Contact Sales

To contact our sales team, you can use the form below. Do not use this form for tickets or help desk, click here to create a ticket.

Synchronise and migrate users and workstation between on-prem AD, Entra ID, Google the easy way. Seamlessly Move devices between AD Joined, Hybrid and Entra Joined.
  • Create ticket
  • Home
  • Migration Agent

Handling SCCM / MECM and Co-Management During Workstation Migrations

A guide to managing Microsoft Configuration Manager clients and co-management states when migrating devices between directories or tenants.

Written by Jamie Richard

Updated at June 2nd, 2026

Contact Sales

To contact our sales team, you can use the form below. Do not use this form for tickets or help desk, click here to create a ticket.

  • Getting Started
  • FAQs
  • API Documentation
  • Integrations
  • Migration Agent
  • Directory Synchronisation
  • Remote DC agent
  • Remote Password Sync Agent
  • Install and Configure
  • Support
  • Complex Expressions
+ More

Table of Contents

The Scenario Migration Scenarios & Requirements 1. Migrating to Entra ID (No Co-Management) 2. Migrating to Entra ID (With Co-Management) ⚠️ Important: Pre-Testing Entra-Only Co-Management 3. Migrating to Another Active Directory (AD-to-AD / Hybrid) ⚠️ Important: Extensive Testing Required The Recommended SCCM Removal Process Scripts support Execution Method: PowerSyncPro Startup Script

The Scenario

When utilizing PowerSyncPro to migrate workstations to a new target environment, special consideration must be given to devices currently managed by Microsoft Configuration Manager (SCCM / MECM).

Because a workstation's SCCM client identity is deeply bound to its underlying Active Directory or hybrid Entra identity at the time of registration, changing the device's join state mid-lifecycle can cause severe authentication mismatches. PowerSyncPro actively tears down the legacy identity during the migration process, meaning any existing SCCM client left on the machine will retain stale artifacts such as the old SMS GUID, defunct hybrid token caches, and invalid client certificates.

To prevent these issues, administrators must evaluate their target management strategy and properly prepare the SCCM client before the PowerSyncPro migration executes.


Migration Scenarios & Requirements

How you handle the SCCM client depends entirely on your target device state and management goals post-migration.

1. Migrating to Entra ID (No Co-Management)

If the workstation is moving to a cloud-native Entra ID join state and will be managed strictly by Microsoft Intune going forward, the existing SCCM client is no longer required.

  • Action Required: The SCCM client must be completely uninstalled from the device prior to the migration.

2. Migrating to Entra ID (With Co-Management)

Microsoft does not support an "identity transplant" to convert an existing hybrid-joined SCCM client into an Entra-only co-managed client. If you leave the existing SCCM client in place, it will fail to authenticate to the Cloud Management Gateway (CMG) after the migration because it is still utilizing the legacy hybrid identity.

  • Action Required: You must perform a complete, deep uninstall of the SCCM client before the migration.
  • Post-Migration Reinstall: After PowerSyncPro joins the device to the new Entra tenant, the user logs in, and the device will automatically enroll into Intune. You must rely on an Intune co-management settings policy in the target tenant to push down a fresh SCCM client installation. This forces the client to register a brand-new SMS GUID anchored to the new Entra identity.

 

⚠️ Important: Pre-Testing Entra-Only Co-Management

Administrators must have already tested and verified SCCM co-management against machines enrolled directly into Entra ID. PowerSyncPro does not make any configuration changes to your target environment to allow for this scenario. A Cloud Management Gateway (CMG) configured for Microsoft Entra ID (token-based) authentication is mandatory, as cloud-only devices will not have internal PKI certificates and cannot reach an on-premises management point.

 

3. Migrating to Another Active Directory (AD-to-AD / Hybrid)

If the machine is being migrated into a different on-premises Active Directory or a different hybrid environment, the SCCM configuration requires a thorough architectural review.

  • Action Required: You must evaluate how SCCM is configured in the target environment (e.g., boundaries, site codes, PKI certificates) to determine if a full re-installation of the SCCM client is required, or if the client can be re-pointed to the new management point post-migration.

 

⚠️ Important: Extensive Testing Required

Managing SCCM handoffs during an identity migration is a highly complex process. We strongly encourage extensive pilot testing of these SCCM configurations and removal scripts before running a broad migration to ensure that all elements (CMG authentication, Intune policies, and registry cleanups) are handled smoothly.

 

 


The Recommended SCCM Removal Process

Standard uninstallation commands often leave behind orphaned WMI namespaces, registry keys, and certificates that will conflict with the post-migration management tooling.

To properly prepare a device for migration, we have seen good results using this community-driven SCCM Client Removal Script available on GitHub here: sccm_removal.ps1.

Scripts support

PowerSyncPro does not support the action of scripts on the computer. You run them at your own risk.

When using community scripts please ensure thorough testing. 

 

 

Execution Method: PowerSyncPro Startup Script

Your chosen script should be run as a "Startup" script within your PowerSyncPro runbook. PowerSyncPro guarantees that the script executes silently as SYSTEM at the exact right moment in the migration sequence, before any directory join operations occur. How to create a command line package to Run. 

co-management migration

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Intune Enrollment Post-Migration: Requirements & Troubleshooting
  • How-To Migrate Workgroup Joined Endpoints to AD / Entra
  • PowerSyncPro Migration Agent - Installation Methods
  • BPRT is the Owner Workstation in Entra

Subscribe to Newsletter

Drop your email in the box below to sign up. We promise to keep our updates relevant and useful – and we’ll never share your details.

PowerSyncPro's logo

PowerSyncPro is the ultimate product for easing the pain and frustration during mergers, acquisitions, divestitures, and consolidations.

Terms & Conditions

  • FAQs
  • Privacy Policy
  • Cookies
  • Anti Slavery Notice

PowerSyncPro

  • Case Studies
  • Contact sales
  • Marketplace
  • EULA

Get Connected

Room 73, Wrest House, Wrest Park, Silsoe, Bedford, England, MK45 4HR
info@powersyncpro.com

Twitter Youtube Linkedin

Expand