On-Premises to Cloud Migration
Half-migrated is the normal state. The console is in the cloud, and UAG, the connectors and the old identity bridge are still running in a rack because nobody scoped the last mile.
The challenges you're facing
The components nobody scoped
Workspace ONE deployments in particular leave a tail: UAG for tunnelling and per-app VPN, ACC or AirWatch Cloud Connector for directory sync, SEG for mail, and vIDM for identity. Each has a different cloud path and some have none.
Impact: A cloud migration that is declared done while the hard dependencies still run on-premises
Identity is the real blocker
Directory sync, certificate issuance and conditional access usually run through the on-premises bridge. Moving the console is easy; moving what authenticates against it is the project.
Impact: Migrations that stall at 80 percent and stay there for a year
Apple is the untested half
The Windows estate gets tested because someone owns it. The Macs and iPhones inherit whatever survives, and nobody checks whether enrolment, escrow or app deployment still work after the cutover.
Impact: An Apple fleet that reports compliant against policies that were never re-validated
Name every on-premises dependency, then retire it deliberately.
We inventory what is still on-premises, decide per component whether it moves, is replaced by a cloud service, or is retired, and sequence the cutover so identity moves before the things that depend on it. The Apple side is validated rather than assumed.
- ✓
A component-by-component inventory: UAG, ACC, SEG, vIDM and whatever else is running
- ✓
A decision per component: migrate, replace or retire, with the reason written down
- ✓
Identity sequenced first, because everything else authenticates through it
- ✓
Apple enrolment, encryption escrow and app delivery re-validated after cutover
- ✓
The on-premises footprint actually decommissioned, not left running quietly
Stuck halfway to cloud?
One hour to establish what is genuinely still on-premises.