---
title: "Migrate Security & Encryption Data Center to Security & Encryption Cloud"
canonical: "https://support.appfire.com/space/SECS/477858075/Migrate%20Security%20%26%20Encryption%20Data%20Center%20to%20Security%20%26%20Encryption%20Cloud"
format: markdown
---
> Macro (aura-html)


This page outlines the steps to migrate your Security & Encryption data from Confluence Data Center to Confluence Cloud. 

## Prework

<span style="color: #172b4d">Before you start, read and understand the following information:</span>

- Understand the [macro differences and feature differences](https://appfire.atlassian.net/wiki/spaces/SECS/pages/477858141/Security+and+Encryption+for+Confluence+Feature+Differences#Macro-Differences-Overview) between the Security and Encryption for Confluence Data Center and Confluence Cloud
- Be aware of the following limitations, and take the suggested actions if needed
  - Rich text content used to create secrets does not appear correctly when migrated. Ensure secrets are in plain text before migration
  - Restricted pages are not supported currently. Depending on the sensitivity of the data, we suggest users manually migrate these secrets or remove any restrictions on related pages
  - Confluence Cloud currently does not support nested macros (See [CONFCLOUD-68323](https://jira.atlassian.com/browse/CONFCLOUD-68323)), which means integration with other apps using nesting will be limited. We suggest moving the secrets outside of the nested macros in your hosted instance before performing the migration.

Administrators using the CCMA tool to allow partial user migration should review the product access of the users before attempting steps related to the **Server Migration **tab

> ℹ️ This is a part of [Step 2 - Secure Macro Transformation to Secrets (Security & Encryption](https://appfire.atlassian.net/wiki/spaces/SECS/pages/477858228))

It is recommended to perform a test migration to understand the steps required to migrate data and reconfigure the migrated data

> ℹ️ This guide assumes you have successfully migrated your Confluence Server data into Confluence Cloud, per Atlassian's [Server to Cloud migration guide](https://www.atlassian.com/migration/cloud/guide/introduction/overview).

## Guide

At the end of this guide, you will have

- Upgraded [Security and Encryption for Confluence Data Center](https://appfire.atlassian.net/wiki/spaces/SECS) to version 3.6.0 or above
- Prepared the Security and Encryption for Confluence Data Center app data in the hosted platform
- Performed migration using the Confluence Cloud Migration tool
- Checked and reconfigured (transformed) the [Security and Encryption for Confluence Cloud](https://appfire.atlassian.net/wiki/spaces/SECC) data in the cloud

> 📝 Depending on how large your Confluence data is, this process may take a few hours to complete.

### Step 1 - Run CCMA

Follow through with the steps in [Step 1 - Run CCMA (Security & Encryption)](https://appfire.atlassian.net/wiki/spaces/SECC/pages/477728388)

**Overview**

- Prepare a set of test data and a staging instance to perform a pre-migration environment test before production migration [OPTIONAL]
- Upgraded Security and Encryption for Confluence Server to version 3.6.0 or above
- Find and identify the spaces that are using the Security and Encryption macros
- Perform the migration using the Confluence Cloud Migration Assistant(CCMA) tool
- Schedule the migration window

### Step 2 - Secure Macro Transformation to Secrets

Follow through with the steps in [Step 2 - Secure Macro Transformation to Secrets (Security & Encryption)](https://appfire.atlassian.net/wiki/spaces/SECS/pages/477858228)

**Overview**

- Have your Confluence cloud instance ready
- Select which secrets you want to migrate from the Data Center Migration Beta tab
- Generate the migration key and passphrase from the Confluence Data Center
- Perform the transformation of the hosted app [secure](https://appfire.atlassian.net/wiki/spaces/SECS/pages/477857356) Macro to its cloud equivalent [Secret](https://appfire.atlassian.net/wiki/spaces/SECC/pages/477727234)
- After a successful migration, admins should check for **Secret** owners without add/delete restrictions and then grant them access

> ✅ For further information on the restrictions - [How do we check and bulk update add/delete restrictions?](https://appfire.atlassian.net/wiki/spaces/SECC/pages/477727914))

> ℹ️ The improved version of Security and Encryption for Confluence Cloud utilizes a zero-knowledge architecture. To learn more, read [What is a legacy secret?](https://appfire.atlassian.net/wiki/spaces/SECC/pages/477727740).
> ℹ️ 
> ℹ️ When migrated to the cloud, legacy secrets are automatically converted. To ensure that this transition happens smoothly, the Administrator executing the migration will be added as the owner of the secrets.

### Step 3 - Troubleshooting Steps

Follow through with the steps in [Step 3 - Troubleshooting Steps (Security and Encryption)](https://appfire.atlassian.net/wiki/spaces/SECS/pages/477858343)

**Overview**

- Ensure the Security and Encryption add-on is given the <span style="color: #0e101a">appropriate</span> permission in space permissions
- Understand the type of error messages and what non-transformed secrets look like.

---

## Next Steps 

- Follow the process in [Step 1](https://appfire.atlassian.net/wiki/spaces/SECS/pages/477858192)