Back to marketplace catalog
PAM To Privilege Cloud Migration Tool
By: Idira
Use case Administrative Tools
Category Idira platform & extensions
Certification Certified
Version 9.4.5
Released Jul 9, 2026
Last updated Aug 11, 2026

Overview

NOTE: At this time, the migration tool is strictly reserved for use by Idira internal teams as part of the official Idira PAM SaaS migration process. Please be advised that Idira will not provide any technical support, troubleshooting, or assistance for migrations attempted without the direct involvement of our internal teams.


The Migration Tool exports a replicated copy of your Vault DB data (database and files) directly from your hosted site to Idira's Privilege Cloud SaaS platform. Idira's Customer Services import your data to a dedicated tenant and create a fully functional Privilege Cloud solution with identical data, assuring a smooth transition to the new cloud environment. Throughout the migration process, your data is secured against any unapproved access by an additional encryption layer, using ad hoc keys that assure the data is secured at all stages of the migration.


Version 9.4.5
Current

Published Jul 9, 2026

  • Features:
  • 1. Support migration from PAM-on-Cloud (AWS and Azure)
  • 2. Added support of Self-Hosted version 15.0
  • Improvements:
  • 1. Step 3/6 - New prompt for directory mapping related to Remote Access (AKA Alero)
  • 2. Step 7 - new prompt for amount of audit logs to migrate
  • 3. Support long directory names of up to 160 characters
  • 4. Support spaces in the directory structure (eg. "Program Files")
  • 5. Support Self Hosted PVWA version 12.1 and above in step 3
  • Bug Fixes:
  • 1. Remove writing temp passwords to files
  • 2. Reduced number of licenses needed for internal accounts

Previous versions

Version 9.3.5

Published Apr 28, 2026

  • - Add SRS Offboard in step 1.
  • - New Export process restoring method.
  • - Support for vaults using HSM.
  • - Support self-hosted vault version 14.6.4 patch.
  • - Changed default extra EPV users in license check from 3 to 1.
  • - Step 3 now ignores users in alero domains.
  • - Step 8/10 - display the Users and Groups csv report.
  • Bug Fixes:
  • - Fix size calculation in step 6 sanity check
  • - Improve 7zip error handling.
Version 9.2.8

Published Feb 23, 2026

  • Identity Administration readiness (step 3) bug fixes.
Version 9.2.7

Published Feb 4, 2026

  • - Support external Directory Service for authentication in SaaS (not internal LDAP/AD)
  • - Support hosted vault versions 14.4 and 14.6
  • - New Corrupted Secrets Report to avoid failures in import
Version 9.1.2

Published Dec 17, 2025

  • - Support migration of distributed vaults, see documentation
  • - Refresh token is done silently when the customer is using MFA, without any user intervention
  • - Removed redundant reports
  • - New order of steps menu
Version 9.0.6

Published Oct 5, 2025

  • 1. Fix bug when reading from ini file if the subdomain begins with a digit
  • 2. Ignore usage of quotes mark in config properties that point to file or path
  • 3. Refresh session token for long uploads
  • 4. Fix issue with handling DR and Backup users in rare cases
Version 9.0.5

Published Sep 3, 2025

  • Features:
  • 1. Added step 0 for initializing migration and creating readiness file
  • 2. Remove requirement for running 'Create Upload Links' by CyberArk services (now done automatically in steps 5,6)
  • 3. Enable optional uploading files through internet proxy - use new configs.ini option PROXY_URL
  • Proxy usage supports optional protection by user/password
  • 4. Access from Upload machine now requires internet access only to domain *.cyberark.cloud
  • Improvements:
  • 1. Export of PSM recordings performance and minor bug fixes
  • 2. Notify about accounts for which the platform does not exist
  • 3. Retry upload if errors occur
  • 4. Performance improvements for exporting many safes in steps 3,4
  • Bug Fixes:
  • 1. Fix issue with keys packaging
  • 2. Fix issue in prerequisite check (step 2) for safes without sharing options
Version 8.6.1

Published Jun 16, 2025

  • Features:
  • 1. Add validation for Gateway groups
  • 2. Support PSMP - allow psm recordings safe to not require .avi files
  • Improvements:
  • 1. Support special characters in admin password
  • 2. Clarify the padr error_action message
  • 3. Allow the CSK to complete successfully even if some files have failed
  • Bug Fixes:
  • 1. Handle damaged files in PSM recordings safe
  • 2. Add support for handling multiple safes coming from two locations
  • 3. Addressed a conflict caused by temp folder path
  • 4. Block in case of nested folders are found in PSM recordings safes
Version 8.5.4

Published Apr 29, 2025

  • Features:
  • 1. Delete PSMP_ADB users during import phase. Warn of this in pre-export tests (step 2).
  • 2. Allow internal users with external authentication to be migrated (will be handled as regular internal users).
  • 3. Enable configuration of amount of PSM recordings to migrate by size or number of recent months. Default: 2TB
  • Improvements:
  • 1. Reduce time required to export and import a large number of accounts. Tested with 500K accounts.
  • Bug Fixes:
  • 1. External user names with comma failed identity connector validations
  • 2. Space characters in safe names wrongly reported as invalid characters
Version 8.3.2

Published Feb 20, 2025

  • Features:
  • - Automatically changes unknown user types to EPVUser
  • - Support migration of older account versions and deleted accounts (by configuration)
  • - Support LATAM special characters in user names
  • - Identify and ignore corrupted platforms
  • - Identity Connector health check
  • Improvements:
  • - Improve performance of upload
  • - Improve performance of PSM recordings packaging
  • Bug Fixes:
  • - Fix users and groups validations for SID-less cases
Version 8.3.1

Published Feb 13, 2025

  • Features:
  • 1. Automatically changes unknown user types to EPVUser
  • 2. Support migration of older account versions and deleted accounts (by configuration)
  • 3. Support LATAM special characters in user names
  • 4. Identify and ignore corrupted platforms
  • 5. Identity Connector health check
  • Improvements:
  • 1. Improve performance of upload
  • 2. Improve performance of PSM recordings packaging
  • Bug Fixes:
  • 1. Fix users and groups validations for SID-less cases
Version 8.2.1

Published Nov 24, 2024

  • Features:
  • 1. Added support for self-hosted vault version 14.0-14.2
  • 2. Automatically handle LDAP Queries that map a user to one group only. Export prerequisite tests will still warn about other queries that should be handled manually.
  • 3. Support migrations in region eu-south-1 (Milan)
  • Improvements:
  • 1. Performance improvements of PSM export time.
  • 2. Enable PSM Hash mechanism to be controlled by config parameter "DO_PSM_HASH", defaults to false to reduce time of psm export.
  • 3. Warn of safes with name containing forbidden characters. In Privilege Cloud forbidden characters are: \ / : * < > . | ? " % & +
  • 4. Improve handling of extra users assigned to DR and Backup groups.
  • Bug Fixes:
  • 1. Correctly handle database export when there is some structural variability.
  • 2. Fixes for users provisioning to identity.
Version 8.0.1

Published Sep 5, 2024

  • Features:
  • 1. Adding Hash mechanism that will be taken for all the zipped data and checked in the security machine on import side to double prof the data is ok
  • 2. Report the Size of all data to enable us to create all disks on the import side accordingly
  • 3. Support tenants version 14.3 - moving the data to tenants with SQL 8
  • Improvements:
  • 1. New 'critical feature list' mechanism to better control compatibility of Export and Import versions
  • 2. Clean up network areas tables that have been deprecated.
  • Bugfixes:
  • 1. Fix bug of migration of special characters specifically in audit logs
  • 2. Fix bug when migrating without PSM in case import should be re-run after a run with PSM
  • 3. Fix bug of reading TSparm when vault is installed and safes are placed in other disk than C: and running Include PSM Recordings
Version 7.4.1

Published Jul 3, 2024

  • Features:
  • 1. Notify user when tool version is not latest
  • 2. Support tenants 14.2 without detailed log tables
  • Improvements:
  • 1. Clarified the Identity login message
  • 2. Support windows 2022 server
  • 3. Changed license comptability severity output
  • 4. Make option 5 validation logs more informative
  • 5. Improved validation error message on expired upload links
  • 6. Support special characters in user and group names
  • 7. Fixed csk output not to print skipped files that belong to psm safes
  • 8. Excluded psm recordings from csk
  • 9. Increased psm limitation in hosted side to 2TB
  • 10. Update minimal powershell version to 5.1
  • 11. Removed LDAPCertificateTool
  • 12. Updated common function submodule to print summary end with errors red
  • Bugfixes:
  • 1. Recopy entropy.rnd when there is more than one SafesDirectory
  • 2. Added -UseBasicParsing flag to groups search invoke method
  • 3. Fixed internal users with LDAP auth query
  • 4. Fixed bug in refreshing identity token
Version 7.2.2

Published Mar 14, 2024

  • General
  • 1. Ensure special characters are supported in user names during H2P migration
  • 2. make export log files names more informative
  • 3. Add CLP010S (csk v14 errors) to check_command_output errors list and use master common functions
Version 7.1.1

Published Dec 19, 2023

  • General
  • 1. Fix messages in messages.ini file.
  • 2. configs.ini - Add list of access levels to enhance PSMMaster group and PSMMaster safe report.
  • 3. Add RED messages to Summary section which contains the list of reports that needs to be looked at in the end of of pre-requsites steps.
  • 4. PSM Recording default support change to 500 GB and/or 6 Months. Whichever condition is fulfilled first.
  • Prerequisite Checks for Export
  • 1. Enhance PSMMaster group and PSMMaster safe report.
  • 2. Create report to notify Customer if there are shared safes which Gateway account is not PVWAGWAccounts group.
  • 3. Create report to notify Customer if there is usage of regular expression in Directory Mapping LDAP Group Match.
Version 6.4.1

Published Nov 6, 2023

Version 6.3.1

Published Oct 16, 2023

Version 6.2.7

Published Oct 11, 2023

Version 6.2.6

Published Oct 5, 2023

Version 6.1.3

Published Aug 16, 2023

Version 5.6.3

Published Aug 6, 2023

Version 5.5.4

Published Jul 26, 2023

Version 5.5.3

Published Jul 19, 2023

Version 5.2.12

Published May 31, 2023

Version 5.0.0

Published May 15, 2023

Version 4.5.3

Published May 4, 2023

Version 4.4.14

Published Apr 24, 2023

Version 4.4.13

Published Apr 24, 2023