Device migration
You can migrate devices from one Sophos Fusion account to another for your customers. You might want to move devices between existing accounts for the same customer or to a new account for the same customer.
Click the appropriate tab for instructions.
To migrate computers, do as follows:
- Turn on device migration for the Sophos Fusion accounts. See Turn on device migration.
- Use the Endpoint API to migrate the computers. See Migrate computers using Endpoint API.
- Review the migration results in Sophos Fusion. See Review the migration results.
Requirements
To migrate computers you must be an administrator for both accounts. You must have the Partner Admin role. See Admins and Roles.
You also need API credentials for both accounts. You must have Service Principal Super Admin credentials. See API Credentials.
To migrate computers you use our Endpoint API. Make sure you're familiar with the following concepts:
- You know how our APIs work. See How our APIs work.
- You have set up our APIs and have the tools to work with them. See Getting started as a tenant.
For more information about the Endpoint API see Endpoint API.
Turn on device migration
If you turn on migration it applies to all customers that the template is assigned to. We recommend that you review the customers the template applies to if you want to use an existing template.
If you clone a template check that the other global settings and base policies are correct for your customers.
You must make sure that the customer accounts you're moving devices between are assigned to your template.
The customer account you're moving devices from is your sending account. The customer account you're moving devices to is your receiving account.
To turn on migration, do as follows:
- Click the Global Settings icon
. - Click Products and Services and click Global Templates.
- Select a template.
- Click Global settings and click Device Migration.
-
Turn on Allow device migration.
-
Under Allow migration until a set time, set a time limit to allow migrations for a limited time period.
-
Click Save.
All assigned customers have their base policies and global settings locked in Sophos Fusion Admin.
Migrate computers using Endpoint API
To migrate computers between Sophos Fusion accounts you use our Endpoint API. These instructions summarize the steps you need to take using the API commands. For detailed information on how to use the commands, see Endpoint API.
To migrate computers, do as follows:
-
For the Sophos Fusion account you want to move computers to, do as follows:
-
In your Receiver enviroment, create a receiving job for the endpoints.
You'll get an access token when you do this. You need this to create the sending job for the other Sophos Fusion account. You also need the ID for the receiving job.
-
-
For the Sophos Fusion account you want to move computers from, do as follows:
- Get a list of endpoints you want to migrate.
-
In your Sender environment, create a sending job with the list of endpoints, the access token, and the ID from the receiving job you set up for the other Sophos Fusion account.
This starts the migration.
You can check the progress of the migration in the API. You can get more detailed information in Sophos Fusion.
Review the migration results
You can use the event and audit logs in your Sophos Fusion accounts to check the migration has been successful. You can also check the receiving Sophos Fusion account for the migrated devices.
In your sending account check your audit log. You should see a "Send endpoints to another tenant" event.
You also must check your computers. Go to the Events tab for each computer. For each computer that migrated, you should see "Device registered with new account <AccountID>. It's now managed by that account".
For each computer that didn't migrate you should see "Device failed to register with new account <AccountID>. It continues to be managed by this account".
In your receiving account check your audit log. You should see an "Allow endpoints to migrate to this tenant" event.
You also must check your computers. Go to Overview > Devices, and then click Computers. You should see your migrated computers. Click on a computer to check it. For each migrated computer, you should see that it's registered, has an assigned user, and is up to date.
You can migrate Sophos APX and AP6 access points from one Sophos Central account to another. The migration process requires deregistering the access points from one account and registering them to another as follows:
- Sign in to the Sophos Central account where the access points are registered.
- Go to My Environment > Wireless Access Points.
- Check the Serial number column and make a note of the serial numbers for the access points you want to migrate. You'll need these to register the access points with the new Sophos Central account.
- Select the access points you want to migrate.
- Click Delete.
-
Click Confirm.
Warning
Deleting the access points from Sophos Central restarts them and disconnects any wireless devices.
-
Sign in to the Sophos Central account you want to migrate the access points to.
- Go to My Environment > Wireless Access Points.
- Click Register to add the access points to the new account. For information on registering access points, see Register an access point.
You can migrate Sophos Switch devices from one Sophos Central account to another. The migration process requires individually deregistering the switches from one account and registering them to another as follows:
- Sign in to the Sophos Central account where the switches are registered.
- Go to My Environment > Switches.
- Check the Serial number column and make a note of the serial numbers for the switches you want to migrate. You'll need these to register the switches with the new Sophos Central account.
- Click a switch that you want to migrate.
- Click Remove from Sophos Central.
-
Click Confirm.
Warning
Deleting the switches from Sophos Central restarts them and disconnects any connected devices.
-
Repeat steps 4, 5, and 6 for all the switches you want to migrate.
- Sign in to the Sophos Central account you want to migrate the switches to.
- Go to My Environment > Switches.
- Click Add switches to add the switches to the new account. For information on registering switches, see Add switches.
