Migrating off Ivanti EPMM without wiping a single device
The fear that stops most EPMM migrations is that every handset has to be factory reset. It does not. Here is how a low user impact migration actually runs.
Every on-premises EPMM environment reaches the same decision point. The servers need patching, the certificates need renewing, the connectors need a maintenance window, and somebody works out what all of that costs per device per year.
The move to Ivanti Neurons for MDM is usually agreed in principle long before it happens. What stalls it is a single question, asked in a steering committee by somebody who has been burned before:
“So we have to wipe every phone?”
No. And the fact that this question still stops migrations is costing organisations real money.
Where the fear comes from
It is not irrational. Historically, moving a device between MDM platforms meant unenrolling from the old one and enrolling into the new one — and on a supervised iOS device, unenrolment could mean losing supervision, which meant a factory reset to get it back.
For a fleet of two thousand handsets held by people who are not in the building, that is not a migration. That is a year-long argument.
What actually happens now
Ivanti’s Low User Impact migration path moves managed devices between EPMM and Neurons for MDM without a factory reset. On most fleets the user experience is a notification, a prompt to accept the new management profile, and a short reconfiguration.
That is the headline. The detail is where migrations succeed or fail.
The things that actually break
In our experience the reset is never the problem. These are:
Certificates. If your EPMM environment issues device or user certificates from an internal CA through a connector, that trust chain has to exist in the new environment before a single device moves. This is the most common cause of a stalled wave.
Per-app VPN. Per-app VPN configurations reference certificate payloads and app identifiers that do not always carry across cleanly. Test this on the pilot cohort with the actual applications, not with Safari.
Email profiles. Devices that lose and re-establish their mail profile will re-download the mailbox. Do that to four hundred devices simultaneously on a Monday morning and you will have a conversation with the messaging team.
Conditional access. If device compliance signals feed Entra ID, there is a window during cutover where the device is not reporting compliant to either platform. Plan for it, or people lose access mid-migration and log a P1.
Apps distributed with configuration. Managed app configuration is delivered by the MDM. Applications that receive their server address, tenant or authentication settings that way will need those settings re-delivered — and until they arrive, the app looks broken to the user.
How we sequence it
The pattern that works:
- Assess first. Device inventory, policy inventory, integration inventory. Specifically: which policies are actually applied to devices, as opposed to which policies exist. In most environments those are very different lists.
- Do not migrate the debt. A migration is the only realistic opportunity you will get to rebuild policy against current requirements. Translating policy rather than copying it adds a week and saves years.
- Build and prove the target. Certificates, identity, mail, VPN and conditional access verified in the new tenancy before any production device moves.
- Pilot with people who will tell you. Twenty to fifty devices, chosen from users who will report a problem rather than work around it silently. IT staff are a bad pilot cohort for exactly this reason.
- Wave by cohort, with a gate. Each wave has a documented rollback position and a defined success criterion. If a wave fails its criterion, the next one does not start.
- Decommission last, and carefully. Trace every connector and certificate dependency before switching off the on-premises infrastructure. Something is always still pointing at it.
What it is worth
The saving that gets quoted is the infrastructure — servers, licences, the maintenance window, the patch cycle. That is real, but it is not the largest item.
The largest item is that the platform stops being a thing your team has to keep alive. No more emergency certificate renewals. No more version compatibility matrices. No more capacity planning for a workforce that changes size every six months.
The one-line version
You do not have to wipe the fleet. You do have to know what your certificates, VPN profiles and app configurations depend on — and that is what the assessment is for.
If you are sitting on an EPMM environment and deferring the decision, we can tell you what the migration would actually involve.