Skip to main content

June 18, 2026

Step 3: Compare Directory Data

After configuring user provisioning and identity federation with your cloud identity provider and syncing users and groups to Identity Service, the next step in the migration process is to compare the new Identity Service directory with your existing Workspace ONE UEM directory (and Omnissa Access directory, if applicable) by running a report. The goal is to identify and fix any critical differences between users, groups, memberships, and attributes before you switch over to the Identity Service directory.

Running a report does not affect end users, who can continue to log in and access their applications.

If you are migrating an Omnissa Access directory along with your Workspace ONE UEM directory, separate reports are generated for each.

Typically, you will run the report a few times to identify problems in the identity provider user attribute mapping until you get results that meet the threshold for migration and that are acceptable to you. The predetermined threshold prevents migration when there are a large number of differences between the new Omnissa Identity Service directory and the Workspace ONE UEM and Omnissa Access directories. These differences can affect your end users' ability to log in and access their applications. You cannot proceed with the migration until the threshold is met.

Follow these guidelines:

  • Before changing attribute mappings, review Critical Considerations. Also, see information about specific attributes in About the Directory Comparison Report.

  • If you update user attribute mappings in your identity provider, restart provisioning. After provisioning is complete, you can run the report again. You should be able to check the provisioning status in the identity provider. For example, Entra ID displays 100% Complete when provisioning is complete.

  • If you want to update the common identifier (used to match users between Identity Service and your existing Workspace ONE UEM and Omnissa Access directories), you must restart the entire migration process. Delete the Identity Service directory and restart migration.

  • If you are migrating an Omnissa Access directory and you update any attributes during the migration process, be aware that you will need to update the attributes in any SAML or WS-Fed applications or SCIM connectors in Omnissa Access that use those attributes.

Note: It can take some time for the report to be generated, especially for large directories. Click the refresh icon to see the progress.

Procedure

  1. In the Omnissa Connect console, select Identity Management > End User Management from the left pane.

  2. Click Launch End User Management.

    Omnissa Identity Service opens in a new tab in the browser.

  3. In the Omnissa Identity Service tab, in the Configuration Steps pane on the right, click Start in the Compare Directory Data step.

    "Compare Directory Data step"

  4. Review the information, then click Run Report.

    Note: It can take some time for the report to be generated, especially for large directories. Click the refresh icon to see the progress.

    "Run Report"

  5. Review the report.

    The page displays the overall status, a high-level comparison of the directories, and sections summarizing the differences in users, groups, and group memberships. To view details, download the comparison file in each section. See About the Directory Comparison Report and About the CSV file for more information.

    Reports for Workspace ONE UEM and Omnissa Access directories are displayed in separate tabs.

    Important: If the overall status is Not ready to migrate, you cannot proceed with migration. You must make changes to your directory, run the report again, and get a status of Ready to migrate before you can proceed.

  6. Analyze the differences and fix the issues in your directory configuration.

    You must fix all the issues that appear as errors on the report. The report download is available for 28 days.

  7. After the changes are provisioned to Identity Service, click Run New Report to run the report again.

    Note: When you run a new report, the previous report is deleted. Download the existing report if you want to save it before running a new report.

    You can run reports for Workspace ONE UEM and Omnissa Access separately or together.

    When you run the report again, you can choose to remove non-critical user attributes from the directory comparison. Carefully evaluating and selecting the attributes to include in the report can reduce noise and help you focus on the important differences.

    To remove non-critical user attributes, deselect them in the Run New Report pop-up window.

    Only the attributes that were flagged as different in the previous reports are listed. You cannot deselect any of the critical attributes. Critical attributes are attributes that must match between Identity Service and Workspace ONE UEM or Omnissa Access and remain unchanged.

    For example:

    "Run Report"

  8. Keep refining your directory configuration based on the reports until you are satisfied with the results and the report displays a Ready to migrate status.

  9. When you are ready to migrate, click Proceed to Migration.

About the Directory Comparison Report

Overall Status

Critical information that indicates whether you can migrate your directory. If the differences between the Identity Service directory and your existing directories are under the threshold, the status is Ready to migrate, otherwise it is Not ready to migrate. The threshold is predetermined and based on factors such as differences in critical attributes. You must get the differences under the threshold in order to proceed with migration.

For example:

"Overall Status section"

Directory Differences

Displays the differences in users, groups, and memberships between the Identity Service directory and your existing directory. The severity of the differences is indicated by error, warning, and information icons. If any errors exist, you cannot proceed with migration.

The differences for Workspace ONE UEM and Omnissa Access directories are displayed in separate tabs. Make sure you resolve the errors for both directories.

Users

Displays the differences in users. You can use the filters Users with Devices or Users without Devices to narrow the list. The differences are grouped into the following categories:

  • Users with Different Attributes: The total number of users that have at least one attribute value that is different between the Identity Service directory and the Workspace ONE UEM or Omnissa Access directory. The Attributes that differ list displays each attribute that is different and the number of users whose values don’t match for that attribute. Some attributes are considered critical and you must resolve the differences for those attributes.

    Caution:

    • Before you change any attribute mappings, review Critical Considerations.
    • Changing the username mapping will cause the following authentication methods to fail: RADIUS, RSA SecurID, and Kerberos. Additionally, the DUO Security authentication method will fail if Username is selected as the Username format setting in the authentication method configuration.
  • Missing Users: Users that are missing in the Identity Service directory but that exist in the Workspace ONE UEM or Omnissa Access directory. These users will not be managed by your identity provider and will not be able to log in after migration.

  • New Users: Users that exist in the Identity Service directory but do not exist in the Workspace ONE UEM or Omnissa Access directory.

To see the full user comparison data, click Download User Comparison and review the CSV file.

For example:

"Users section"

Groups

Displays the differences in groups. The differences are grouped into the following categories:

  • Groups with Different Attributes: The total number of groups that have at least one attribute value that is different between the Identity Service directory and the Workspace ONE UEM or Omnissa Access directory. The Attributes that differ list displays each attribute that is different and the number of groups whose values don’t match for that attribute. Some attributes are considered critical and you must resolve the differences for those attributes.

    Caution: Before you change any attribute mappings, review Critical Considerations.

  • Missing Groups: Groups that are missing in the Identity Service directory but that exist in the Workspace ONE UEM or Omnissa Access directory.

    Note: All the groups must be present in the Identity Service directory to comply with the migration requirements. If any groups are missing, you cannot proceed with migration.

  • New Groups: Groups that exist in the Identity Service directory but do not exist in the Workspace ONE UEM or Omnissa Access directory.

Note: Workspace ONE UEM groups that are provisioned from Omnissa Access using the AirWatch Provisioning app appear in the comparison report. Other Custom Workspace ONE UEM groups do not appear in the report.

To see the full group comparison data, click Download Group Comparison and review the CSV file.

For example:

"Groups section"

User Memberships

Displays the differences in memberships between the directories. The differences are grouped into the following categories:

  • Missing Memberships: Memberships that are missing in the Identity Service directory but that exist in the Workspace ONE UEM or Omnissa Access directory.

    Note: If a user or group is missing, then their memberships will not be shown as missing memberships.

  • New Memberships: Memberships that exist in the Identity Service directory for existing groups in Workspace ONE UEM or Omnissa Access but that do not exist in the Workspace ONE UEM or Omnissa Access directory.

To see the full user membership comparison data, click Download Membership Comparison and review the CSV file.

For example:

"User Memberships section"

About the CSV File

You can download a CSV file for each type of comparison: users, groups, and memberships. Only those users, groups, and memberships that have differences between the two directories are listed in the files. The CSV export file size limit is 10,000 lines.

Users CSV file

The users CSV file lists users that exist in one directory but are missing in the other, or that have at least one attribute value that is different between the directories.

Users are categorized as EXISTING, MISSING, and NEW. EXISTING denotes users that exist in both directories and that have at least one attribute value that is different between the two directories. MISSING denotes users that do not exist in Identity Service but do exist in UEM. NEW denotes users that exist in Identity Service but do not exist in Workspace ONE UEM or Omnissa Access.

The file includes the following user attributes and values:

  • For EXISTING users, the core set of identifying attributes and any attributes that are different
  • For NEW and MISSING users, all attributes

The UEM-attributeName or Access-attributeName column displays the user’s value in UEM or Access and the SCIM-attributeName column displays the user’s value in Identity Service. If the value is different, DIFF appears in the attributeName(Diff) column.

Groups CSV file

The groups CSV file is similar to the users CSV file.

Memberships CSV file

The memberships CSV file includes missing and new memberships information for groups and users that exist in both Identity Service and Workspace ONE UEM or Omnissa Access directories. The group information is obtained from Workspace ONE UEM or Omnissa Access and the user information is obtained from Omnissa Identity Service.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…