Migrate to ePO - SaaS

Prev Next

ePO - SaaS is a multi-tenant, enterprise SaaS model of ePO - On-prem that runs in the AWS cloud infrastructure, accessible through an internet browser. You can migrate from your ePO - On-prem server to cloud using the ePO - SaaS Migration extension. This process allows you to manage your systems that are migrated to the cloud using ePO - SaaS.

Before you begin, make sure that these conditions are met.

  • You have an active ePO - SaaS account.

  • Your ePO - On-prem version is 5.3.1 or later.

  • You have installed the ePO - SaaS Migration extension on your current ePO - On-prem server.

  • The ePO - On-prem server has internet connectivity. If you're using a proxy server, make sure that you have configured the proxy server settings.

  • The client systems can communicate with the ePO - SaaS server.

  • The agent repository policies have proxy settings to connect to the ePO - SaaS server.

  • You have configured the proxy and firewall settings to allow communication with the ePO - SaaS server. For more information, see KB90878.

  • The ePO - SaaS tenant account that you're planning to link has an active subscription and administrator rights.

  • You have identified inactive systems and excluded them from the migration process. Migration can't be complete if even one of the systems is not reachable.

  • You have explored the available options in the Settings page and chose what is relevant to you.

  1. Log on to ePO - On-prem and select MenuePO - SaaSePO - SaaS Migration.

  2. Enter your ePO - SaaS credentials.

  3. (If your email account is associated with multiple tenants...) Select a tenant account from the Select Tenant drop-down.

    The Select Tenant drop-down appears only if the user account is configured for multiple tenants.

  4. Click Link to ePO - SaaS account.

    You have successfully linked your ePO - On-prem to your ePO - SaaS account. The email ID used to log on is displayed in the left pane.

  5. Click Clone configuration to ePO - SaaS to copy the configurations.

    You can see a list of systems that can be migrated, and a list of incompatible products that can't be migrated.

    Tip

    Plan to migrate your systems in multiple phases — A trial phase to migrate few systems, then one or more phases to migrate the remaining systems.

  6. Click Settings to customize the migration, then click Save.

    • Migrate resources — Select Client Task, Policy, Tag, and Active Directory Configuration to migrate them from your system to ePO - SaaS.

    • Delete Systems after Migration — Select to delete the migrated systems on ePO - On-prem server after migrating to ePO - SaaS.

    • Auto Migrate newly added Systems — Select to automatically migrate the newly added systems of a pre-migrated group.

    The ePO - On-prem configurations such as policies, user-defined client tasks, and tags are copied to ePO - SaaS.

  7. (Skip this step if you prefer to manually set up Active Directory server.)

    Migrate Active Directory configurations to :

    1. Click Migrate active directory configurations to ePO - SaaS

      A list of Active Directory servers registered with is displayed. Active Directory servers registered with server names or IP addresses are disabled from migrating the configuration. You can reconfigure such systems with domain names and migrate.

    2. Select the Active Directory servers for which you want to migrate the configuration. Based on the system with which you have registered the Windows Server, select SaaS or On-Premises from the drop-down list, search, and add the server systems. Click GUID-7AAC22A2-66FC-4AFC-833A-C76F74AA7810-low.png to Save selected systems as AD connector. Migrating the configuration takes longer when systems are selected from On-Premises.

    3. Click the checkbox to choose the Active Directory servers. Click Migrate <n> AD configurations, where n is the number of Active Directory connectors that are selected for migrating the configuration. For migrating Active Directory configuration, you can choose a maximum of two Active Directory connectors.

      Migrating the configuration of each Active Directory server can take 20–30 minutes and the migration status is displayed. Click Move to next step.

  8. Select the type of system from the drop-down list, then search your system.

    Type at least 3 characters to see the list of systems.

    • All Systems

    • ePO - SaaS

    • On-Premises (If you select an on-premises system, Active Directory migration will take some time because the system resources will migrate to Trellix in the next ASCI interval only.)

  9. Select the systems, click Save selected systems as AD connector then click Migrate AD configurations.

    Note

    • The maximum number of systems you can select is 2.

    • The systems you select must have access to the domain to which you want to migrate them.

    • Active Directory connectors can be deployed on Windows systems only.

    Important

    The standard ASCI interval is 60 minutes. For Active Directory migration, set the ASCI interval short, preferably 5 minutes. For more information, see Configure the ASCI setting.

    The selected systems are migrated sequentially. Each Active Directory undergoes these 5 steps before successful migration.

    1. The selected systems (managed by ePO - On-prem) are migrated to ePO - SaaS.

    2. Trellix Agent and DXL on the selected systems upgrade to the latest version.

    3. The DXL connectivity of the selected systems is verified.

    4. The Active Directory connector package is deployed on the selected systems.

    5. Checks whether Test Connection for Active Directory passes.

    If one of the selected systems passes the Test Connection check, the Active Directory migration is considered successful.

  10. Click Migrate compatible systems to ePO - SaaS.

  11. Select the groups that you want to migrate, then click Migrate Groups.

    Note

    Choose a group of 10–25 systems as a pilot group to migrate from the current ePO - On-prem server to ePO - SaaS. This enables you to be aware of any issues that might occur before migrating all systems in System Tree.

    You can view the progress of migration in the ePO - SaaS Migration page.

    • All compatible systems in the selected group are tagged as ePO - SaaS Migration.

    • A deployment task ePO - SaaS Migration is created.

    • Three separate deployment packages for ePO - SaaS migration for Windows, Linux, and macOS are checked in to the Main Repository.

ePO - SaaS starts to manage all migrated systems. Migration begins during the next agent-server communication, and systems start to communicate with ePO - SaaS.

  1. Log on to ePO - SaaS and verify if the selected systems appear in System Tree.

  2. Verify if all policies appear as expected.

  3. To see the list of systems in which the Active Directory Connector package is deployed and the details, go to MenuConfigurationDirectory Service.

  4. Continue to migrate the remaining systems.

You can view information about your migrated systems using these queries that are included in the ePO - SaaS Migration extension.

  • Systems By migration status

  • Table View of migrated systems

  • Trend of Migrated systems