download the [UEM Migration Tool](https://www.manageengine.com/ems/migration-tool.html) on the machine running the central server. 2. Install the downloaded EXE file and set up credentials to access the migration tool. Once you sign in, you will be able to view the migration tool console. 3. Configure [Proxy Settings](https://www.manageengine.com/products/desktop-central/help/server/configuring-proxy-server.html). Supported options: 1. **No Connection to Internet** 2. **Direct Connection to Internet** 3. **HTTP Proxy configuration** 4. **Automatic configuration using script** To set up proxy settings, click **Settings → Proxy → Choose the connection type** from the dropdown → **Save**. ![Migration Tool - Proxy Settings](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/migration-1.webp) 4. For Apple devices, configure [NAT settings](https://www.manageengine.com/products/desktop-central/help/admin/nat-settings.html) by clicking **Settings → NAT** and adding the required IP address or FQDN, then click **Save**. ![Migration Tool - NAT Settings](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/migration-2.webp) 5. Navigate to the **Migration** tab and click **Migrate Now** to proceed. ![Migration Tool - Migrate Now](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/migration-3.webp) ### 2. Source Authentication (On-Premises as Example) > **Note** > > 1. If you are migrating from a cloud product, select the product name and proceed to the [cloud authentication](https://www.manageengine.com/products/desktop-central/help/general/migration-process.html#cloud-authentication) steps. > 2. If you are migrating from or to MSP products, contact [support](mailto:endpointcentral-support@manageengine.com) for further assistance. 1. Select the required product for migration (for example, **Endpoint Central On-premises**). 2. Enter the complete URL (FQDN) and port number of your source server. 3. Select the domain associated with your administrator account. 4. Enter the credentials of an administrator account with the required privileges on the source server and click **Proceed** to authenticate. Once validated, the tool connects to the source server and transitions to the Destination Server Details section. ![Migration Tool - Source Server Authentication](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/migration-server-auth.webp) ### 3. Destination Authentication (Cloud as Example) 1. Select the destination product (for example, **Endpoint Central Cloud**). 2. Select the **Data Center** (US, EU, CN, IN, AU, UK, CA, SA, AE, JP) in which your cloud account is hosted. ![Migration Tool - Destination Server Authentication](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/migration-dest-auth.webp) 3. Click **Authenticate**. You will be redirected to the Zoho Accounts page to sign in with your credentials. ![Migration Tool - Zoho Sign-in](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/zoho-signin.webp) 4. On the **Consents page**, read the terms and agreements and click **Accept**. ![Migration Tool - UEM Migration Services](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/uem-migration-service.webp) ### 4. Module Selection & Execution 1. After completing authentication, select the modules to migrate. The tool presents 11 migration modules — select the ones relevant to your migration path: ![Migration Tool - Module Selection](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/migration-custom.webp) - Mobile Device Management - Scope of Management - Patch - Software Deployment - Configuration - Repository - Vulnerability Manager (VMP) - BitLocker - Device Control Plus - Application Control - Endpoint DLP 2. **Pay attention to dependencies:** Some sub-groups within a module depend on others. For example, within the Mobile Device Management module, MDM Groups depends on MDM Users — if MDM Users is not selected, MDM Groups cannot be migrated. 3. Select the prerequisites checkbox to view the list of prerequisites in a pop-up, verify them, and click **Agree and Proceed**. ![Migration Tool - Module Prerequisites](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/migration-popup.webp) 4. Click **Migrate** to initiate data migration. ![Migration Tool - Module Migration](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/migration-modules.webp) 5. Monitor progress on the **Migration Status** page. ### Retry Option for Migration Failure 1. **Failure Recovery:** If a module fails, click **Retry**. If a dependent module fails, it will be marked as **Skipped**. You cannot edit details while migration is in progress. ![Migration Tool - Migration Status](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/server/migration-status.webp) 2. Use the **Add New** button to migrate additional modules that were not selected in the initial run. ## Post-Migration Verification > **Note** > > After completing data migration, agent deployment, and device enrollment, perform the following verification steps to confirm a clean and stable transition. - Migrated agents land in the default remote office by default. Manually move them to their respective remote offices after migration is complete. Refer to [Remote Office Management](https://www.manageengine.com/products/desktop-central/help/configuring_desktop_central/managing_computers_wan.html) for steps. - Distribution servers for each remote office must be manually installed on the destination server after migration. - Inventory scan details will populate automatically after agent migration completes. - Configurations and Automated Patch Deployment (APD) tasks are saved as drafts and remain suspended after migration. Redeploy them to the target devices after moving agents to their respective remote offices. - Only manually created software packages and template packages that are live and unmodified are migrated. All other packages must be recreated on the destination server. - Domain metadata transfers automatically. Enter domain credentials on the destination server to sync the domains. - After migration, mobile devices are moved to their respective groups. Device-specific MDM profiles are not migrated and must be manually redeployed to the respective devices on the destination server. - Only Android Enterprise apps and enterprise apps are migrated. Apple ABM/ASM tokens must be manually added on the destination server after migration.