Migrating TACC to ePO - SaaS using ePO extension

Prev Next

ePO - SaaS is a multi-tenant, enterprise SaaS model of ePO - On-prem that runs in the AWS cloud infrastructure, accessible through an internet browser. You can migrate from your ePO - On-prem server to cloud using the ePO - SaaS Migration extension. This process allows you to manage your systems that are migrated to the cloud using ePO - SaaS.

Before you begin, make sure that these conditions are met.

  • You have an active ePO - SaaS account.

  • Your Trellix ePO - On-prem version is 5.10.0 Update 15 or later.

  • You have the latest TACC On-prem Extension.

  • You have installed the ePO - SaaS Migration extension on your current ePO - On-prem server.

  • The ePO - On-prem server has internet connectivity. If you're using a proxy server, ensure that you have configured the proxy server settings.

  • The client systems can communicate with the ePO - SaaS server.

  • The agent repository policies have proxy settings to connect to the ePO - SaaS server.

  • You have configured the proxy and firewall settings to allow communication with the ePO - SaaS server. For more information, see KB90878.

  • The ePO - SaaS tenant account you plan to link has an active subscription and administrator rights.

  • You have identified inactive systems and excluded them from the migration process. Migration can't be completed if one system is unreachable.

  • You have explored the available options in ePO - On-prem from the MenuePO - SaaSePO - SaaS MigrationSettings page.

  1. Log on to ePO - On-prem and select MenuePO - SaaSePO - SaaS Migration.

  2. Configure ePO - SaaS account:

    1. Click Configure ePO - SaaS account. Enter your ePO - SaaS credentials, to link to an existing ePO - SaaS account.

    2. (If your account belongs to multiple tenants...) Select a tenant account from the tenant drop-down list. The tenant drop-down appears only if the user account is configured for multiple tenants.

    3. Click Link to ePO - SaaS Account.

      You have successfully linked your ePO - On-prem account to your ePO - SaaS account. The email ID used to log on is displayed in the left pane.

  3. Customize migration settings:

    1. Click Settings on the right side of the window to customize your migration. You can select policies and Active Directory configuration from Migrate Resources.

      • Migrate Resources — Select Policy and Active Directory configuration to migrate to ePO - SaaS.

      • Delete Systems after Migration — Select to delete the migrated policies and settings on the ePO - On-prem on-premises server after migrating to ePO - SaaS. If you aren't sure about the migrated resources, we recommend not selecting this option.

      • Auto Migrate newly added Systems — (Recommended) Select to automatically migrate the newly added policies and settings.

    2. Click Save.

  4. Clone configuration to ePO - SaaS:

    1. Click Clone configuration to ePO - SaaS to copy the policies and settings to ePO - SaaS.

    2. Click Clone to ePO - SaaS.

      If you have migrated the policies and settings earlier, the button appears as Clone again to ePO - SaaS. Click Clone again to ePO - SaaS to migrate the newly created or any policies and settings that were not migrated earlier. For example, if you have migrated your TACC policies and settings earlier, you can click Clone again to ePO - SaaS to migrate the rules and rule groups.

  5. (Skip this step if you prefer to manually set up an Active Directory server.)

    Migrate Active Directory configurations to ePO - SaaS:

    1. Click Migrate active directory configurations to ePO - SaaS

      A list of Active Directory servers registered with ePO - On-prem is displayed. Active Directory servers registered with server names or IP addresses are disabled from migrating the configuration. You can reconfigure such systems with domain names and migrate.

    2. Select the Active Directory servers for which you want to migrate the configuration. Based on the system with which you have registered the Windows Server, select SaaS or On-Premises from the drop-down list, search, and add the server systems. Click GUID-7AAC22A2-66FC-4AFC-833A-C76F74AA7810-low.png to Save selected systems as AD connector. Migrating the configuration takes longer when systems are selected from On-Premises.

    3. Click the checkbox to choose the Active Directory servers. Click Migrate <n> AD configurations, where n is the number of Active Directory connectors that are selected for migrating the configuration. For migrating Active Directory configuration, you can choose a maximum of two Active Directory connectors.

      Migrating the configuration of each Active Directory server can take 20–30 minutes, and the migration status is displayed. Click Move to next step.

  6. Migrate compatible systems to ePO - SaaS.

    1. Click Migrate compatible systems to ePO - SaaS.

    2. Select the groups that you want to migrate, then click Migrate Groups.

      Note

      Choose a group of 10–25 systems as a pilot group to migrate from the current ePO - On-prem server to ePO - SaaS.. This enables you to be aware of any issues that might occur before migrating all systems in System Tree.

    You can view the progress of migration in the ePO - SaaS Migration page.

    • All compatible systems in the selected group are tagged as ePO - SaaS Migration.

    • A deployment task ePO - SaaS Migration is created.

    • Three separate deployment packages for ePO - SaaS migration for Windows, Linux, and macOS are checked in to the Main Repository.

    TACC rues, rule groups, tasks with their assignments, policies, and Active Directory configuration are copied to ePO - SaaS. Migration begins during the next agent-server communication.

Log on to ePO - SaaS:

  1. Verify if the selected systems appear in System Tree.

  2. Verify if all policies appear as expected.

  3. Verify that the connectors are installed successfully in ePO - SaaS from the MenuConfigurationDirectory Service page.

  4. Continue to migrate the remaining systems.

You can view information about your migrated systems using these queries that are included in the ePO - SaaS Migration extension.

  • Systems By migration status

  • Table View of migrated systems

    This view automatically excludes all incompatible machines as per the criteria.

  • Trend of Migrated systems