> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard.md).

# Step 3. Run user acceptance tests (UAT) in a Multi-Tenant Deployment using the Migration Wizard

After you finish the data transfer in the pre-migration wizard for each tenant, you will receive an email confirming the completion of the initial data sync.

In each Cortex XSOAR 8 tenant, the migration wizard starts and enables you to verify that all of your data and content are synced and that your integrations work correctly. You can skip the migration steps within the wizard, set the switchover date, and proceed with migration, but we strongly recommend that you follow the wizard to avoid any issues.

{% hint style="info" %}

### Note

* Account Admins and Instance administrators only have access to the Cortex XSOAR 8 tenant during the UAT stage.
* Playground data is not migrated.
* When logging into Cortex Gateway, if you see that a Cortex XSOAR tenant is available for activation, you should ignore this message. Cortex XSOAR tenant activation is undertaken using the migration process. Migration will take place at the scheduled switchover date and not in Cortex Gateway.
* During the UAT phase, all daily tasks are still performed in the Cortex XSOAR 6 instance. We recommend you limit changes in Cortex XSOAR 6 during the UAT phase, as some items are not resynced at the switchover date, such as creating and editing users and jobs. Users should not change their avatars; otherwise, their avatars may not be migrated.
  {% endhint %}

When using the wizard, you can go back and forth between steps to complete them at your convenience.

During the UAT phase, you must add the Cortex XSOAR 8 IP addresses to your firewall allow list, if you haven't done so already.

**Migration steps**

Although you can start the migration wizard in each tenant in any order, you must complete the switchover in the following order:

1. Child tenant
2. Development tenant
3. Main tenant

{% hint style="info" %}

### Note

The migration wizard shows how many child tenants have migrated and how many are remaining. Until all tenants are migrated, you can't set the switchover date for the main and development tenants.
{% endhint %}

During this UAT stage, test and configure content in each of the following tenants:

{% tabs %}
{% tab title="Child tenant" %}
You have up to 60 days from the date of the initial data sync to complete the switchover. We recommend minimizing the User Acceptance Testing (UAT) period to the shortest necessary duration to reduce downtime during the switchover phase.

We strongly advise keeping the UAT period within 30 days, as there may be extended downtime on the switchover day due to the amount of data transferred.

| Task                                 | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | See More                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User, user groups, and roles         | Review and update users, user groups, and roles. Local users with a defined email address are migrated and are designated the PANW IDP user type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/users-user-groups-and-roles-multi-tenant.md)                |
| Security and Authentication Settings | During the UAT phase, you must configure the SSO settings using the new Cortex XSOAR 8 URLs. When you first log in to the UAT, you can't use SSO. After logging into the UAT, SSO can be enabled to allow future SSO logins.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/security-and-authentication-multi-tenant.md)                |
| Incidents and indicators             | If you selected migrate incident and indicator data, review the incidents and indicators, including layouts, fields, and investigation data. All active incidents copied to Cortex XSOAR 8 have been paused.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/incidents-and-indicators-multi-tenant.md)                   |
| Jobs                                 | Although jobs are disabled, you should temporarily enable selected jobs for testing, but when complete, disable them to avoid conflicts with Cortex XSOAR 6.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/jobs-multi-tenant.md)                                       |
| Engines                              | Engines should be upgraded and reconfigured to work with the new IP addresses of Cortex XSOAR 8.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/engines-multi-tenant.md)                                    |
| Integration instances                | <p>Test your integrations to verify connectivity and that mail configurations are working properly.</p><p>To avoid conflicts during the migration period, integration instances that send emails and any long-running instances are temporarily disabled in the Cortex XSOAR 8 instance. For these disabled integrations, for testing purposes, enable them temporarily and disable them after testing is complete. Alternatively, you can use the <strong>Test</strong> button to verify connectivity.</p><p>All other integrations enabled in the Cortex XSOAR 6 instance are enabled, but fetching is disabled. Mirroring settings of the integration are ignored, and the mirroring capability is turned off during the migration</p> | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/integration-instance-configuration-changes-multi-tenant.md) |
| Syslog                               | The schema for Syslog events in Cortex XSOAR 8 does not support some fields from Cortex XSOAR 6. If you have customized your Syslog or a system that reads data from your Syslog, you may need to update your customization to match the new schema.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/syslog-configuration-multi-tenant.md)                       |
| API Keys                             | You need to set up API keys for Cortex XSOAR 8 and reconfigure third-party services that use them.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/api-keys-in-cortex-xsoar-8-multi-tenant.md)                 |
| {% endtab %}                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                             |

{% tab title="Development tenant" %}
You have up to 90 days from the date of the initial data sync to complete the switchover. We recommend minimizing the User Acceptance Testing (UAT) period to the shortest necessary duration to reduce downtime during the switchover phase.

We strongly advise keeping the UAT period within 30 days, as there may be extended downtime on the switchover day due to the amount of data transferred.

| Task                                 | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | See More                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User, user groups, and roles         | Review and update users, user groups, and roles. Local users with a defined email address are migrated and are designated the PANW IDP user type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/users-user-groups-and-roles-multi-tenant.md)                |
| Security and Authentication Settings | During the UAT phase, you must configure the SSO settings using the new Cortex XSOAR 8 URLs. When you first log in to the UAT, you can't use SSO. After logging into the UAT, SSO can be enabled to allow future SSO logins.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/security-and-authentication-multi-tenant.md)                |
| Incidents and indicators             | If you selected migrate incident and indicator data, review the incidents and indicators, including layouts, fields, and investigation data. All active incidents copied to Cortex XSOAR 8 have been paused.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/incidents-and-indicators-multi-tenant.md)                   |
| Jobs                                 | Although jobs are disabled, you should temporarily enable selected jobs for testing, but when complete, disable them to avoid conflicts with Cortex XSOAR 6.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/jobs-multi-tenant.md)                                       |
| Engines                              | Engines should be upgraded and reconfigured to work with the new IP addresses of Cortex XSOAR 8.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/engines-multi-tenant.md)                                    |
| Remote repositories                  | <p>Test your tenant so you can push content.</p><p>If you use multiple Git branches in Cortex XSOAR 6, you must update your merge processes to use the new branches created for Cortex XSOAR.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/remote-repositories-multi-tenant.md)                        |
| Integration instances                | <p>Test your integrations to verify connectivity and that mail configurations are working properly.</p><p>To avoid conflicts during the migration period, integration instances that send emails and any long-running instances are temporarily disabled in the Cortex XSOAR 8 instance. For these disabled integrations, for testing purposes, enable them temporarily and disable them after testing is complete. Alternatively, you can use the <strong>Test</strong> button to verify connectivity.</p><p>All other integrations enabled in the Cortex XSOAR 6 instance are enabled, but fetching is disabled. Mirroring settings of the integration are ignored, and the mirroring capability is turned off during the migration</p> | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/integration-instance-configuration-changes-multi-tenant.md) |
| Syslog                               | The schema for Syslog events in Cortex XSOAR 8 does not support some fields from Cortex XSOAR 6. If you have customized your Syslog or a system that reads data from your Syslog, you may need to update your customization to match the new schema.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/syslog-configuration-multi-tenant.md)                       |
| API Keys                             | You need to set up API keys for Cortex XSOAR 8 and reconfigure third-party services that use them.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/api-keys-in-cortex-xsoar-8-multi-tenant.md)                 |
| {% endtab %}                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                             |

{% tab title="Main tenant" %}
You have up to 90 days from the date of the initial data sync to complete the switchover. We recommend minimizing the User Acceptance Testing (UAT) period to the shortest necessary duration to reduce downtime during the switchover phase.

We strongly advise keeping the UAT period within 30 days, as there may be extended downtime on the switchover day due to the amount of data transferred.

| Task                                 | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | See More                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User, user groups, and roles         | <p>Review and update users, user groups, and roles. Local users with a defined email address are migrated and are designated the PANW IDP user type.</p><p>All roles that were created in the main tenant will be migrated to Cortex Gateway, so they can be propagated to all of your child tenants.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                 | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/users-user-groups-and-roles-multi-tenant.md)                |
| Security and Authentication Settings | During the UAT phase, you must configure the SSO settings using the new Cortex XSOAR 8 URLs. When you first log in to the UAT, you can't use SSO. After logging into the UAT, SSO can be enabled to allow future SSO logins.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/security-and-authentication-multi-tenant.md)                |
| Engines                              | Engines should be upgraded and reconfigured to work with the new IP addresses of Cortex XSOAR 8.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/engines-multi-tenant.md)                                    |
| Remote repositories                  | <p>Test your production tenant so it can pull content.</p><p>If you use multiple Git branches in Cortex XSOAR 6, you must update your merge processes to use the new branches created for Cortex XSOAR.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/remote-repositories-multi-tenant.md)                        |
| Integration instances                | <p>Test your integrations to verify connectivity and that mail configurations are working properly.</p><p>To avoid conflicts during the migration period, integration instances that send emails and any long-running instances are temporarily disabled in the Cortex XSOAR 8 instance. For these disabled integrations, for testing purposes, enable them temporarily and disable them after testing is complete. Alternatively, you can use the <strong>Test</strong> button to verify connectivity.</p><p>All other integrations enabled in the Cortex XSOAR 6 instance are enabled, but fetching is disabled. Mirroring settings of the integration are ignored, and the mirroring capability is turned off during the migration</p> | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/integration-instance-configuration-changes-multi-tenant.md) |
| Syslog                               | The schema for Syslog events in Cortex XSOAR 8 does not support some fields from Cortex XSOAR 6. If you have customized your Syslog or a system that reads data from your Syslog, you may need to update your customization to match the new schema.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/syslog-configuration-multi-tenant.md)                       |
| API Keys                             | You need to set up API keys for Cortex XSOAR 8 and reconfigure third-party services that use them.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | [See more](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard/api-keys-in-cortex-xsoar-8-multi-tenant.md)                 |
| {% endtab %}                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                             |
| {% endtabs %}                        |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                             |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz/step-3.-run-user-acceptance-tests-uat-in-a-multi-tenant-deployment-using-the-migration-wizard.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
