Applies to: EPP 7.2, EPP 7.4 SP2, EPP 7.6 SP5 → EPP 8.5 (on-prem) or EPP Cloud 6.0
1. Overview
This guide consolidates all EPP 7.x → EPP 8.5 migration paths into a single document. Instead of pointing customers to a different article for every source version, use this one document for any customer running EPP 7.2, 7.4, or 7.6 direct them to Section 2 to find their row, then to the matching numbered section.
Migration transfers Groups, Clients, and Policies from the old 7.x EPP server to the new EPP 8.5 server (or to EPP Cloud). It does not transfer Users, Reports, or Patch Management settings on any version. See Section 7 for the full list of exclusions.
Where to find this in the console: in the EPP 8.5 console, go to Deployment > Migration. This page has two options:“EPP 7.x to EPP 8.x” (Section 4 of this page) and“Migrate to Cloud” (Section 6). This section covers both, but only for a customer moving from EPP 7.2 / 7.4 / 7.6.
2. Find Your Migration Path
Use this table to identify the customer's starting version and the correct section to follow.
| Your Current Version | Migration Target | What Gets Migrated | Section number |
|---|---|---|---|
| EPP 7.6 SP5 | EPP 8.5 (on-prem) | Groups, Clients, Policies | 4 Unified Migration Steps |
| EPP 7.4 SP2 | EPP 8.5 (on-prem) | Groups, Clients, Policies | 4 Unified Migration Steps |
| EPP 7.2 | EPP 8.5 (on-prem) | Groups, Clients, Policies | 4 Unified Migration Steps |
| EPP 7.6 SP5 / 7.4 SP2 / 7.2 | EPP Cloud 6.x | Groups, Clients, Policies | 6 Migration to Cloud |
| Endpoint Security 5.x, 6.x & 7.5 | Not directly supported | Not applicable | Upgrade to EPP 7.6 SP5 first, then follow Section 4 |
Applies to all paths
- Linux and Mac clients are not migrated automatically on any path. See version-specific limitations.
- Internet Explorer 11 is required on Windows 7 endpoints.
- Reboot is required once migration completes.
3. Before You Begin – Common Pre-Migration Checklist
Regardless of which version you are migrating from, confirm the following before starting. Version-specific requirements (service pack, OS exclusions, tool acquisition, limits) are consolidated in Section 4.
- SSR = Secondary Server (also called Secondary Site Server) a provision from EPP 7.x where a customer runs master and secondary servers across different sites. The SSR onboarding notes in Section 4 only matter if you are actually using a master-secondary setup. Customers using single site-server architecture, mentioned notes don't apply.
- Decide the client installation path prior downloading the client migration tool. If you need a non-default path, set it in EPP 8.5 console > Configurations > Client Installation before migrating , it cannot be changed after that.
- Endpoints may reboot up to twice during migration.
- EPP 7.x to EPP 8.x migration page is active for only 60 days from feature activation.
4. Unified Migration Steps EPP (EPP 7.2 / 7.4 / 7.6 → EPP 8.5)
In the EPP 8.5 console, this feature lives under Deployment > Migration, which has two options: “EPP 7.x to EPP 8.x” (covered in this section) and “Migrate to Cloud” (Section 6). The download links for the Export Tool and the Client Migration Tool are provided on the same Migration page for all three source versions, you can simply pick the link matching your old EPP version (7.2, 7.4, or 7.6). From that point, the procedure is the same five steps EPP for every version; only a handful of details differ, captured in the tables below.
Service Pack & OS requirements by version
| Starting Version | Required Service Pack | OS Exclusions (in addition to Section 2) |
|---|---|---|
| EPP 7.6 | Service Pack 5 (SP5) on server & clients | Linux, Mac, Win Vista, Win XP, Win 2000 Server, Win 2008 Server not supported |
| EPP 7.4 | Service Pack 2 (SP2) on server & clients | Linux, Mac, Win Vista, Win XP, Win 2000 Server, Win 2008 Server not supported |
| EPP 7.2 | None specified | Linux, Mac, Win Vista, Win XP, Win 2000 Server, Win 2008 Server not supported |
Version-specific details below
| Version | Export Tool Filename | Default Export Path | Max Groups | Max Policies |
|---|---|---|---|---|
| EPP 7.6 | Export Tool (downloaded from the version-specific link on the Migration page) | …\Seqrite\Seqrite Endpoint Protection 7.60\Admin\Export | 1697 | 1698 |
| EPP 7.4 | Export Tool (downloaded from the version-specific link on the Migration page) | …\Seqrite\Seqrite Endpoint Protection\7.4\Admin\Export | 1697 | 1698 |
| EPP 7.2 | Export Tool (downloaded from the version-specific link on the Migration page) | …\Seqrite Endpoint Protection\7.2\Admin\Export | 1697 | 1698 |
Important : Applies to all three versions
- Secondary Server (SSR) must be onboarded to Control Center before exporting/importing group, client, and policy data (Step EPP 1–2). See the note on SSR in Section 3 this does not apply to single-site-server customers.
- If OS requirements are not met, data will not migrate.
- Clients install to the default path unless changed beforehand: EPP 8.5 console > Configurations > Client Installation.
- EPP 7.4 only: if the EPP 7.4 server runs 64-bit OS with self-protection enabled, exporting to the default path will fail use a custom path instead.
Step 1: Download and run the Export Tool on the old EPP server
- Go to EPP 8.5 console > Deployment > Migration > EPP 7.x to EPP 8.x. Download the Export Tool using the link that matches your old EPP version 7.2, 7.4, or 7.6.
- Run the downloaded tool on the old EPP 7.x console to collect the Client, Group, and Policy data.
- When prompted ‘Do you want to change export location? [y/n]’, type ‘y’ for a custom path or ‘n’ for the default path (see the table above for your version's default path).
- Tool exports Client.dat, Groups.dat and Policy files and zips them automatically into Export.zip.
Step 2: Import data into the EPP 8.5 console
- In the EPP 8.5 console, go to Deployment > Migration > EPP 7.x to EPP 8.x this same page is used to import data regardless of which version you're migrating from.
- Click Import Data. Client and Groups and Policy are selected by default; clear selection if you don't want to import.
- Click Browse / Upload File and select the Export.zip file.
- Click Import. a success message confirms the data has been imported. Check the table above for your version's max groups/policies limit.
Note on duplicate groups & policies (all versions)
- If a duplicate group exists on both the old server and EPP 8.5, it is skipped but if the applied policies differ, the EPP 8.5’s policy is retained.
- If a duplicate Policy, Device name, or User Defined Dictionary name is found, a timestamp is appended to the imported name.
Step 3: Download and run the Client Migration Tool
- On the same Migration > EPP 7.x to EPP 8.x page, download the Client Migration Tool using the link that matches the your old EPP version, this will download migrate.zip.
- Extract migrate.zip on the old 7.x server. It contains acsvpack.exe and supporting files (clagnt.dat, accadef.ini, agntsetp.exe, agsetp64.exe, clagnt.ini etc).
- Run acsvpack.exe on the old EPP console, console matching the version you downloaded the tool for.
- When prompted, choose Yes to migrate endpoints group-wise, or No to migrate all endpoints at once.
- Click OK, migration service pack is now applied on the old server. From here, the remaining EPP client migration process is identical across all versions.
Step 4: Migrate endpoints, group by group
- Log on to the old EPP console and go to Clients > Manage Groups.
- Select the group to migrate, each group can only be migrated once. Choose “Migration to EPP 8.x” from the submenu.
- Click Yes to confirm.
- Restart the endpoint when prompted. Upto 2 restarts may be required.
- Migration applies to the selected parent group and all of its child subgroups.
- For Linux clients: Import of Export.zip at 8.x/Cloud console. Go to EPP 8.5 console > Deployment > Online Installer, download the latest Linux packager, extract, and run it on respective Linux client. This uninstalls the old client and installs the new one automatically.
Step 5: Remove inactive clients from the old console
- Migrated clients show as offline/inactive on the old console.This is expected.
- Log on to the old web console and go to Admin Settings > Clients.
- Under Inactive Client Settings, select Enable automatic removal of inactive clients.
- Choose the number of inactive days after which a client is considered inactive, then click Apply.
Limitations common to all three versions
- The Default client on the old EPP server is not migrated, uninstall the old server, then install the EPP 8.5 client manually.
- Update Agent upgrade is not supported.
- EPP Users and Reports are not migrated.
- Patch Management settings are not migrated.
- Mac clients are not supported. Uninstall the old client and install the EPP 8.5 client manually.
5. After Migration Common Verification Steps on EPP
- Confirm that the migrated clients appear online in the EPP 8.5 console.
- Confirm the same clients show as offline/inactive on the old server console. This is expected, not an error.
- Run the inactive-client cleanup on the old console (Step 5 in Section 4) so the old console doesn't carry stale entries.
- Spot-check that policies applied to migrated groups match expectations, especially for any group that existed on both old and new servers (duplicate groups keep the EPP 8.5 policy see the note under Step 2 in Section 4).
6. Migrate to Cloud
Step 0 Get onboarded to EPP Cloud
- Customer must opt in for a new EPP Cloud license key. This is arranged through the Seqrite Sales team, not through the EPP console.
- The new Cloud key/tenant must be onboarded on the Cloud side separately.
- Once onboarded, you can enable the migration tab from backend and follow the same steps to first import the data from old 7.x console to EPP on cloud under the same migration page and download the Client migration tool to execute on the old 7.x console.
- Advise you to reach out to your Sales representative to request the Cloud key, and to Support to complete the tenant onboarding, before starting Step 1 below.
Once onboarding is complete, the rest of the process is the same:
- In the EPP console, go to Deployment > Migration.
- Select Migrate to Cloud.
- Click Export a zip file containing client, group, policy and global configuration data downloads automatically.
- Sign in to the now-onboarded EPP Cloud tenant and import the exported data.
- Download the resulting .dat file from the Cloud tenant and issue the migration command to the migrated endpoints via EPP Console > Client Actions.
Migrated endpoints will initially show offline in the on-prem console until the migration command is issued and takes effect.
7. What Is Never Migrated (All Versions)
Set customer expectations up front the following are out of scope for every migration path above:
- EPP Users and Reports
- Patch Management settings
- Update Agent upgrades
- Linux and Mac clients (must be uninstalled and manually reinstalled on EPP 8.5)
- The server's own Default client
- Master-Secondary server setups (EPP 7.6 path)
8. Frequently Asked Questions
My customer is on EPP 5, 6, or a version up to 7.5 that isn't 7.2, 7.4, or 7.6 what do I tell them?
These versions are not directly supported by the migration tool. Per Seqrite's supported-path table, they should first upgrade to EPP 7.6 SP5, then follow the Section 4 migration path from there.
Can you skip straight to EPP Cloud instead of EPP 8.5?
Yes EPP 7.2, 7.4 SP2, and 7.6 SP5 can all migrate directly to EPP Cloud 3.0 with the same scope (Groups, Clients, Policies). Direct them to Section 6.
Will you lose your historical reports?
Yes Reports and Users are not part of any migration path today. Set this expectation before migration begins to avoid a support escalation afterward.
Can you self-serve the Cloud migration without contacting anyone?
No. A new EPP Cloud license key and separate tenant onboarding are required before the data export/import step before you begin. Direct reach out to Sales for the license key and to Support for tenant onboarding.