> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migration-faqs-xsoar-6-multi-tenant-to-xsoar-8-saas-multi-tenant.md).

# Migration FAQs - XSOAR 6 Multi-Tenant to XSOAR 8 SaaS Multi-Tenant

The following sections describe the frequently asked questions when migrating from Cortex XSOAR 6 multi-tenant to Cortex XSOAR 8 SaaS multi-tenant.

* [General](#general)
* [Users and roles](#users-and-roles)
* [UAT phase - Migration wizard](#uat-phase---migration-wizard)
* [Dev/Prod - Migration wizard](#devprod---migration-wizard)
* [IP address changes](#ip-address-changes)
* [Switchover date](#switchover-date)

### General

<details>

<summary>What are the options for Cortex XSOAR 8?</summary>

Cortex XSOAR 8 is available as both a Cloud-based and On-prem solution.

</details>

<details>

<summary>Who is the Cortex XSOAR 6 On-prem to SaaS migration available for?</summary>

The Cortex XSOAR 6 On-prem multi-tenant/MSSP to Cortex XSOAR 8 SaaS multi-tenant/MSSP migration is available for all multi-tenant/MSSP customers, including FedRAMP Moderate.

</details>

<details>

<summary>I am currently using Cortex XSOAR 6 On-prem multi-tenant/MSSP. What are my migration options?</summary>

**XSOAR 8 SaaS Multi-Tenant**

| Migration Option                                           | Availability | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ---------------------------------------------------------- | ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Self-service migration to Cortex XSOAR 8 SaaS multi-tenant | Now          | <p>A self-service migration option is available now. This option does not include the migration of indicator or incident data.</p><p>We recommend going through this process with your assigned Customer Success Representative and Sales Representative to assist in migrating your content, such as automations, playbooks, etc.</p><p>See <a href="/spaces/nPfgrPjdRQBvgLTOrM8C/pages/kb7zxcR3ciubPWSFERMi">Migrate from Cortex XSOAR 6 to Cortex XSOAR 8 SaaS (Self-Service)</a>.</p> |
| Start fresh with Cortex XSOAR 8 SaaS multi-tenant          | Now          | Activate a new Cortex XSOAR 8 main and child tenant without migrating content or data.                                                                                                                                                                                                                                                                                                                                                                                                    |
| Migration wizard to Cortex XSOAR 8 SaaS multi-tenant       | Now          | Migration wizards will automate data migration to Cortex XSOAR 8 SaaS multi-tenant, including incidents and indicators. To use the migration wizards, you must first upgrade to Cortex XSOAR 6.14 and above.                                                                                                                                                                                                                                                                              |

</details>

<details>

<summary>I currently have a child tenant (part of MSSP), and I want to move to an Enterprise (standalone) tenant. What are my options?</summary>

This is not supported. We support migration from Cortex XSOAR 6 Enterprise to Cortex XSOAR 8 SaaS Enterprise and Cortex XSOAR 6 Multi-tenant to Cortex XSOAR 8 SaaS Multi-tenant. For other options, you need to create a new Cortex XSOAR 8 tenant.

</details>

<details>

<summary>Do I need to update Cortex XSOAR 6 Multi-Tenant before migration?</summary>

If you want to use the migration wizard, upgrade all Cortex XSOAR 6 servers to 6.14 and above.

</details>

<details>

<summary>In which region will my Cortex XSOAR 8 tenants be created?</summary>

Cortex XSOAR 8 is deployed on GCP Cloud. When you create your Cortex XSOAR 8 tenant, you select a geographical region where the tenant will reside. For information about regions, see [Supported Regions](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/supported-host-regions.md).

</details>

<details>

<summary>Who can initiate the migration?</summary>

You can activate your tenants (main, child, and development) using the CSP Account Admin (Super User). If you can't see your tenant for activation in Cortex Gateway, check for your entitled account using your serial number in the [Admin Site](https://adminsite.paloaltonetworks.com/EntitlementsSearch).

</details>

<details>

<summary>Do I need to redeploy engines as a part of the migration to Cortex XSOAR 8?</summary>

Yes. If you are using the migration wizard, engines will work with both Cortex XSOAR 6 and Cortex XSOAR 8 during the UAT phase. After the switchover, Cortex XSOAR 6 engines will not work with Cortex XSOAR 8. Engines should be upgraded, and IP addresses should be updated during the UAT phase.

</details>

<details>

<summary>Are API keys migrated?</summary>

No. The Cortex XSOAR 8 URL is different from the Cortex XSOAR 6 URL. Users have to use a new URL to access the new system. Other components, such as SSO integrations or API keys, that rely on the legacy URL, will not work and must be reconfigured.

In Cortex XSOAR 6, API keys created in the main tenant are propagated to all child tenants. In Cortex XSOAR 8, there is no propagation of API keys, and you must create new API keys in each tenant.

If you are using the migration wizard, you should complete the configuration steps during the UAT phase.

</details>

<details>

<summary>Do I need to do anything with my SSO?</summary>

If you are using local users, all users will be migrated.

SSO configuration is not migrated. SSO settings depend on the URL, which will change when you move to Cortex XSOAR 8 SaaS. The SSO settings should be reconfigured during the UAT phase in each tenant.

</details>

<details>

<summary>We have a lot of data (incidents and indicators) in Cortex XSOAR 6. Is everything migrated and kept forever?</summary>

The default retention period for incidents in Cortex XSOAR is 6 months for each tenant. After your renewal date, you will have a further 6-month retention period (default period), which can be extended by purchasing retention licenses. For more information about the retention policy, see [Retention Policy and Enforcement](/cortex-xsoar-8-saas/learn-about-cortex-xsoar/data-retention-policy.md).

Although indicators do not have a time limit, they will be limited per tenant as follows:

* XSOAR + TIM customers: Up to 100 million indicators
* XSOAR customers (no TIM license): Up to 3 million indicators

Indicator retention enforcement is planned for 2025.

</details>

<details>

<summary>Are Docker images migrated?</summary>

Docker images are migrated unless they are in an external registry, they start with `demisto/`, or the base image name contains a dot. Dots are allowed in the tag-name component after the `:`.

Images in the `localhost` registry will be migrated with the name trimmed.

Examples of Docker images that are migrated as-is:

* `custom-python:latest`
* `my-image:1.3`
* `custom/python:3.14`

Examples of Docker images with address trimmed:

* `localhost/my-image:1.3` to `my-image:1.3`
* `localhost/custom/my-image:1.3` to `custom/my-image:1.3`
* `localhost:5000/my-image:1.3` to `my-image:1.3`

Examples of Docker images that will not be migrated:

* `demisto/python:3.12801`
* `demisto/custom-image:latest`
* `demisto/custom-image:3.12801`
* `organization-registry.io:5000/my-image:1.3`
* `docker.github.io/my-image:1.3`
* `102.57.81.150:5000/custom/python:3.14`

</details>

### Users and roles

<details>

<summary>Which users are migrated from Cortex XSOAR 6 to Cortex XSOAR 8?</summary>

Only users with a unique email address in Cortex XSOAR 6 are migrated to Cortex XSOAR 8 with the migration wizard. E-mail addresses should be valid and unique (you cannot reuse the same email address).

</details>

<details>

<summary>Are custom roles migrated? Will users in Cortex XSOAR 8 receive the same permissions as in XSOAR 6?</summary>

Yes. If you are using the migration wizard, at the initial data sync stage, when the UAT phase begins, roles are migrated, including any custom roles from Cortex XSOAR 6. At the switchover date, users and roles are not resynced, so any roles created during the UAT phase in Cortex XSOAR 6 are not migrated.

Users have the same permissions, but roles are managed differently in Cortex XSOAR 8. Cortex XSOAR 8 includes user groups. For more information on how users and roles are managed in Cortex XSOAR 8, see [Set up users and roles](/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/users-and-roles-in-cortex-xsoar.md).

</details>

<details>

<summary>What happens to roles created on the Cortex XSOAR 6 main tenant?</summary>

All roles created on the main tenant are migrated to Cortex Gateway and propagated to ALL child tenants.

</details>

<details>

<summary>What happens to roles created on the child tenant?</summary>

Roles created on the child tenant on Cortex XSOAR 6 are migrated to the relevant child tenant on Cortex XSOAR 8.

</details>

<details>

<summary>Are the SSO users migrated to Cortex Gateway?</summary>

SSO users from Cortex XSOAR 6 are not migrated to Cortex Gateway. SSO must be set up separately for your main, child, and development tenants. There is no propagation of SSO from the main tenant to child tenants.

</details>

<details>

<summary>How do I migrate my local users on the main tenant to Cortex XSOAR 8?</summary>

Before you start the migration process, add the users with a valid email address to your CSP account. During the initial data sync (at the end of the pre-migration stage), the users are mapped from Cortex XSOAR 6 to the CSP using the email address you added for each user.

</details>

<details>

<summary>How are users migrated to child tenants?</summary>

Users can only access the Cortex XSOAR child tenant using SSO. SSO must be set up separately on your child tenants. There is no propagation of SSO from the main tenant to child tenants.

</details>

### UAT phase - Migration wizard

<details>

<summary>Who can access the environment during the UAT phase?</summary>

Only Instance Administrators and Account Admins can access the Cortex XSOAR 8 tenants during the UAT phase. In the migration form, before the migration starts, you can specify which users can access the UAT. Those users must exist in Cortex XSOAR 6 with an email address; otherwise, they will not be migrated to Cortex XSOAR 8. If that occurs, you will need to create a new user for that user in the CSP.

{% hint style="info" %}

### Tip

We recommend you verify that all required users exist in Cortex XSOAR 6 before the initial data sync.
{% endhint %}

</details>

<details>

<summary>Are instance credentials transferred as part of the data sync?</summary>

Yes, they are transferred, but only once during the initial sync. As credentials are not resynced during the switchover date, we recommend refraining from changing the credentials during the UAT phase. If you make changes after the initial sync, they should be done manually in both Cortex XSOAR 6 and Cortex XSOAR 8.

</details>

<details>

<summary>How long does the UAT phase take?</summary>

It depends on the number of use cases that you have. It should not take more than a few days for a person dedicated to this task in an average deployment.

</details>

<details>

<summary>What is the recommended timeframe for the UAT phase?</summary>

We recommend keeping the UAT phase as short as possible to reduce the number of changes made on Cortex XSOAR 6, as data needs to be resynced to Cortex XSOAR 8 at the switchover date, which will impact the service downtime length (up to 12 hours of downtime during the switchover). By default, the switchover date is pre-scheduled for a month after the migration starts. If you complete the UAT phase earlier, we recommend changing the switchover date to the earliest possible date.

</details>

<details>

<summary>Is there downtime for Cortex XSOAR 6 during the initial sync?</summary>

There is no downtime during the data transfer (initial sync). Your Cortex XSOAR 6 environments must be running 6.14 and above.

</details>

### Dev/Prod - Migration wizard

<details>

<summary>Is the Development to Production 'Excluded Changes' list on our Cortex XSOAR 6 Dev instance migrated to Cortex XSOAR 8?</summary>

Yes, they are migrated.

</details>

<details>

<summary>Can I migrate my development tenant separately from my production tenant using the remote repository feature?</summary>

During the UAT phase, the migration steps for development and production machines are performed separately, and the switchover date for development and production machines does not need to be set simultaneously. We recommend migrating the development tenant before migrating the production tenant.

</details>

<details>

<summary>We are using a private content repository. Can we continue to use it in Cortex XSOAR 8?</summary>

Yes. In the pre-migration wizard, specify you are using a private content repository.

</details>

<details>

<summary>Should we use our GitHub repository or move to the built-in repository? What are the pros and cons?</summary>

For a simple one-branch deployment, we recommend using a built-in repository. If you would like to use multiple branches or if you need access to the content repository outside the Cortex XSOAR platform (for example, to implement scanners), you must use a private repository.

</details>

### IP address changes

<details>

<summary>Are IPs and URLs changed during the migration? What do we need to do?</summary>

Yes, both IPs and URLs are changed. Add the Cortex XSOAR 8 IP addresses to your firewall allow list during the UAT phase or immediately after the migration completes. If you are not using the migration wizard, add the addresses to your firewall list before transitioning to Cortex XSOAR 8. New API keys and new SSO connections must also be created for Cortex XSOAR 8.

</details>

<details>

<summary>What are the new IPs and URLs we need to whitelist? When should we add them to the Allow list?</summary>

We recommend adding the new IPs and URLs to the allow list ASAP, even before the migration. For a list of the new IP addresses, see [Supported host regions](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/supported-host-regions.md).

The URLs are listed in [Enable Access to Cortex-XSOAR](/cortex-xsoar-8-saas/onboard-cortex-xsoar/deployment-steps/step-1-activate-cortex-xsoar/enable-access-to-palo-alto-networks-resources.md).

</details>

### Switchover date

<details>

<summary>Can you select your initial sync and switchover dates?</summary>

Yes, you start your UAT and select your switchover date. You can also cancel the switchover date and start again if necessary. For more information, see [Migrate from Cortex XSOAR 6 Multi-Tenant to Cortex XSOAR 8 Multi-Tenant using the migration wizard](/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migrate-from-cortex-xsoar-6-multi-tenant-to-cortex-xsoar-8-saas-multi-tenant-using-the-migration-wiz.md).

</details>

<details>

<summary>Can you select different switchover dates for Dev/Prod/Child tenants?</summary>

Yes, but you must first select and complete the child tenant switchover.

</details>

<details>

<summary>How long is the downtime during the switchover date?</summary>

If you dedcide to resync data, usually, the switchover takes a few hours, but it depends on the complexity of your deployment and the volume of data created on Cortex XSOAR 6 during the UAT phase, which depends in part on how long the UAT period was. You can assume a longer UAT phase will cause longer downtime during the switchover. In extreme cases, the switchover might take up to twelve hours.

</details>

<details>

<summary>I need an urgent change of the switchover date, but the system doesn't allow me to change the date. What can I do?</summary>

The switchover date change is allowed up to 48 hours before the scheduled switchover because we start the switchover preparation in advance. If you have an emergency that requires a change, contact customer support to file an urgent request for a date change.

</details>

<details>

<summary>I didn't complete the switchover within the allotted time. What can I do?</summary>

If you exceed the time limit, you can no longer set a switchover date on the Cortex XSOAR 8 tenant. To reset the switchover date, you must open a support ticket in the Customer Support Portal (CSP).

</details>

<details>

<summary>I need to use Cortex XSOAR 6 after the switchover date. What can I do?</summary>

After the switchover date, although you can still access your Cortex XSOAR 6 instance after migration until EoL or the end of your contract term (whichever comes first), you can't perform automation, such as playbooks, CLI automations, and field-triggered scripts on Cortex XSOAR 6. If you need to perform automation, contact Customer Support.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-migration-guide/cortex-xsoar-8-saas-multi-tenant-migration/migration-faqs-xsoar-6-multi-tenant-to-xsoar-8-saas-multi-tenant.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
