Migrate VA-based Source to a SaaS Source
Some sources that are connected to virtual appliance (VA) clusters can be migrated to SaaS connections. This ensures data (users and entitlements) remain intact and can maintains your source configurations like access profiles, roles, password settings, and correlation configurations when switching from a VA cluster to a SaaS connection. To migrate a source from a VA-based source to a SaaS source, you will provide configuration details on a draft version of the source before publishing the source.
Note
- You must have an Admin or Source Admin user level to migrate a source.
- SailPoint recommends “I AM ROLE” Auth Type on VA-based sources, as the AWS SaaS connector supports only Role Authentication.
A draft version of the source is created. As your migration process is in progress the live source will continue to work as it is. For more information, refer to the Amazon Web Services SaaS Supported Features topic.
Important Considerations Before Migrating:
-
You do not need to edit additional configurations (other than connection credentials) to migrate the source.
-
If your source migration is in progress, please do not make any configuration changes to your live source as those can be overwritten once you apply the migration your draft version.
-
Once you've gone ahead with your migration, it can't be rolled back. Your source is permanently migrated to a SaaS source.
-
Any preview operations or configuration changes on the draft source will not impact the live source until you apply the migration.
Migrating Sources
To migrate your source, complete the following:
-
Go to Admin > Connections > Sources.
-
Select or edit the VA-based source you want to migrate.
-
Open the source configuration, and select Migrate to SaaS.
-
When prompted, select Continue.
A draft version of the source is created. The live source will continue to work.
-
Select Connection Settings.
Note
On the Connection Settings page, configuration needs to be done as per AWS SaaS Connectors. -
Re-enter encrypted configuration details. For example, you might need to re-enter the Client Secret, Password, Refresh Token, Personal Access Token ( PAT ), or Certificates to migrate from the VA cluster to the SaaS connection.
Important
Avoid editing the other configuration options in the draft source. -
Select Review and Test.
-
Select Test Connection.
-
When you've finished reviewing your changes and successfully tested your connection, select Apply Migration.
Your changes will be applied to the live source and the draft source will be deleted.
Note
The user must re-enter the value in the AWS Account settings page on the live source.
Viewing Source Migration Status
You can view the status and creation date of draft sources.
-
Go to Admin > Connections > Sources > Source Migration Status.
-
Select Source Migration Status.
-
To view or edit the draft source, select Actions
> Preview on the draft source. -
To delete the draft source, select Actions
> Delete on the draft source.