Neon glowing brain cloud symbol with digital grid and magenta light rays in dark cyberspace environment
Privilege Cloud Migration

5 Steps to a Clean
Privilege Cloud Migration

A migration is a job where accuracy beats speed every time. Move a few thousand accounts and get even a small subset wrong, and you've got a very long weekend ahead of you. Here are the five steps that you can follow to make sure everything lands where it should.

Scroll to explore
1

Start with a complete inventory

Before anything moves, run reports to collect lists of every safe, account, platform, and permission from the source. That inventory should now be the source of truth that you will work from.

Safes Accounts Platforms Permissions
Source of Truth
Run reports to collect lists from source
Build a single inventory document
This is your source of truth going forward
Automation Benefits

Fast

Consistent

Repeatable

Accurate

API-driven migration beats manual every time

2

Automate the move, don't do it manually

Recreating thousands of accounts by hand is slow, and the likelihood for mistakes to occur is greatly increased. Use the API to "move" safes, accounts, and permissions programmatically and be sure you match up everything to align with what you have On Prem, unless you want to make changes to what you currently have. It's faster, and it's consistent.

3
Critical Step

Test it against a non-prod tenant first

The beauty of scripting the move is that you can run it against a test tenant before you touch production. See what breaks, fix it, and run it again until it's clean. When you migrate in Prod, you've already done it once.

Skip This & Risk
Unknown errors Prod surprises Long weekend Fire drills
Test First Approach
Rehearse Fix early Confidence Clean prod run
Migration Strategy
Batch 1: Unmanaged Accounts Phase 1

Accounts not currently vaulted: low risk, bulk migration, validates automation

Batch 2: Managed Accounts Phase 2

Single migration window: no dual-instance user confusion

Smaller batches = less risk · Easier validation · Cleaner cutover

4

Migrate in batches: unmanaged, then managed

Be careful to not cut off the limb that you're standing on by doing an all-or-nothing cutover. Stand up everything in the new tenant and start migrating accounts in batches that aren't being managed today (we all know they exist). This allows you to do another validation with your automation and generally moves a sizeable chunk of accounts into the new cloud environment. This also reduces the total number of accounts that you would need to move over when you are migrating your managed accounts which would need to be done in a single migration window as you don't want users having to use two different CyberArk instances.

5

Reconcile every batch with a report

After each batch, compare the target back against your source-of-truth inventory and produce a reconciliation report. These reports provide a quality check and add to your audit evidence.

Reconciliation Report

Every account accounted for

All accounts present and verified in target

Every permission matched

Permissions aligned with source inventory

Every exception flagged

Gaps documented for audit trail and follow-up

Quality assurance · Audit evidence · Peace of mind

Follow these and a migration turns into a controlled, boring process, which is just what you want it to be.

If you've got a move to Privilege Cloud coming up, please reach out. We do these all the time.