> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migration-faqs-xsoar-6-on-prem-to-xsoar-8-saas.md).

# Migration FAQs - XSOAR 6 On-Prem to XSOAR 8 SaaS

The following sections describe the frequently asked questions when migrating from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS.

* [General](#general)
* [Users and roles](#users-and-roles)
* [UAT phase - Migration wizard](#uat-phase---migration-wizard)
* [Dev/Prod - Migration wizard](#developmentproduction---migration-wizard)
* [IP address changes](#ip-address-changes)
* [Switchover date](#switchover-date)

### General

<details>

<summary>Who is the Cortex XSOAR 6 On-prem to SaaS migration available for?</summary>

The Cortex XSOAR 6 On-prem to SaaS migration (for a single tenant) is available for all customers, including FedRAMP Moderate.

</details>

<details>

<summary>I am currently using Cortex XSOAR 6 On-prem. What are my migration options?</summary>

| Migration To                            | Migration Option                              | Availability                                                                                                                                                                         | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| --------------------------------------- | --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| XSOAR 8 SaaS                            | Self-service migration to Cortex XSOAR 8 SaaS | Now                                                                                                                                                                                  | <p>A self-service migration option is available now. This option does not include the migration of indicator or incident data.</p><p>To use the self-service migration option, activate a new Cortex XSOAR 8 tenant for up to 60 days by requesting an evaluation license. After self-service migration, you can decommission your Cortex XSOAR 6 server and then move your licenses to Cortex XSOAR 8. We recommend going through this process with your assigned Customer Success Representative and Sales Representative to assist in migrating your content such as automations, playbooks, etc.</p><p>See <a href="/pages/kb7zxcR3ciubPWSFERMi">Migrate from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS (Self-Service)</a>.</p> |
| Start fresh with Cortex XSOAR 8 SaaS    | Now                                           | Activate a new Cortex XSOAR 8 tenant without migrating content or data.                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Migration Wizard to Cortex XSOAR 8 SaaS | Now                                           | Migration wizards automate data migration, including incidents and indicators, to Cortex XSOAR 8 SaaS. You must upgrade to Cortex XSOAR 6.13 and above to use the migration wizards. |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

</details>

<details>

<summary>I currently have a child tenant (part of MSSP), and I want to move to an Enterprise (standalone) tenant. What are my options?</summary>

This is not supported. We support migration from Cortex XSOAR 6 Enterprise to Cortex XSOAR 8 SaaS Enterprise and Cortex XSOAR 6 Multi-tenant to Cortex XSOAR 8 SaaS Multi-tenant. For other options, you need to create a new Cortex XSOAR 8 tenant.

</details>

<details>

<summary>Do I need to update Cortex XSOAR 6 before migration?</summary>

If you want to use the migration wizard, upgrade to 6.13 and above.

</details>

<details>

<summary>In which region will my Cortex XSOAR 8 tenant be created?</summary>

Cortex XSOAR 8 is deployed on GCP Cloud. When you create your Cortex XSOAR 8 tenant, you select a geographical region where the tenant will reside. You can view a complete [list of available regions](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/supported-host-regions.md).

</details>

<details>

<summary>Who can initiate the migration?</summary>

You can activate your tenants (DEV/PROD) using the CSP Account Admin (Super User). If you can't see your tenant for activation in Cortex Gateway, check your entitled account using your serial number in the [Admin Site](https://adminsite.paloaltonetworks.com/EntitlementsSearch).

</details>

<details>

<summary>Do I need to redeploy engines as a part of the migration to Cortex XSOAR 8?</summary>

Yes. If you are using the migration wizard, during the UAT phase, engines will work with both Cortex XSOAR 6 and Cortex XSOAR 8. After the switchover, Cortex XSOAR 6 engines will not work with Cortex XSOAR 8. Engines should be upgraded and IP addresses updated during the UAT phase.

</details>

<details>

<summary>Are API keys migrated?</summary>

No. The Cortex XSOAR 8 URL is different from the Cortex XSOAR 6 URL. Users have to use a new URL to access the new system. Other components, such as SSO integrations or API keys, that rely on the legacy URL, will not continue to function and must be reconfigured. If you are using the migration wizard, you should complete the reconfiguration steps during the UAT phase.

</details>

<details>

<summary>Do I need to do anything with my SSO?</summary>

Yes, SSO settings depend on the URL, which will change when you move to Cortex XSOAR 8 SaaS. SSO settings should be reconfigured during the UAT phase.

</details>

<details>

<summary>We have a lot of data (incidents and indicators) in Cortex XSOAR 6. Is everything migrated and kept forever?</summary>

The default retention period for incidents in Cortex XSOAR is 6 months. After your renewal date, you will have a further 6-month retention period (default period), which can be extended by purchasing retention licenses. For more information about the retention policy, see [Retention Policy and Enforcement](/cortex-xsoar-8-retention-policy/cortex-xsoar-8-retention-policy-faqs/readme.md).

From 2025, although indicators do not have a time limit, they will be limited per tenant as follows:

* XSOAR + TIM customers: Up to 100 million indicators
* XSOAR customers (no TIM license): Up to 3 million indicators

</details>

<details>

<summary>Are Docker images migrated?</summary>

Docker images are migrated unless they are in an external registry, they start with `demisto/`, or the base image name contains a dot. Dots are allowed in the tag-name component after the `:`.

Images in the `localhost` registry will be migrated with the name trimmed.

Examples of Docker images that are migrated as-is:

* `custom-python:latest`
* `my-image:1.3`
* `custom/python:3.14`

Examples of Docker images with address trimmed:

* `localhost/my-image:1.3` to `my-image:1.3`
* `localhost/custom/my-image:1.3` to `custom/my-image:1.3`
* `localhost:5000/my-image:1.3` to `my-image:1.3`

Examples of Docker images that will not be migrated:

* `demisto/python:3.12801`
* `demisto/custom-image:latest`
* `demisto/custom-image:3.12801`
* `organization-registry.io:5000/my-image:1.3`
* `docker.github.io/my-image:1.3`
* `102.57.81.150:5000/custom/python:3.14`

</details>

<details>

<summary>How long are Management Audit logs kept?</summary>

For migrated customers, Management Audit logs are kept for 10 years.

</details>

### Users and roles

<details>

<summary>Which users are migrated from Cortex XSOAR 6 to Cortex XSOAR 8?</summary>

Only users with a unique email address in Cortex XSOAR 6 are migrated to Cortex XSOAR 8 with the migration wizard. E-mail addresses should be valid and unique (you cannot reuse the same email address).

</details>

<details>

<summary>Are custom roles migrated? Will users in Cortex XSOAR 8 receive the same permissions as in XSOAR 6?</summary>

Yes. If you are using the migration wizard, at the initial data sync stage, when the UAT phase begins, roles are migrated, including any custom roles from Cortex XSOAR 6. At the switchover date, users and roles are not resynced, so any roles created during the UAT phase in Cortex XSOAR 6 are not migrated.

Users have the same permissions, but roles are managed differently in Cortex XSOAR 8. Cortex XSOAR 8 includes user groups. Read more about how [users and roles](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management.md) are managed in Cortex XSOAR 8.

</details>

### UAT phase - Migration wizard

<details>

<summary>Who can access the environment during the UAT phase?</summary>

Only Instance Administrators and Account Admins can access the Cortex XSOAR 8 tenant during the UAT phase. In the migration form, before the migration starts, you specify which users can access the UAT. Those users must exist in Cortex XSOAR 6 with an email address; otherwise, they will not be migrated to Cortex XSOAR 8. If that occurs, you need to create a new user for that user in the CSP.

{% hint style="info" %}

### Tip

We recommend you verify that all required users exist in Cortex XSOAR 6 before the initial data sync.
{% endhint %}

</details>

<details>

<summary>Are instance credentials transferred as part of the data sync?</summary>

Yes, they are transferred, but only once during the initial sync. As credentials are not resynced during the switchover date, we recommend refraining from changing them during the UAT phase. If you make changes after the initial sync, they should be done manually in both Cortex XSOAR 6 and Cortex XSOAR 8.

</details>

<details>

<summary>How long does the UAT phase take?</summary>

It depends on the number of use cases that you have. It should not take more than a few days for a person dedicated to this task in an average deployment.

</details>

<details>

<summary>What is the recommended timeframe for the UAT phase?</summary>

We recommend keeping the UAT phase as short as possible to reduce the number of changes made on Cortex XSOAR 6, as data needs to be resynced to Cortex XSOAR 8 at the switchover date, which will impact the service downtime length (up to 12 hours of downtime during the switchover). By default, the switchover date is pre-scheduled for a month after the migration starts. If you complete the UAT phase earlier, we recommend changing the switchover date to the earliest possible date.

</details>

<details>

<summary>Is there downtime for Cortex XSOAR 6 during the initial sync?</summary>

There is no downtime during the initial sync. Your Cortex XSOAR 6 environments must be running 6.13 and above.

</details>

### Development/Production - Migration wizard

<details>

<summary>Is the Development to Production 'Excluded Changes' list on our Cortex XSOAR 6 Dev instance migrated to Cortex XSOAR 8?</summary>

Yes, they are migrated.

</details>

<details>

<summary>Can I migrate my development tenant separately from my prod tenant using the remote repository feature?</summary>

During the UAT phase, the migration steps for development and production machines are performed separately, and the switchover date for development and production machines does not need to be set simultaneously. We recommend migrating the development tenant before migrating the production tenant.

</details>

<details>

<summary>We are using a private content repository. Can we continue to use it in Cortex XSOAR 8?</summary>

Yes. In the pre-migration wizard, specify that you are using a private content repository.

</details>

<details>

<summary>Should we use our GitHub repository or move to the built-in repository? What are the pros and cons?</summary>

We recommend using a built-in repository for a simple one-branch deployment. However, if you would like to use multiple branches or need access to the content repository outside the Cortex XSOAR platform (for example, to implement some scanners),, you must use a private repository.

</details>

### IP address changes

<details>

<summary>Are IPs and URLs changed during the migration? What do we need to do?</summary>

Yes, both IPs and URLs have been changed. Add the Cortex XSOAR 8 IP addresses to your firewall allow list during the UAT phase or immediately after the migration is complete. If you are not using the migration wizard, add the addresses to your firewall list before transitioning to Cortex XSOAR 8. You must also create new API keys and SSO connections for Cortex XSOAR 8.

</details>

<details>

<summary>What are the new IPs and URLs we need to whitelist? When should we add them to the Allow list?</summary>

We recommend adding the new IPs and URLs to the allow list ASAP, even before the migration. For a list of the new IP addresses, see [Enable access to Palo Alto Networks resources](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).

</details>

### Switchover date

<details>

<summary>Can you select your initial sync and switchover dates?</summary>

Yes, you start your UAT and select your switchover date. You can also cancel the switchover date and start again if necessary. For more information, see [Migrate from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS using the pre-migration and migration wizard](/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migrate-from-cortex-xsoar-6-to-cortex-xsoar-8-saas-using-the-pre-migration-and-migration-wizard.md).

</details>

<details>

<summary>Can you select different switchover dates for Dev/Prod tenants?</summary>

Yes, you can select different switchover dates for Dev/Prod tenants.

</details>

<details>

<summary>How long is the downtime during the switchover date?</summary>

If you decide to resync data, usually the switchover takes a few hours, but it depends on the complexity of your deployment and the volume of data created on Cortex XSOAR 6 during the UAT phase, which depends in part on how long the UAT period was. You can assume that a longer UAT phase will cause longer downtime during the switchover. In extreme cases, the switchover might take up to twelve hours.

</details>

<details>

<summary>I need to change the switchover date urgently, but the system doesn't allow me to change the date. What can I do?</summary>

The switchover date change is allowed up to 48 hours before the scheduled switchover because we start the switchover preparation in advance. If you have an emergency that requires a change, contact customer support to file an urgent request for a date change.

</details>

<details>

<summary>I didn't complete the switchover within the allotted time. What can I do?</summary>

If you exceed the time limit, you can no longer set a switchover date on the Cortex XSOAR 8 tenant. To reset the switchover date, you must open a support ticket in the Customer Support Portal (CSP).

</details>

<details>

<summary>I need to use Cortex XSOAR 6 after the switchover date. What can I do?</summary>

After the switchover date, although you can still access your Cortex XSOAR 6 instance after migration until EoL or the end of your contract term (whichever comes first), you can't perform automation, such as playbooks, CLI automations, and field-triggered scripts on Cortex XSOAR 6. If you need to perform automation, contact Customer Support.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-migration/migration-faqs-xsoar-6-on-prem-to-xsoar-8-saas.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
